Ransom

How to remove “Generic.Ransom.Magniber.E2005B70”?

Malware Removal

The Generic.Ransom.Magniber.E2005B70 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Magniber.E2005B70 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Generic.Ransom.Magniber.E2005B70?


File Info:

crc32: FCE7AAA5
md5: b2383841680fb6059c3fa46c15d0a375
name: B2383841680FB6059C3FA46C15D0A375.mlw
sha1: 4de5d882dc971d7427466f454106182538d1a696
sha256: dfac60d3603ac94b077036e2809be306a6a810e5abff96998982e266cc7e308c
sha512: 7446b601d4243309433f49f9891909a668b31f313f9a8652f2d6c1d571c5e482b07e80bbfb868297ee6eec3bd0b8c3c29cdd367e8e82c663eb123355e1f164a3
ssdeep: 3072:cPpwM7IJBmg/D59YvRccyb+SDMAascAs+FT:cNETvF9cRccm+ga0/F
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Unindigenous
InternalName: jigmen
FileVersion: 4.6
CompanyName: Unindigenous
ProductName: jigmen snushed
ProductVersion: 4.6
FileDescription: jigmen unenthused
OriginalFilename: jigmen.exe
Translation: 0x0409 0x04b0

Generic.Ransom.Magniber.E2005B70 also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Generic.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
ALYacDeepScan:Generic.Ransom.Magniber.E2005B70
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 0051c8bc1 )
K7AntiVirusTrojan ( 0051c8bc1 )
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.EYLT
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
CynetMalicious (score: 100)
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Magniber.E2005B70
NANO-AntivirusTrojan.Win32.Encoder.evnjlb
MicroWorld-eScanDeepScan:Generic.Ransom.Magniber.E2005B70
TencentWin32.Trojan.Generic.Pcii
Ad-AwareDeepScan:Generic.Ransom.Magniber.E2005B70
ComodoMalware@#3gqvqbdxj2wv1
BitDefenderThetaGen:NN.ZevbaF.34170.hq0@aS1f4gpi
VIPRETrojan.Win32.Generic!BT
FireEyeGeneric.mg.b2383841680fb605
EmsisoftDeepScan:Generic.Ransom.Magniber.E2005B70 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.cqelj
AviraHEUR/AGEN.1121409
Antiy-AVLTrojan/Generic.ASMalwS.22DEA12
MicrosoftRansom:Win32/Cerber.A
GDataDeepScan:Generic.Ransom.Magniber.E2005B70
Acronissuspicious
McAfeeRansomware-GIX!B2383841680F
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
PandaTrj/GdSda.A
RisingTrojan.Generic@ML.83 (RDML:mdxqy9aUoHhKDFP9TcH9tA)
YandexTrojan.GenAsa!HFpGDCyTixw
IkarusTrojan.Win32.Crypt
FortinetW32/Kryptik.EYKI!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Generic.Ransom.Magniber.E2005B70?

Generic.Ransom.Magniber.E2005B70 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment