Ransom

What is “Generic.Ransom.Snatch.ACC673E7”?

Malware Removal

The Generic.Ransom.Snatch.ACC673E7 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Generic.Ransom.Snatch.ACC673E7 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Uses Windows utilities for basic functionality
  • Writes a potential ransom message to disk
  • Created a process from a suspicious location
  • Exhibits possible ransomware file modification behavior
  • CAPE detected the Snatch malware family
  • Creates a known Babuk ransomware decryption instruction / key file.
  • Uses suspicious command line tools or Windows utilities

How to determine Generic.Ransom.Snatch.ACC673E7?


File Info:

name: 1FEC17F108AF2F1BEEF1.mlw
path: /opt/CAPEv2/storage/binaries/e5eb247b9775f54746c5442d05a5befd0fb7be2a3847ed60541ccd8aad3d32ce
crc32: AB843A09
md5: 1fec17f108af2f1beef1e986b0a1c621
sha1: 200d8fbef238346508feebd95c4112c23be1c240
sha256: e5eb247b9775f54746c5442d05a5befd0fb7be2a3847ed60541ccd8aad3d32ce
sha512: 1e4b3354c7491b3ca718725baacb9ee18324994b15672ca7df05cb89a54f9cf9cce06c8583fae69227c4ab41a6898c77edbc240d7b22d3a991daa425974a2880
ssdeep: 49152:sU0PZgvJ6yzfUeac3DVqi3FmTJYRXCbxM8MGwZO2hnZXDaYKbCre4AWz5E:sU02vo4MNSFmTJSXqMRGj29ZXDaYgCSE
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T10CB5335720A2A870F2909971116D7EE92A0331233A1934B14E8EDDFEC93E5D6F9DF607
sha3_384: 60840a0f2c73495851bd93c022bb2cd0d3408baa416c5252cac13bbd7dac3e6f29ce39d7e7761736cf5396e7b72d9c24
ep_bytes: 60be15d05c008dbeeb3fe3ff5783cdff
timestamp: 1970-01-01 00:00:00

Version Info:

0: [No Data]

Generic.Ransom.Snatch.ACC673E7 also known as:

Elasticmalicious (moderate confidence)
MicroWorld-eScanDeepScan:Generic.Ransom.Snatch.ACC673E7
FireEyeGeneric.mg.1fec17f108af2f1b
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
BitDefenderThetaGen:NN.ZexaF.34742.roGfaGdTetc
SymantecRansom.Snatch!gm1
ESET-NOD32a variant of WinGo/Filecoder.A
ClamAVWin.Ransomware.Snatch-9865467-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderDeepScan:Generic.Ransom.Snatch.ACC673E7
Ad-AwareDeepScan:Generic.Ransom.Snatch.ACC673E7
EmsisoftDeepScan:Generic.Ransom.Snatch.ACC673E7 (B)
VIPREDeepScan:Generic.Ransom.Snatch.ACC673E7
McAfee-GW-EditionBehavesLike.Win32.TrojanWellMess.vc
SophosGeneric ML PUA (PUA)
GDataDeepScan:Generic.Ransom.Snatch.ACC673E7
JiangminTrojan.Generic.eqsvo
AviraHEUR/AGEN.1211756
MAXmalware (ai score=80)
MicrosoftProgram:Win32/Wacapew.C!ml
CynetMalicious (score: 100)
ALYacDeepScan:Generic.Ransom.Snatch.ACC673E7
MalwarebytesMalware.Heuristic.1003
APEXMalicious
SentinelOneStatic AI – Malicious PE
Cybereasonmalicious.108af2

How to remove Generic.Ransom.Snatch.ACC673E7?

Generic.Ransom.Snatch.ACC673E7 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment