Ransom

Generic.Ransom.Amnesia.EC727CB8 information

Malware Removal

The Generic.Ransom.Amnesia.EC727CB8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Amnesia.EC727CB8 virus can do?

  • Attempts to connect to a dead IP:Port (3 unique times)
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Deletes its original binary from disk
  • Modifies boot configuration settings
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Likely virus infection of existing system binary
  • Clears Windows events or logs
  • Creates a copy of itself
  • Uses suspicious command line tools or Windows utilities

Related domains:

iplogger.co
iplogger.org
ocsp.comodoca.com
ocsp.usertrust.com
ocsp.sectigo.com
crl.usertrust.com

How to determine Generic.Ransom.Amnesia.EC727CB8?


File Info:

crc32: D0AA17DD
md5: 536d107e9752c74f3a1874fecb4f5fdb
name: 536D107E9752C74F3A1874FECB4F5FDB.mlw
sha1: 616882dd3b63ff6499aafcef3e66bf9b8cf41492
sha256: a40f5a1583f9b4640f6b0cc9cd42b0c391a927e5889b1e20468effaac428f71a
sha512: b0dbfe08fb2d16c3bab8ac36a520f33134253bff25a2bfacb8c067d6186058963b28e5fbfe594cba71fb82ee9585c8542d3701a00dea0232316dd43718eb7090
ssdeep: 6144:P1NfihAGGNARFWCgk1+VhpBviL/YxqVK5Vo:POmqRFWCgG+/9xr5V
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Generic.Ransom.Amnesia.EC727CB8 also known as:

K7AntiVirusTrojan ( 004f6e981 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.26587
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Scarab
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (D)
AlibabaRansom:Win32/Higuniel.c0cf86b5
K7GWTrojan ( 004f6e981 )
Cybereasonmalicious.e9752c
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.FS
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Scarab-6965729-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderDeepScan:Generic.Ransom.Amnesia.EC727CB8
NANO-AntivirusTrojan.Win32.Filecoder.fjluyw
MicroWorld-eScanDeepScan:Generic.Ransom.Amnesia.EC727CB8
TencentWin32.Trojan.Filecoder.Suef
Ad-AwareDeepScan:Generic.Ransom.Amnesia.EC727CB8
SophosMal/Generic-S
ComodoTrojWare.Win32.TrojanDownloader.Delf.gen@1xqow5
BitDefenderThetaAI:Packer.DEEEAD0E1E
VIPREFraudTool.Win32.SecurityShield.ek!c (v)
TrendMicroMal_Purge
McAfee-GW-EditionBehavesLike.Win32.ExploitMydoom.dh
FireEyeGeneric.mg.536d107e9752c74f
EmsisoftDeepScan:Generic.Ransom.Amnesia.EC727CB8 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ctare
AviraHEUR/AGEN.1117085
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Generic.ASMalwS.28B14BE
MicrosoftRansom:Win32/Higuniel.A
AegisLabTrojan.Win32.Agent.4!c
GDataDeepScan:Generic.Ransom.Amnesia.EC727CB8
AhnLab-V3Malware/Win32.Purge.C2596671
Acronissuspicious
McAfeeGenericRXGB-WP!536D107E9752
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
MalwarebytesMachineLearning/Anomalous.100%
PandaTrj/GdSda.A
TrendMicro-HouseCallMal_Purge
RisingRansom.Higuniel!8.F44A (CLOUD)
YandexTrojan.GenAsa!UDTQ20lr1Po
IkarusTrojan-Ransom.FileCrypter
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.FS!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Generic.Ransom.Amnesia.EC727CB8?

Generic.Ransom.Amnesia.EC727CB8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment