Malware

Generic.BrResMon.1.12F24170 (file analysis)

Malware Removal

The Generic.BrResMon.1.12F24170 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.BrResMon.1.12F24170 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Attempts to connect to a dead IP:Port (7 unique times)
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Albanian
  • The binary likely contains encrypted or compressed data.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Checks the CPU name from registry, possibly for anti-virtualization

Related domains:

www.billerimpex.com
www.macartegrise.eu
www.poketeg.com
perovaphoto.ru
asl-company.ru
www.fabbfoundation.gm
www.perfectfunnelblueprint.com
www.wash-wear.com
pp-panda74.ru
cevent.net
bellytobabyphotographyseattle.com
alem.be
apps.identrust.com
crl.identrust.com
x1.c.lencr.org
boatshowradio.com
dna-cp.com
acbt.fr
r3.o.lencr.org
wpakademi.com
www.cakav.hu
www.mimid.cz
6chen.cn
goodapd.website
oceanlinen.com
tommarmores.com.br
nesten.dk
zaeba.co.uk
www.n2plus.co.th
koloritplus.ru
h5s.vn
marketisleri.com
www.toflyaviacao.com.br
www.rment.in
www.lagouttedelixir.com
www.krishnagrp.com
big-game-fishing-croatia.hr
ocsp.digicert.com

How to determine Generic.BrResMon.1.12F24170?


File Info:

crc32: 10E8FA73
md5: c93286c935d68042e3a46a18dfd97573
name: C93286C935D68042E3A46A18DFD97573.mlw
sha1: 022f89ef6ce588d47a1af477a26c94cde551b8db
sha256: c25d13eef912c5655bfef73b07e64543b3a7a15f7c385f70e3d09ed484ca5a24
sha512: d2b928f1d80f6f6aad186f2dbda986c53c80caf688db5f90865c3573454129dcb7edec51fb68bb9a869cc907481a6389f015783b8ab0ea6145449de0d1289eb6
ssdeep: 3072:dlfnjSXomJyaMBVv54GJl6pUiiK9xqNHrJiedvZ1BEGUiE6VvO37Id3zYBNv3Aw:/fj2RyvvqGbw6K92Lw0Rw77IGZAw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, zayiujxeiraj
FileVersion: 10.1.10.11
ProductVersion: 2.13.5.66
Translation: 0x3245 0xa910

Generic.BrResMon.1.12F24170 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00516fdf1 )
LionicTrojan.Win32.GandCrypt.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDeepScan:Generic.BrResMon.1.12F24170
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
AlibabaTrojan:Win32/Kryptik.0e90ad9e
K7GWTrojan ( 0056f44a1 )
Cybereasonmalicious.935d68
CyrenW32/Kryptik.HR.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GKAE
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.BrResMon.1.12F24170
NANO-AntivirusTrojan.Win32.GenKryptik.fgtwlz
ViRobotTrojan.Win32.S.Gandcrab.218624.A
MicroWorld-eScanDeepScan:Generic.BrResMon.1.12F24170
TencentWin32.Trojan.Generic.Sxxq
Ad-AwareDeepScan:Generic.BrResMon.1.12F24170
SophosMal/Generic-S
ComodoTrojWare.Win32.Vigorf.AZ@7szk9m
BitDefenderThetaGen:NN.ZexaF.34050.nu0@aaCV@DfO
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.c93286c935d68042
EmsisoftDeepScan:Generic.BrResMon.1.12F24170 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojanDownloader.Upatre.ajnc
AviraTR/GandCrab.mzr
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.27D9C9F
MicrosoftRansom:Win32/Genasom
SUPERAntiSpywareTrojan.Agent/Generic
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataWin32.Trojan-Ransom.GandCrab.N
AhnLab-V3Trojan/Win32.Gandcrab.C2669036
Acronissuspicious
McAfeeTrojan-FPYT!C93286C935D6
MAXmalware (ai score=100)
VBA32BScope.Trojan.Chapak
MalwarebytesMalware.AI.1873745228
PandaTrj/Genetic.gen
RisingTrojan.Kryptik!1.B5F8 (CLASSIC)
YandexTrojan.GenAsa!w5oEEXC3uhQ
IkarusTrojan.GoCloudnet
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GKAE!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.GandCrab.HwoCEpsA

How to remove Generic.BrResMon.1.12F24170?

Generic.BrResMon.1.12F24170 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment