Ransom

About “Ransom.Babuk.67” infection

Malware Removal

The Ransom.Babuk.67 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Babuk.67 virus can do?

  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Manipulates data from or to the Recycle Bin
  • Authenticode signature is invalid
  • Exhibits possible ransomware file modification behavior
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools

How to determine Ransom.Babuk.67?


File Info:

name: 5BCED01ECD212F07450A.mlw
path: /opt/CAPEv2/storage/binaries/1b7a5caa591627cb8c94e348781f62a82811eee44c2cd36a85dcb1fc44a2108a
crc32: F35A498C
md5: 5bced01ecd212f07450a78de579770b4
sha1: 23ed71c8800d6b06581fb13ac79844f34cde1064
sha256: 1b7a5caa591627cb8c94e348781f62a82811eee44c2cd36a85dcb1fc44a2108a
sha512: 6a108d4fd1aed7f46a80574bedb7df41031b1a48e3f7ff23586ea5d70521f578870e85c89533f692b7952f4d7dd0615f7f41490823235eef9c4b16df32ce5c13
ssdeep: 1536:WwG6++mq1sA1jB5gJsifsrQLOJgY8ZZP8LHD4XWaNH71dLdG1iiFM2iG2xyqM8En:jf++mqOAhB5gJtsrQLOJgY8Zp8LHD4Xr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1CB6385116B45E6B6D5912170811BF1B6C23A097003F162A7A7C11BBBFB256B8F27DF23
sha3_384: ea35b811590ae228219a259a6e8eef17c3dd207b764bd3c249e83e8ad065a03e225cac45408d7c9e3eac14c7bc56a2d6
ep_bytes: 558bec81ec94000000a1a410410033c5
timestamp: 2022-05-05 13:45:58

Version Info:

0: [No Data]

Ransom.Babuk.67 also known as:

BkavW32.AIDetect.malware2
MicroWorld-eScanGen:Variant.Ransom.Babuk.67
FireEyeGeneric.mg.5bced01ecd212f07
ALYacGen:Variant.Ransom.Babuk.67
VIPREGen:Variant.Ransom.Babuk.67
Cybereasonmalicious.ecd212
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
APEXMalicious
ClamAVWin.Ransomware.Packer-7473772-1
BitDefenderGen:Variant.Ransom.Babuk.67
AvastWin32:RansomX-gen [Ransom]
Ad-AwareGen:Variant.Ransom.Babuk.67
McAfee-GW-EditionBehavesLike.Win32.Upatre.km
EmsisoftGen:Variant.Ransom.Babuk.67 (B)
SentinelOneStatic AI – Suspicious PE
GDataGen:Variant.Ransom.Babuk.67
JiangminGeneric.Ransom.b
AviraTR/Dropper.Gen
ArcabitTrojan.Ransom.Babuk.67
MicrosoftRansom:Win32/Babuk.ECCP!MTB
CynetMalicious (score: 100)
AhnLab-V3Ransomware/Win.Maze.R473427
McAfeeGenericRXQL-KE!5BCED01ECD21
MAXmalware (ai score=88)
VBA32BScope.Trojan.Encoder
MalwarebytesMalware.AI.3155384457
RisingTrojan.Generic@AI.97 (RDML:4WZraxOcNLqw/o4esjJF8A)
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Babuk.KE!tr.ransom
BitDefenderThetaAI:Packer.55BF964A1E
AVGWin32:RansomX-gen [Ransom]
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_70% (D)

How to remove Ransom.Babuk.67?

Ransom.Babuk.67 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment