Ransom

About “Generic.Ransom.Amnesia.8E246F03” infection

Malware Removal

The Generic.Ransom.Amnesia.8E246F03 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Amnesia.8E246F03 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • CAPE extracted potentially suspicious content
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • Drops a binary and executes it
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Created a process from a suspicious location
  • Overwrites an accessibility feature binary for Windows login bypass, persistence or privilege escalation
  • Detects Joe or Anubis Sandboxes through the presence of a file
  • Checks the presence of disk drives in the registry, possibly for anti-virtualization
  • A script or command line contains a long continuous string indicative of obfuscation
  • Creates a copy of itself

How to determine Generic.Ransom.Amnesia.8E246F03?


File Info:

name: 13DA1D92A84EE8E7586D.mlw
path: /opt/CAPEv2/storage/binaries/2cafff6bb9fd4314975895a53a5743e41a585da98583903907245aa470eb0596
crc32: 5C3882E6
md5: 13da1d92a84ee8e7586ded9eabf33f46
sha1: 74bd9fd087546aa2934ce744880c8c19b8174209
sha256: 2cafff6bb9fd4314975895a53a5743e41a585da98583903907245aa470eb0596
sha512: 3d76341c7af96c689f7e5eaad2fc540e2466c55c221527802028156dfaf092df4684166623db3100371509fb32d6e7a2b6d8cf41a9ae10b72e34af899eb29713
ssdeep: 6144:zuaknWpWCFf2r0Z0FUcUgtPRLr/45QKHju:z5pWCF2u09lRHcHj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T13644AE37EB809976E0497D789D45C7B2E63A79300E1D1056BDE92F0EE9382C2922D7D3
sha3_384: 4a9c5f519ff357e14042173ea288c23595534eeeb9b220c8e51f37cf7e0ea128f004ce1a40cce46f5437ca94faf40d5b
ep_bytes: 558bec83c4f0b8e0aa4300e8e0adfcff
timestamp: 2021-10-12 21:16:51

Version Info:

0: [No Data]

Generic.Ransom.Amnesia.8E246F03 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Generic.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26375
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.8E246F03
FireEyeGeneric.mg.13da1d92a84ee8e7
ALYacDeepScan:Generic.Ransom.Amnesia.8E246F03
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 004f6e981 )
AlibabaRansom:Win32/Pulobe.6a0
Cybereasonmalicious.2a84ee
BitDefenderThetaAI:Packer.98DB57631F
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FS
TrendMicro-HouseCallMal_Purge
Paloaltogeneric.ml
ClamAVWin.Ransomware.Deepscan-6975721-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Amnesia.8E246F03
AvastWin32:RansomX-gen [Ransom]
TencentWin32.Trojan.Filecoder.Dzao
Ad-AwareDeepScan:Generic.Ransom.Amnesia.8E246F03
EmsisoftDeepScan:Generic.Ransom.Amnesia.8E246F03 (B)
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
GDataDeepScan:Generic.Ransom.Amnesia.8E246F03
AviraTR/Downloader.Gen
MicrosoftRansom:Win32/Pulobe.RB!MSR
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Ransom.R338400
Acronissuspicious
McAfeeRansom-Scarab!13DA1D92A84E
MAXmalware (ai score=87)
VBA32BScope.Trojan.Encoder
MalwarebytesRansom.Scarab
APEXMalicious
RisingRansom.Scarab!1.BACD (CLASSIC)
YandexTrojan.GenAsa!bXAtAcuJUJk
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Msht.GJ!tr
AVGWin32:RansomX-gen [Ransom]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_90% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Generic.Ransom.Amnesia.8E246F03?

Generic.Ransom.Amnesia.8E246F03 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment