Ransom

About “Generic.Ransom.Buhtrap.B667608B” infection

Malware Removal

The Generic.Ransom.Buhtrap.B667608B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Buhtrap.B667608B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Executed a command line with /C or /R argument to terminate command shell on completion which can be used to hide execution
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • Creates RWX memory
  • Guard pages use detected – possible anti-debugging.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Attempts to delete or modify volume shadow copies
  • Attempts to delete system state backup
  • Modifies boot configuration settings
  • Created a process from a suspicious location
  • A system process is generating network traffic likely as a result of process injection
  • Collects and encrypts information about the computer likely to send to C2 server
  • Installs itself for autorun at Windows startup
  • CAPE detected the Zeppelin malware family
  • Attempts to modify proxy settings
  • Attempts to execute suspicious powershell command arguments
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Buhtrap.B667608B?


File Info:

name: 11458193E92E804AB696.mlw
path: /opt/CAPEv2/storage/binaries/f2ad2b40a1ca4c337396cf8dd0528796c1e1657d8c76c441f459ac0e1dc60396
crc32: E9F57858
md5: 11458193e92e804ab696bcd124000db8
sha1: 32046e359203d00fb02afe3c5290fce1d162dba6
sha256: f2ad2b40a1ca4c337396cf8dd0528796c1e1657d8c76c441f459ac0e1dc60396
sha512: fef000b7c8bffe9d3a8370ee6a827cefc58e0cd9789a9b27bf482b19d7396b9b47e9a5bba867e13aafef0d97498db8e1c5db2ead1f1d0fef989fd4931e106d81
ssdeep: 6144:xyJE1yd7WHJmcyfjtPWna4DQFu/U3buRKlemZ9DnGAevIhdi0Tl+:xU/d7WsvBPWa4DQFu/U3buRKlemZ9Dnl
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T156247D36B6804472D1732E7CDE1A56AE913E7A301F2C14477DE85E8D9E3E3A2652D2C3
sha3_384: 417c3efe735835aca403088b8a5eb7f99659135542920d53e4fa20b5bae5fc4ebfc302ad2d5565a4c7e302f288972598
ep_bytes: 558bec83c4f0b86cef4200e87451fdff
timestamp: 2022-07-06 12:57:28

Version Info:

0: [No Data]

Generic.Ransom.Buhtrap.B667608B also known as:

CynetMalicious (score: 100)
FireEyeGeneric.mg.11458193e92e804a
CAT-QuickHealTrojan.AgentIH.S18008568
McAfeeGenericRXKB-RP!11458193E92E
MalwarebytesRansom.Zeppelin
VIPREGeneric.Ransom.Buhtrap.B667608B
K7AntiVirusTrojan ( 0055c8001 )
BitDefenderGeneric.Ransom.Buhtrap.B667608B
K7GWTrojan ( 0055c8001 )
Cybereasonmalicious.3e92e8
VirITRansom.Win64.Zeppelin.BJO
CyrenW32/Ransom.LV.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Buran.J
APEXMalicious
ClamAVWin.Ransomware.Buhtrap-9865977-0
KasperskyHEUR:Trojan.Win32.Agent.gen
MicroWorld-eScanGeneric.Ransom.Buhtrap.B667608B
AvastFileRepMalware [Misc]
Ad-AwareGeneric.Ransom.Buhtrap.B667608B
EmsisoftGeneric.Ransom.Buhtrap.B667608B (B)
F-SecureHeuristic.HEUR/Malware
TrendMicroRansom.Win32.ZEPPELIN.SMTH
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
SophosML/PE-A + Mal/Behav-010
IkarusTrojan-Ransom.Buran
GDataWin32.Trojan-Ransom.Zeppelin.FW0CV4
JiangminTrojanRansom.Hospital.a
AviraHEUR/Malware
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASCommon.195
ArcabitGeneric.Ransom.Buhtrap.BDA2FD8B
ZoneAlarmHEUR:Trojan.Win32.Agent.gen
MicrosoftRansom:Win32/Zeppelin.A!MSR
AhnLab-V3Trojan/Win32.BuhTrap.R338445
Acronissuspicious
VBA32BScope.TrojanRansom.Crypmod
ALYacGeneric.Ransom.Buhtrap.B667608B
CylanceUnsafe
TrendMicro-HouseCallRansom.Win32.ZEPPELIN.SMTH
RisingRansom.Zeppelin!1.D4C1 (CLASSIC)
YandexTrojan.GenAsa!CxfKQU+AivY
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Buran.H!tr.ransom
BitDefenderThetaAI:Packer.2B43D09E1F
AVGFileRepMalware [Misc]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Generic.Ransom.Buhtrap.B667608B?

Generic.Ransom.Buhtrap.B667608B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment