Ransom

Generic.Ransom.Buhtrap.1C3B0427 malicious file

Malware Removal

The Generic.Ransom.Buhtrap.1C3B0427 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Buhtrap.1C3B0427 virus can do?

  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Code injection with CreateRemoteThread in a remote process
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Creates a copy of itself

Related domains:

geoiptool.com
www.geodatatool.com
ocsp.comodoca.com
ocsp.usertrust.com
crl.usertrust.com

How to determine Generic.Ransom.Buhtrap.1C3B0427?


File Info:

crc32: 100AAB92
md5: d4282e2f634a5837c3952ac22d175980
name: D4282E2F634A5837C3952AC22D175980.mlw
sha1: bac3a1544f6ee6e8e474f519dcb31b9a30109762
sha256: 74429a3139a43c9c47dfdb64bbda21c3083d09ba076f76b57a7d658a15bbb48e
sha512: 2ad5a8eb4a83cbb81f08cf28b1acfd2cecc71256dacbf818633ae817e56b178eb45263be2c22ac6c84e6c6e100ac7944de9c3a98802ab09d1f43535deacfdbbb
ssdeep: 3072:BoRLPeRw6VotY+127M2mC7IzAjxxR/5wthVpyOE:WL+o18HmCCAjxxR/SV2
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

0: [No Data]

Generic.Ransom.Buhtrap.1C3B0427 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005745d11 )
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader34.15615
CynetMalicious (score: 100)
ALYacTrojan.Ransom.VegaLocker
MalwarebytesTrojan.Agent
ZillyaTrojan.Filecoder.Win32.16783
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Zeppelin.617854aa
K7GWTrojan ( 005745d11 )
Cybereasonmalicious.f634a5
CyrenW32/Ransom.NCZB-6965
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Buran.J
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderGeneric.Ransom.Buhtrap.1C3B0427
NANO-AntivirusTrojan.Win32.Filecoder.icpzfa
MicroWorld-eScanGeneric.Ransom.Buhtrap.1C3B0427
TencentWin32.Trojan.Raas.Auto
Ad-AwareGeneric.Ransom.Buhtrap.1C3B0427
SophosML/PE-A + Mal/Behav-010
ComodoMalware@#26xvrx35gmvvo
BitDefenderThetaAI:Packer.8A0D0E341E
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.ZEPPELIN.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.hz
FireEyeGeneric.mg.d4282e2f634a5837
EmsisoftGeneric.Ransom.Buhtrap.1C3B0427 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Agent.cyvj
WebrootW32.Malware.Gen
AviraHEUR/Malware
MicrosoftTrojan:Win32/Malex.gen!J
AegisLabTrojan.Win32.Agent.4!c
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
GDataGeneric.Ransom.Buhtrap.1C3B0427
AhnLab-V3Malware/Win32.Generic.C4224454
McAfeeArtemis!D4282E2F634A
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Crypmod
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.ZEPPELIN.SMTH
RisingRansom.Zeppelin!8.1155D (CLOUD)
YandexTrojan.Agent!UcVtTOrDJps
IkarusTrojan-Ransom.Buran
eGambitUnsafe.AI_Score_99%
FortinetW32/Buran.H!tr.ransom
AVGFileRepMalware

How to remove Generic.Ransom.Buhtrap.1C3B0427?

Generic.Ransom.Buhtrap.1C3B0427 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment