Ransom

What is “Generic.Ransom.CloudSword.BAB6738F”?

Malware Removal

The Generic.Ransom.CloudSword.BAB6738F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.CloudSword.BAB6738F virus can do?

  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • Looks up the external IP address
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Attempts to identify installed AV products by installation directory
  • Harvests credentials from local FTP client softwares
  • Harvests information related to installed instant messenger clients
  • Harvests information related to installed mail clients
  • Attempts to create or modify system certificates
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
checkip.dyndns.org
freegeoip.app

How to determine Generic.Ransom.CloudSword.BAB6738F?


File Info:

crc32: 052CC212
md5: be64079ed4a977e0f2d5b7a99f183f92
name: BE64079ED4A977E0F2D5B7A99F183F92.mlw
sha1: 24f74503e7d7846e68946b60375ab0ff5cd751b8
sha256: 16de3eda535222554559d0d0c3b678ccbe117c58fce8c648b48e3e957a797401
sha512: 1f0ed0d75621bf178bb5a6bbc4c2959e9e71a3f1027bfcd78e4962e285226831a9c954141f828417bd443834879f75af9c867883583a5a6ed1c97a8aeecc785a
ssdeep: 6144:4qjI2XreXWCR2lnpUrmyE6wRshinuRZ+oQMjUrBFfY6YpnQ2A:1rrqklpUPExsQnuf+2UrXqpVA
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Generic.Ransom.CloudSword.BAB6738F also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0057eb291 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.CloudSword.BAB6738F
CrowdStrikewin/malicious_confidence_90% (W)
K7GWTrojan ( 0057eb291 )
Cybereasonmalicious.ed4a97
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan-PSW.Win32.Stealer.gen
BitDefenderDeepScan:Generic.Ransom.CloudSword.BAB6738F
MicroWorld-eScanDeepScan:Generic.Ransom.CloudSword.BAB6738F
Ad-AwareDeepScan:Generic.Ransom.CloudSword.BAB6738F
SophosGeneric ML PUA (PUA)
McAfee-GW-EditionBehavesLike.Win32.ICLoader.dc
FireEyeGeneric.mg.be64079ed4a977e0
EmsisoftDeepScan:Generic.Ransom.CloudSword.BAB6738F (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Woreflint.A!cl
ArcabitDeepScan:Generic.Ransom.CloudSword.BABD1A52F
GDataDeepScan:Generic.Ransom.CloudSword.BAB6738F
MAXmalware (ai score=82)
YandexTrojan.Slntscn24.bVVB1s
FortinetW32/Injector.EOWC!tr
AVGFileRepMalware
Paloaltogeneric.ml
Qihoo-360HEUR/QVM20.1.8E9F.Malware.Gen

How to remove Generic.Ransom.CloudSword.BAB6738F?

Generic.Ransom.CloudSword.BAB6738F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment