Malware

Johnnie.270524 removal tips

Malware Removal

The Johnnie.270524 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Johnnie.270524 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Drops a binary and executes it
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to identify installed AV products by installation directory
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
iplogger.org
a.tomx.xyz
wushupalace.top

How to determine Johnnie.270524?


File Info:

crc32: E9781536
md5: f25064e3106e8ce869b1d6cea1145166
name: F25064E3106E8CE869B1D6CEA1145166.mlw
sha1: 67212c1c7682399dc662dacca64e4be561dea29c
sha256: 2017dbcd4a518b53e7c7c6aaa3028c01ce9a3cde29015dd3d3d0ef0c5a93251e
sha512: fc6fc5cc3699bb95a806fa887a99ee01be0b2760b4ba34aa46ad0cd38a0e07b304d1527e93724a690ebd812b1223d69fa86d8423379f1252a671227eef218878
ssdeep: 12288:3kHaoYw9u8P9vzqeiRcXCQoYIIrbn35mKMW54+nX+i60VgwX6ZybyA:VoYv89NxFoY3rj5mVUTnXvlVgwX6K7
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Johnnie.270524 also known as:

Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Stop.Z5
ALYacGen:Variant.Johnnie.270524
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.3106e8
SymantecPacked.Generic.620
APEXMalicious
AvastFileRepMalware
KasperskyUDS:Trojan-Spy.Win32.Stealer.gen
BitDefenderGen:Variant.Johnnie.270524
MicroWorld-eScanGen:Variant.Johnnie.270524
Ad-AwareGen:Variant.Johnnie.270524
SophosML/PE-A
McAfee-GW-EditionBehavesLike.Win32.Generic.jc
FireEyeGeneric.mg.f25064e3106e8ce8
EmsisoftGen:Variant.Johnnie.270524 (B)
SentinelOneStatic AI – Malicious PE
MicrosoftTrojan:Win32/Sabsik.FL.A!ml
GDataGen:Variant.Johnnie.270524
Acronissuspicious
McAfeePacked-GDT!F25064E3106E
MAXmalware (ai score=83)
VBA32BScope.Trojan.AET.281105
RisingTrojan.Kryptik!1.D975 (CLASSIC)
IkarusTrojan.Win32.Azorult
MaxSecureTrojan.Malware.300983.susgen
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Johnnie.270524?

Johnnie.270524 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment