Ransom Trojan

BScope.Trojan-Ransom.SageCrypt (file analysis)

Malware Removal

The BScope.Trojan-Ransom.SageCrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What BScope.Trojan-Ransom.SageCrypt virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Detected script timer window indicative of sleep style evasion
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Collects information to fingerprint the system

How to determine BScope.Trojan-Ransom.SageCrypt?


File Info:

crc32: 81793F2E
md5: b9272245571192fadabe09dbe414ddb5
name: upload_file
sha1: a2cf4e5f1b1b347d53e237b4b2f13cf31e177c55
sha256: 19ee6debbef6334a0b5d9eb5f3b0a6a36229c9377b86aa74d3a0a2bd79ee6519
sha512: ab65b4f9872cb6969d82b8ce9b9ae5fb053cef99adca091261dffa3ee207e21f27bf1d2a87476091f27cd71bf96eaa38a186676be4540a9481579cf8a6ee54ec
ssdeep: 12288:RHxHbps6eCvIpbRuxw61WgdDlqwcVDYX4k:nTexpcxw6RaYXP
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (c) 2014 - . All rights reserved. labDVxfffd
InternalName: Lags
FileVersion: 7.8.9.4
CompanyName: labDVxfffd
FileDescription: Macsx Appraisals Eggheads Landscape Dropout
Comments: Macsx Appraisals Eggheads Landscape Dropout
ProductName: Lags
ProductVersion: 7.8.9.4
PrivateBuild: 7.8.9.4
OriginalFilename: Lags
Translation: 0x0409 0x04b0

BScope.Trojan-Ransom.SageCrypt also known as:

BkavW32.AIDetectVM.malware1
DrWebTrojan.Encoder.10781
MicroWorld-eScanTrojan.GenericKD.34249925
FireEyeGeneric.mg.b9272245571192fa
ALYacTrojan.GenericKD.34249925
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 004f76a01 )
BitDefenderTrojan.GenericKD.34249925
K7GWTrojan ( 004f76a01 )
Cybereasonmalicious.557119
TrendMicroMal_MiliCry-1h
BitDefenderThetaGen:NN.ZexaF.34142.Dq0@aWgZllbi
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
GDataTrojan.GenericKD.34249925
KasperskyTrojan-Ransom.Win32.SageCrypt.dcv
AlibabaRansom:Win32/SageCrypt.3db06a86
NANO-AntivirusTrojan.Win32.SageCrypt.falyiz
ViRobotTrojan.Win32.Z.Sagecrypt.475136.A
AegisLabTrojan.Win32.SageCrypt.j!c
TencentMalware.Win32.Gencirc.10b2ea82
EmsisoftTrojan.GenericKD.34249925 (B)
ComodoTrojWare.Win32.Genome.qfaax@0
F-SecureTrojan.TR/AD.Sage.icukk
ZillyaTrojan.SageCrypt.Win32.177
Invinceaheuristic
Trapminesuspicious.low.ml.score
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
JiangminTrojan.SageCrypt.hj
AviraTR/AD.Sage.icukk
eGambitUnsafe.AI_Score_99%
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.TSGeneric
ArcabitTrojan.Generic.D20A9CC5
ZoneAlarmTrojan-Ransom.Win32.SageCrypt.dcv
CynetMalicious (score: 100)
AhnLab-V3Win-Trojan/Sagecrypt.Gen
McAfeeGenericRXBG-ZF!B92722455711
TACHYONRansom/W32.SageCrypt.475136
VBA32BScope.Trojan-Ransom.SageCrypt
MalwarebytesRansom.Sage
PandaTrj/CI.A
ESET-NOD32Win32/Filecoder.NHQ
TrendMicro-HouseCallMal_MiliCry-1h
RisingRansom.Milicry!8.A2F2 (TFE:5:Fxti397groL)
YandexTrojan.SageCrypt!
SentinelOneDFI – Suspicious PE
FortinetW32/Generic.AP.C8398!tr
Ad-AwareTrojan.GenericKD.34249925
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
Qihoo-360HEUR/QVM10.1.8A60.Malware.Gen

How to remove BScope.Trojan-Ransom.SageCrypt?

BScope.Trojan-Ransom.SageCrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment