Ransom

What is “Ransom.BlackMoon”?

Malware Removal

The Ransom.BlackMoon is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.BlackMoon virus can do?

  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Attempts to modify desktop wallpaper
  • Creates a hidden or system file
  • Network activity detected but not expressed in API logs

How to determine Ransom.BlackMoon?


File Info:

crc32: BC30B02C
md5: a0d418e31766effadc6a37e81ad21743
name: A0D418E31766EFFADC6A37E81AD21743.mlw
sha1: 9ec2753f1a123fcd42d95811e1f3b27547b215d0
sha256: 6caa53b30e5a22779b159d7bdef67f66aea567b6f93360c3c79b6a2d5a37e9a5
sha512: f11160a126b865e561cd1fc99b5bf25a52bfb0be14fb709ba012a045b26f585456f7f55d2d0a3b5d754e1512771b89d768e40718589fc9c9a16b30c2a07dda74
ssdeep: 3072:PDFwsTEaWvmd7yllkX2qSjtNbpcRcFHwOa:PJwwdWtllEdS3dQO
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.BlackMoon also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00566a451 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.31816
CynetMalicious (score: 100)
ALYacTrojan.Ransom.Filecoder
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.14887
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Filecoder.1e042f1f
K7GWTrojan ( 00566a451 )
Cybereasonmalicious.31766e
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OCB
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.wvl
BitDefenderGen:Heur.Mint.Zard.46
NANO-AntivirusTrojan.Win32.Encoder.hkhqdh
MicroWorld-eScanGen:Heur.Mint.Zard.46
TencentMalware.Win32.Gencirc.1170c559
Ad-AwareGen:Heur.Mint.Zard.46
SophosGeneric ML PUA (PUA)
ComodoTrojWare.Win32.BlackMoon.R@8c1vff
BitDefenderThetaGen:NN.ZexaF.34738.mqW@aKp4VKnb
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom.Win32.BLACKMOON.A
McAfee-GW-EditionBehavesLike.Win32.Dropper.ch
FireEyeGeneric.mg.a0d418e31766effa
EmsisoftGen:Heur.Mint.Zard.46 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Gen.azp
WebrootW32.Malware.Gen
AviraTR/FileCoder.lbjnh
eGambitUnsafe.AI_Score_99%
MicrosoftTrojan:Win32/Occamy.C6C
ArcabitTrojan.Mint.Zard.46
AegisLabTrojan.Win32.Graftor.4!c
ZoneAlarmTrojan-Ransom.Win32.Gen.wvl
GDataGen:Heur.Mint.Zard.46
TACHYONRansom/W32.BlackMoon.200704
McAfeeArtemis!A0D418E31766
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Genasom
MalwarebytesRansom.BlackMoon
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom.Win32.BLACKMOON.A
RisingTrojan.Generic@ML.99 (RDML:fizZNe/UUGY+h9TVkM3Q4Q)
YandexTrojan.Filecoder!W70McAgpWjs
IkarusPUA.BlackMoon
MaxSecureTrojan.Malware.101236308.susgen
FortinetW32/CoinMiner.ESFJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Ransom.BlackMoon?

Ransom.BlackMoon removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment