Malware

Ranpack.3 (file analysis)

Malware Removal

The Ranpack.3 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ranpack.3 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Drops a binary and executes it
  • Performs some HTTP requests
  • Detects the presence of Wine emulator via function name
  • Detects Sandboxie through the presence of a library
  • Detects SunBelt Sandbox through the presence of a library
  • Attempts to remove evidence of file being downloaded from the Internet
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Operates on local firewall’s policies and settings
  • Creates a copy of itself
  • Attempts to disable System Restore
  • Attempts to modify or disable Security Center warnings
  • Anomalous binary characteristics

Related domains:

slpsrgpsrhojifdij.ru
sruhsuirghurhgud.ru
siusiehfusguiriu.ru
fsuesuuuesheuhfu.ru
rsiiuisuiuiuidui.ru
eeifiifigginsish.ru
eifusieuuusususu.ru
aiiiaiifhfugugud.ru
ueusifhsiheadhih.ru
unokaoeojoejfghr.ru
siiiifejijsirjgi.ru
aaiiaiaiaiishihg.ru
aaaaaaaofoofofgh.ru
ommmononafagoake.ru
iiiiaeieifihgihi.ru
aaaaaaaueieieiii.ru
aaaaaaaauhguhifi.ru
ollsorshsrhijfij.ru
koooooookoeoirif.ru
abucuabuheuahehu.ru
bbbuuusuuhisgijs.ru
ibseyhefrjifsrgg.ru
yuhujishruuhtuhu.ru
aaiiehiehueudhuh.ru
niursosokforhoht.ru
sruhsuirghurhgud.su
siusiehfusguiriu.su
fsuesuuuesheuhfu.su
rsiiuisuiuiuidui.su
eeifiifigginsish.su
eifusieuuusususu.su
aiiiaiifhfugugud.su
ueusifhsiheadhih.su
unokaoeojoejfghr.su
siiiifejijsirjgi.su
aaiiaiaiaiishihg.su
aaaaaaaofoofofgh.su
ommmononafagoake.su
iiiiaeieifihgihi.su
aaaaaaaueieieiii.su
aaaaaaaauhguhifi.su
ollsorshsrhijfij.su
koooooookoeoirif.su
abucuabuheuahehu.su
bbbuuusuuhisgijs.su
ibseyhefrjifsrgg.su
yuhujishruuhtuhu.su
aaiiehiehueudhuh.su
niursosokforhoht.su
sruhsuirghurhgud.net
siusiehfusguiriu.net
fsuesuuuesheuhfu.net
rsiiuisuiuiuidui.net
eeifiifigginsish.net
eifusieuuusususu.net
aiiiaiifhfugugud.net
ueusifhsiheadhih.net
unokaoeojoejfghr.net
siiiifejijsirjgi.net
aaiiaiaiaiishihg.net
aaaaaaaofoofofgh.net

How to determine Ranpack.3?


File Info:

crc32: 96120C07
md5: 06621b83a1f59d16442e014fa17e11f3
name: 06621B83A1F59D16442E014FA17E11F3.mlw
sha1: 7b0c073fc9249f20762076c9b43b74fba2171e9a
sha256: c8e44c53636fff2d99df4f54205b7bfaca2dbd41f17e0890a86cf923dbd8b81d
sha512: e3567835e9af9d540b46e4c4081624a6ea3d54c011f179e2e986d79d261d6ca5a38a407cc22826e2fa489f91f3f90f0ddee76e1906e22e6d3cebf92a3797a7a5
ssdeep: 1536:kUZBgxL3732cuw70i4U5BIKLddhB5b9+uHu9l1ifS8d4A3xNJ/:xB4LLmENjhB5iv8f1+AbJ
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright (C) 2017, whxofirr
InternalName: siyyajhi.ehi
FileVersion: 1.3.6
ProductVersion: 1.0.4.11

Ranpack.3 also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 00543e471 )
Elasticmalicious (high confidence)
DrWebTrojan.PWS.Siggen2.8759
CynetMalicious (score: 99)
CAT-QuickHealTrojan.Tiggre.S4565990
ALYacGen:Variant.Ranpack.3
CylanceUnsafe
ZillyaTrojan.Bayrob.Win32.33555
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaTrojan:Win32/Gandcrab.17638314
K7GWTrojan ( 00543e471 )
Cybereasonmalicious.3a1f59
CyrenW32/Kryptik.NH.gen!Eldorado
SymantecPacked.Generic.525
ESET-NOD32a variant of Win32/Kryptik.GNKP
APEXMalicious
AvastWin32:MalwareX-gen [Trj]
ClamAVWin.Packed.Chapak-7489442-0
KasperskyHEUR:Trojan.Win32.Zenpak.gen
BitDefenderGen:Variant.Ranpack.3
NANO-AntivirusTrojan.Win32.Bayrob.fkwffr
ViRobotTrojan.Win32.Agent.1532416
SUPERAntiSpywareRansom.GandCrab/Variant
MicroWorld-eScanGen:Variant.Ranpack.3
TencentMalware.Win32.Gencirc.116e4cf6
Ad-AwareGen:Variant.Ranpack.3
SophosMal/Generic-R + Mal/GandCrab-D
ComodoTrojWare.Win32.Ransom.Gandcrab.AO@7zf1nr
BitDefenderThetaGen:NN.ZexaF.34688.Du0@aWfnK3oe
VIPRETrojan.Win32.Generic!BT
TrendMicroTrojan.Win32.SODINOK.SM.hp
McAfee-GW-EditionBehavesLike.Win32.Multiplug.gz
FireEyeGeneric.mg.06621b83a1f59d16
EmsisoftTrojan.Crypt (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Chapak.aez
AviraTR/Patched.Ren.Gen
MicrosoftTrojan:Win32/Gandcrab.VRD!MTB
AegisLabTrojan.Win32.Zenpak.4!c
GDataGen:Variant.Ranpack.3
TACHYONTrojan/W32.Crypted.479744
AhnLab-V3Win-Trojan/MalPe4.Suspicious.X1939
McAfeePacked-FPI!06621B83A1F5
MAXmalware (ai score=85)
VBA32BScope.Trojan.Fuery
MalwarebytesTrojan.MalPack.GS
PandaTrj/CI.A
TrendMicro-HouseCallTrojan.Win32.SODINOK.SM.hp
RisingTrojan.Kryptik!1.B50A (CLOUD)
YandexTrojan.GenAsa!BKyIT5Zap9k
IkarusTrojan.Win32.Gandcrab
FortinetW32/GenKryptik.CUPF!tr
AVGWin32:MalwareX-gen [Trj]
Paloaltogeneric.ml

How to remove Ranpack.3?

Ranpack.3 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment