Ransom

Generic.Ransom.Magniber.2FA182D5 removal guide

Malware Removal

The Generic.Ransom.Magniber.2FA182D5 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Magniber.2FA182D5 virus can do?

  • Executable code extraction
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Generic.Ransom.Magniber.2FA182D5?


File Info:

crc32: AB5C9F0E
md5: b8dec28a2b5c7b6dfb8cc835c6fbcf8f
name: B8DEC28A2B5C7B6DFB8CC835C6FBCF8F.mlw
sha1: 02d38d317441427ee2c714ed52d755cf25c6d73c
sha256: 9f3f88e1012d0d50fa318f90e7995fbcebc7ca52da4d4a676291e8d58cfb862a
sha512: 1d11a9517549cf7a11690c6846ecdd542f2a6deade8d77a5855bc5459f04bab43819415fa7f85c1b3f145fb7bbaaac833909a5ff7e955948e4a894072f362b2a
ssdeep: 3072:oO7Z0/5tuAmIPMSI08ljvhBocpMbmOftaMJUBtz:oOuuZ6MSI0wjZBoc4mab
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright Tulsi
InternalName: epistolet
FileVersion: 2.0.0.13061
CompanyName: Tulsi
ProductName: epistolet copepods
ProductVersion: 2.0.0.13061
FileDescription: epistolet immixture heo
OriginalFilename: epistolet.exe
Translation: 0x0409 0x04b0

Generic.Ransom.Magniber.2FA182D5 also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Ransom.Magniber.2FA182D5
FireEyeGeneric.mg.b8dec28a2b5c7b6d
McAfeeArtemis!B8DEC28A2B5C
CylanceUnsafe
ZillyaTrojan.Generic.Win32.63319
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0051c8bc1 )
BitDefenderDeepScan:Generic.Ransom.Magniber.2FA182D5
K7GWTrojan ( 0051c8bc1 )
Cybereasonmalicious.a2b5c7
CyrenW32/S-fb71d293!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyHEUR:Trojan-Ransom.Win32.Zerber.pef
AlibabaRansom:Win32/Cerber.68c7c34b
NANO-AntivirusTrojan.Win32.Kryptik.evqemd
RisingRansom.Cerber!8.3058 (CLOUD)
Ad-AwareDeepScan:Generic.Ransom.Magniber.2FA182D5
EmsisoftDeepScan:Generic.Ransom.Magniber.2FA182D5 (B)
ComodoMalware@#23fg6lvtych4x
F-SecureHeuristic.HEUR/AGEN.1113889
DrWebTrojan.Encoder.4691
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.ctprj
AviraHEUR/AGEN.1113889
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Cerber.A
ArcabitDeepScan:Generic.Ransom.Magniber.2FA182D5
ZoneAlarmHEUR:Trojan-Ransom.Win32.Zerber.pef
GDataDeepScan:Generic.Ransom.Magniber.2FA182D5
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.Magniber.2FA182D5
MAXmalware (ai score=97)
VBA32BScope.TrojanRansom.Zerber
MalwarebytesMalware.Heuristic.1003
PandaTrj/GdSda.A
ESET-NOD32a variant of Win32/Kryptik.EYLT
TencentWin32.Trojan.Generic.Pikc
YandexTrojan.Agent!qZg6lB6yzys
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Evo-gen [Susp]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Ransom.Cerber.HxMBuV8A

How to remove Generic.Ransom.Magniber.2FA182D5?

Generic.Ransom.Magniber.2FA182D5 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment