Ransom

Generic.Ransom.Magniber.DEEC0C92 (file analysis)

Malware Removal

The Generic.Ransom.Magniber.DEEC0C92 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Magniber.DEEC0C92 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Behavioural detection: Transacted Hollowing

How to determine Generic.Ransom.Magniber.DEEC0C92?


File Info:

name: 322B04432E2643EB97BA.mlw
path: /opt/CAPEv2/storage/binaries/a0db96dcc2eefcbfafdf14d9fc5a1dc81afe1c3c41d93e319f643d856c7ca287
crc32: 69800316
md5: 322b04432e2643eb97baed335aca6f1b
sha1: 7549d61027ad211d550e4ae8bb9f02b9f4f7320d
sha256: a0db96dcc2eefcbfafdf14d9fc5a1dc81afe1c3c41d93e319f643d856c7ca287
sha512: 1faaa606f4b606d40f29dca25f56c5a2c5a8a41efd3f121a96a275f7702480251cbaa3bcd69db8c6e30282d3fbd7cc469284faf2359b3be4abed07dd7b38303f
ssdeep: 384:dro9vUrJ9ZGIQs8a5rPA+Q43TMrYxEYL6dGrIUfPB3n5jw2cdYIRpchegImbUY:duGzGQ8a58LQM+bmdGrz1w2caDy
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T102A27110979DD3D8E5A10A70636D3EB768FDA9712F4F50BFE34006792A60FC5A628B13
sha3_384: 5138694fe6d3712318cb421accfcf27acf6e113bcf1dc77e46894be04aeae0f0375d0bdc4540aa023a371981d9dbfb24
ep_bytes: 558bec81ec1c050000535657b9130000
timestamp: 2022-04-07 04:58:51

Version Info:

0: [No Data]

Generic.Ransom.Magniber.DEEC0C92 also known as:

MicroWorld-eScanGeneric.Ransom.Magniber.DEEC0C92
FireEyeGeneric.mg.322b04432e2643eb
CAT-QuickHealTrojan.MultiRI.S21117873
ALYacGeneric.Ransom.Magniber.DEEC0C92
CylanceUnsafe
SangforSuspicious.Win32.Save.a
Cybereasonmalicious.32e264
CyrenW32/Magniber.A.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Magniber.H
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Magniber-9939771-0
KasperskyUDS:Trojan.Multi.GenericML.xnet
BitDefenderGeneric.Ransom.Magniber.DEEC0C92
AvastWin32:DropperX-gen [Drp]
TencentWin32.Trojan.Filecoder.Lgjr
Ad-AwareGeneric.Ransom.Magniber.DEEC0C92
EmsisoftGeneric.Ransom.Magniber.DEEC0C92 (B)
DrWebTrojan.Encoder.35399
VIPREGeneric.Ransom.Magniber.DEEC0C92
McAfee-GW-EditionGenericRXGC-JU!322B04432E26
Trapminemalicious.moderate.ml.score
SophosML/PE-A
GDataGeneric.Ransom.Magniber.DEEC0C92
AviraTR/Dropper.Gen2
MAXmalware (ai score=80)
MicrosoftRansom:Win32/Cryptolocker.PAO!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.JU.R490619
Acronissuspicious
McAfeeGenericRXGC-JU!322B04432E26
VBA32BScope.Trojan.Agentb
MalwarebytesMalware.AI.3337457501
RisingTrojan.Generic@AI.100 (RDML:OVMwpkbfyw47FpXpoeefsQ)
YandexTrojan.GenAsa!q2PC60Zhsjk
IkarusTrojan.Dropper
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Magniber.H!tr.ransom
BitDefenderThetaGen:NN.ZexaF.34786.bqW@aGNfhAk
AVGWin32:DropperX-gen [Drp]
PandaAdware/SecurityProtection
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Generic.Ransom.Magniber.DEEC0C92?

Generic.Ransom.Magniber.DEEC0C92 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment