Ransom Trojan

GenPack:Trojan.Ransom.ABZ (file analysis)

Malware Removal

The GenPack:Trojan.Ransom.ABZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What GenPack:Trojan.Ransom.ABZ virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Likely virus infection of existing system binary
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable UAC
  • Attempts to disable Windows Defender
  • Attempts to modify or disable Security Center warnings

Related domains:

z.whorecord.xyz
a.tomx.xyz
viweabkkfe.com
lscyqrjofqmtn.com
ltcfpuctidqqqxxzpikz.com
wowsfhnnvlwhlotryvh.com
linbzxpkmdtngnbdg.com
sjytgtnkdl.com
zkkfpkbbfnmihohix.com
vjuxtixi.com
ntrshvquunyzxevkucs.com
lxpcmncky.com
pjgnhujlmwtgf.com
pvqwziehrqscosb.com
qxcrbliabignczlmuc.com
okenhqzgxngnkbwouvfm.com
oismeark.com
bfgtwvhgsibiufmcerl.com
wxluitpliymeoirc.com
mzwfwjayhom.com
kvmihtamuopvagdlrwzg.com
rtlwqvhwuisfnery.com
xzfqmrfmyuaxs.com
xtvklujmo.com
dxkirxfzwhnnah.com
vyeaukkyszhdeug.com
kcubcfuhwwn.com
cpejcogzznpudbsmaxxm.com
zvwbjvhfrkqciz.com
pnqclaedmavju.com
kwsrmhroj.com
qwtzjokvjfvecysgypbd.com
avcctrnrxx.com
vgcdinjoj.com
towhyechciopdte.com
tmgskmvaxftffa.com
eiiveuuptweirgz.com
fryqhsblmvzsal.com
ohrpszrfydauhfuzyzbk.com
zbzxolintzi.com
fidkjesxq.com
owsxylebhmuzver.com
izaubgigwfl.com
yievjaklo.com
hqihrutpabwndvldae.com
nuepdkau.com
rjpkxiywinyhjoqltq.com
worazowxtkdznvvz.com
fzzxkhmkfunhotpjmdoy.com
kuyfpapjundhcit.com
nxcyhbauwgvdryyz.com
ajfdmjbywzibf.com

How to determine GenPack:Trojan.Ransom.ABZ?


File Info:

crc32: 39FDB3C8
md5: 7fb238f32b4e3804fd175d1a687d9611
name: 7FB238F32B4E3804FD175D1A687D9611.mlw
sha1: 2420bbc3b7352c57877622e2303bbe2b528d0796
sha256: 75052ca1cf9c295f631979d111d6be4a27c15426e00b215583c6b2128b184547
sha512: 4199bd264a2dad2f20cd4a702b02afe29ae346efa944d786642c0b757453617971316ab41f4b83aa6897899ca967c2d18027ca9063c99b434657185b33c7cc0f
ssdeep: 3072:YVOOJx1R5yAdd0cubb+gjPZ2KtjS+YIoBe5DE1Dx+IHIGLKnbFNOsKpjf:gOOtRrd0PyotjS+Yt9nHIGLINOHpr
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

GenPack:Trojan.Ransom.ABZ also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0044516f1 )
Elasticmalicious (high confidence)
DrWebTrojan.Winlock.9241
CynetMalicious (score: 100)
ALYacGenPack:Trojan.Ransom.ABZ
CylanceUnsafe
ZillyaTrojan.Blocker.Win32.63628
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Blocker.a54d0f7e
K7GWTrojan ( 0044516f1 )
Cybereasonmalicious.32b4e3
CyrenW32/Ransom.HTLL-8465
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.BH
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Swed-9757258-0
KasperskyTrojan-Ransom.Win32.Blocker.bqlz
BitDefenderGenPack:Trojan.Ransom.ABZ
NANO-AntivirusTrojan.Win32.Blocker.idkjzn
MicroWorld-eScanGenPack:Trojan.Ransom.ABZ
TencentWin32.Trojan.Raas.Auto
Ad-AwareGenPack:Trojan.Ransom.ABZ
SophosMal/Generic-R + Mal/TinyDL-T
ComodoMalware@#3c4s85tcyu0xi
BitDefenderThetaAI:Packer.1AB822821E
VIPRETrojan.Win32.Generic!BT
TrendMicroTROJ_DIRCRYPT.K
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.7fb238f32b4e3804
EmsisoftGenPack:Trojan.Ransom.ABZ (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Blocker.srq
AviraTR/Crypt.XPACK.Gen
MicrosoftRansom:Win32/Blocker
AegisLabTrojan.Win32.GenericCryptor.m5oU
GDataGenPack:Trojan.Ransom.ABZ
Acronissuspicious
McAfeeArtemis!7FB238F32B4E
MAXmalware (ai score=83)
VBA32Trojan.Agent
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_DIRCRYPT.K
RisingRansom.Blocker!8.12A (CLOUD)
YandexTrojan.Blocker!tZo7CxxVvcs
IkarusTrojan-Ransom.FileCrypter
FortinetW32/Blocker.BH!tr.ransom
AVGFileRepMalware
Paloaltogeneric.ml

How to remove GenPack:Trojan.Ransom.ABZ?

GenPack:Trojan.Ransom.ABZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment