Ransom

Mal/Ransom-BZ (file analysis)

Malware Removal

The Mal/Ransom-BZ is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Mal/Ransom-BZ virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Mal/Ransom-BZ?


File Info:

name: DF32362FAB6CB3BE1CF0.mlw
path: /opt/CAPEv2/storage/binaries/50ce1ef4d7931d647d2dfa6a6d684ff1b377645aba17c0776b5dca72073421f9
crc32: 8D62C565
md5: df32362fab6cb3be1cf04bcadf0de9c7
sha1: e282d0eddea83ad36c796962adf341d19ef03402
sha256: 50ce1ef4d7931d647d2dfa6a6d684ff1b377645aba17c0776b5dca72073421f9
sha512: 4a94f861122672b5dee7b89bbd07fd0d510f0cc14fb64caed501b6d50852affc8a4c6ab2dd8ffd92a6bbdf8fef18e2d8132ddd2aa5bbe54e1e6f835c5706ea62
ssdeep: 12288:gggZ8iH5Pbd3bik6cT0MPJdpY6qVD6G8Jsyq0Sy22qw4Ea3YgsKn7nRa:++4tbipCFS6qVD6GEsyqJ14a3rn9a
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T106A4AC107942E436F92B127E8FABC5DA4249BC52DF3245E736E12F8F4A763D29631342
sha3_384: 92dd82a1882c2bf5649c18ece4425ca144972a98d4e1d2ed5277c48d54b8284408350204818436b8ccab7c121eaf650e
ep_bytes: e88c660000e916feffff5153555657ff
timestamp: 2013-08-30 11:58:49

Version Info:

CompanyName: Feed Inc.
FileDescription: Feed Exacttime
FileVersion: 11.0.526.698 love
InternalName: else.exe
LegalCopyright: (c) Feed. All rights reserved.
LegalTrademarks: Feed Corporation. All rights reserved.
OriginalFilename: else.exe
ProductName: Feed Exacttime
ProductVersion: 11.0.526.698
Translation: 0x047f 0x04e4

Mal/Ransom-BZ also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zbot.l!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Trojan.Crypt.63
ClamAVWin.Trojan.Zbot-58951
FireEyeGeneric.mg.df32362fab6cb3be
CAT-QuickHealTrojanPWS.Zbot.Y
SkyhighBehavesLike.Win32.Infected.gh
McAfeeGenericATG-FHB!DF32362FAB6C
Cylanceunsafe
ZillyaTrojan.Zbot.Win32.135469
SangforTrojan.Win32.ZPACK.Gen8
K7AntiVirusRiskware ( 0040eff71 )
AlibabaTrojanSpy:Win32/Generic.8795d112
K7GWRiskware ( 0040eff71 )
CrowdStrikewin/malicious_confidence_100% (D)
BitDefenderThetaGen:NN.ZexaF.36744.Cu0@aC!!ilcG
VirITTrojan.Win32.Banker.WK
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32Win32/Spy.Zbot.AAU
APEXMalicious
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Spy.Win32.Zbot.pef
BitDefenderGen:Variant.Trojan.Crypt.63
NANO-AntivirusTrojan.Win32.Zbot.cmholp
AvastWin32:Malware-gen
RisingSpyware.Zbot!8.16B (TFE:5:Uh2521ZfBQP)
TACHYONTrojan-Spy/W32.ZBot.471040.AA
EmsisoftGen:Variant.Trojan.Crypt.63 (B)
F-SecureTrojan.TR/Crypt.ZPACK.Gen8
DrWebTrojan.PWS.Panda.4379
VIPREGen:Variant.Trojan.Crypt.63
Trapminemalicious.high.ml.score
SophosMal/Ransom-BZ
IkarusTrojan-PWS.Win32.Zbot
GDataGen:Variant.Trojan.Crypt.63
JiangminTrojanSpy.Zbot.dtje
WebrootW32.InfoStealer.Zeus
GoogleDetected
AviraTR/Crypt.ZPACK.Gen8
Antiy-AVLTrojan[Spy]/Win32.Zbot
KingsoftWin32.Trojan-Spy.Zbot.pef
XcitiumTrojWare.Win32.Spy.Zbot.OZX@52f0i6
ArcabitTrojan.Trojan.Crypt.63
ZoneAlarmHEUR:Trojan-Spy.Win32.Zbot.pef
MicrosoftPWS:Win32/Zbot
VaristW32/Zbot.NS.gen!Eldorado
AhnLab-V3Spyware/Win32.Zbot.R82186
ALYacGen:Variant.Trojan.Crypt.63
MAXmalware (ai score=100)
VBA32TrojanSpy.Zbot
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10b16d74
YandexTrojan.GenAsa!CHqlL+8pVB4
SentinelOneStatic AI – Malicious PE
FortinetW32/KRYPTIK.PDA!tr
AVGWin32:Malware-gen
Cybereasonmalicious.ddea83
DeepInstinctMALICIOUS

How to remove Mal/Ransom-BZ?

Mal/Ransom-BZ removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment