Ransom

Generic.Ransom.CloudSword.8A5829A9 (file analysis)

Malware Removal

The Generic.Ransom.CloudSword.8A5829A9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.CloudSword.8A5829A9 virus can do?

  • Creates RWX memory
  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Generic.Ransom.CloudSword.8A5829A9?


File Info:

crc32: 242FF59B
md5: d55665f1ed15d0f26609674f5afc27d5
name: D55665F1ED15D0F26609674F5AFC27D5.mlw
sha1: 8c835c18cbd68b4f06a314908257a16f63d86872
sha256: d7c0e4aa2973ac083ef78cd2621d8a05bc4d581572dde488673f9fc0d07145ba
sha512: 77422ece289e97b7c1749a9df938c4a88ab6ec0c16fa9af0d8076912785196673ab03b581431446f9a07feb01554778517560f867e39ccfadd7739018afc561b
ssdeep: 768:7mOHkWx/vSaSJOLbVxlQdPAyI1V1zaHTR:7mOHkE37SJOLbvlwAyI1V1zOR
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2018
Assembly Version: 1.0.0.0
InternalName: White.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: White
ProductVersion: 1.0.0.0
FileDescription: White
OriginalFilename: White.exe

Generic.Ransom.CloudSword.8A5829A9 also known as:

K7AntiVirusTrojan ( 0052d20d1 )
LionicTrojan.Win32.Spora.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.25064
McAfeeArtemis!D55665F1ED15
CylanceUnsafe
ZillyaTrojan.Spora.Win32.1058
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_70% (D)
K7GWTrojan ( 0052d20d1 )
Cybereasonmalicious.1ed15d
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.WhiteRose.A
APEXMalicious
AvastWin32:Malware-gen
CynetMalicious (score: 99)
KasperskyTrojan-Ransom.Win32.Spora.fba
BitDefenderGeneric.Ransom.CloudSword.8A5829A9
NANO-AntivirusTrojan.Win32.Spora.ezplsz
MicroWorld-eScanGeneric.Ransom.CloudSword.8A5829A9
TencentWin32.Trojan.Spora.Wqcs
Ad-AwareGeneric.Ransom.CloudSword.8A5829A9
SophosMal/Generic-R + Mal/Infitear-A
ComodoMalware@#2us260immx8tz
BitDefenderThetaGen:NN.ZemsilF.34170.cm0@aiJ!cBd
McAfee-GW-EditionArtemis!Trojan
FireEyeGeneric.mg.d55665f1ed15d0f2
EmsisoftGeneric.Ransom.CloudSword.8A5829A9 (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1109331
Antiy-AVLTrojan/Generic.ASMalwS.25407A0
MicrosoftRansom:MSIL/BlackHeart!MTB
GDataMSIL.Trojan-Ransom.WhiteRose.A
AhnLab-V3Trojan/Win32.Ransomlock.C2493708
MAXmalware (ai score=100)
MalwarebytesRansom.Spora
PandaTrj/GdSda.A
YandexTrojan.Spora!kXMDI8JmDoE
IkarusTrojan-Ransom.FileCrypter
FortinetMSIL/WhiteRose.A!tr.ransom
AVGWin32:Malware-gen

How to remove Generic.Ransom.CloudSword.8A5829A9?

Generic.Ransom.CloudSword.8A5829A9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment