Ransom

Generic.Ransom.HydraCrypt.1DCBCF8F (file analysis)

Malware Removal

The Generic.Ransom.HydraCrypt.1DCBCF8F is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.HydraCrypt.1DCBCF8F virus can do?

  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

How to determine Generic.Ransom.HydraCrypt.1DCBCF8F?


File Info:

crc32: D1B26417
md5: 4d2f05db3c5995e87b1158bf90463511
name: 4D2F05DB3C5995E87B1158BF90463511.mlw
sha1: 4329860a8c16f829e8e3ecdbbbfa0bf70897fe7e
sha256: 10171873398cc87c07a61d876d845d96344037fbc0715568b9458af220467c78
sha512: 65742d67a5f65dc5f592282b5fb0d390e8320b014e6fb9b690591ffc4306ee7ab531a457b3cb6850145e8dda236a360f444fa48017333fbc40b101c0c02d61d1
ssdeep: 384:kOgHs6cYgBzrncDzkcZ+LJxr91Cf/nbJTyu:kOgHs7hzOAo+9xr9Snbou
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright:
Assembly Version: 0.0.0.0
InternalName: ransom1.exe
FileVersion: 0.0.0.0
ProductVersion: 0.0.0.0
FileDescription:
OriginalFilename: ransom1.exe

Generic.Ransom.HydraCrypt.1DCBCF8F also known as:

Elasticmalicious (high confidence)
DrWebTrojan.ClipBankerNET.7
MicroWorld-eScanGeneric.Ransom.HydraCrypt.1DCBCF8F
ALYacGeneric.Ransom.HydraCrypt.1DCBCF8F
CylanceUnsafe
CrowdStrikewin/malicious_confidence_60% (D)
Cybereasonmalicious.b3c599
CyrenW32/Azorult.D.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Filecoder.AGP
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.MSIL.Fsysna.gen
BitDefenderGeneric.Ransom.HydraCrypt.1DCBCF8F
Ad-AwareGeneric.Ransom.HydraCrypt.1DCBCF8F
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34796.bm0@aedsaFc
McAfee-GW-EditionBehavesLike.Win32.Trojan.mm
FireEyeGeneric.mg.4d2f05db3c5995e8
EmsisoftGeneric.Ransom.HydraCrypt.1DCBCF8F (B)
SentinelOneStatic AI – Malicious PE
AviraTR/ATRAPS.Gen
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:MSIL/ApisCryptor.PAA!MTB
ArcabitGeneric.Ransom.HydraCrypt.1DCBCF8F
ZoneAlarmHEUR:Trojan.MSIL.Fsysna.gen
GDataMSIL.Trojan-Ransom.Remind.B
AhnLab-V3Ransomware/Win.FTD.C4544232
McAfeeRansomware-FTD!4D2F05DB3C59
MAXmalware (ai score=89)
MalwarebytesRansom.Chaos
PandaTrj/GdSda.A
RisingRansom.Destructor!1.B060 (CLASSIC)
MaxSecureTrojan.Malware.300983.susgen
FortinetMSIL/Filecoder.24EB!tr.ransom
AVGWin32:RansomX-gen [Ransom]

How to remove Generic.Ransom.HydraCrypt.1DCBCF8F?

Generic.Ransom.HydraCrypt.1DCBCF8F removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment