Ransom

Ransom.BlackRuby information

Malware Removal

The Ransom.BlackRuby is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.BlackRuby virus can do?

  • Executable code extraction
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Unusual version info supplied for binary

Related domains:

freegeoip.net
github.com

How to determine Ransom.BlackRuby?


File Info:

crc32: 2CC272EE
md5: 7df8c61f053ed2c09741dd45acf922b4
name: 7DF8C61F053ED2C09741DD45ACF922B4.mlw
sha1: 6accc38be7fb264c24ff0b63940f990b1360844a
sha256: c625af92afe494e9373406a3f437ff6fea0b40158bc75cddca5b6e89202603d6
sha512: 729f7a54cd4e7f14c32cb22622f1786502d319eab26b102341c163ac2fab1b9bfa3542f31f7b045b37e35ad279b0b2358c5a1dccb989af4ce322a7433f5eaf22
ssdeep: 768:GpvZ5dLkTA3W0yLcroacjIm0rZz9KVViQrGrpJwtoGL06mi6zzrgCDxgiQhI6Is:668aLcDz/KVViOGkt0JoC1giOp
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 Microsoft all right reserved
Assembly Version: 4.10.19.120
InternalName: Windows Defender.exe
FileVersion: 4.10.19.120
CompanyName:
LegalTrademarks:
Comments: Microsoft Windows Defender Service
ProductName: Microsoft Windows Defender
ProductVersion: 4.10.19.120
FileDescription: Microsoft Windows Defender
OriginalFilename: Windows Defender.exe

Ransom.BlackRuby also known as:

K7AntiVirusTrojan ( 005260861 )
LionicTrojan.Win32.Sysn.4!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.24772
CynetMalicious (score: 99)
ALYacDeepScan:Generic.Ransom.Hiddentear.A.D078EDE2
CylanceUnsafe
ZillyaDropper.Sysn.Win32.7361
SangforTrojan.Win32.Save.a
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 005260861 )
Cybereasonmalicious.f053ed
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Dropper.Win32.Sysn.cips
BitDefenderDeepScan:Generic.Ransom.Hiddentear.A.D078EDE2
NANO-AntivirusTrojan.Win32.Sysn.eymawt
MicroWorld-eScanDeepScan:Generic.Ransom.Hiddentear.A.D078EDE2
TencentWin32.Trojan.Raas.Auto
Ad-AwareDeepScan:Generic.Ransom.Hiddentear.A.D078EDE2
SophosMal/Generic-S + Mal/Infitear-A
ComodoMalware@#39auubd26olnh
BitDefenderThetaGen:NN.ZemsilF.34058.em0@aSsGqai
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionRansomware-GJQ!7DF8C61F053E
FireEyeDeepScan:Generic.Ransom.Hiddentear.A.D078EDE2
EmsisoftTrojan.Agent (A)
SentinelOneStatic AI – Suspicious PE
JiangminTrojanDropper.Sysn.edt
WebrootW32.Trojan.Gen
AviraTR/FileCoder.dxckl
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan[Dropper]/Win32.Sysn
ZoneAlarmTrojan-Dropper.Win32.Sysn.cips
MicrosoftRansom:MSIL/Encruby
VBA32TrojanDropper.Sysn
MAXmalware (ai score=98)
MalwarebytesRansom.BlackRuby
PandaTrj/GdSda.A
YandexTrojan.DR.Sysn!fE1fzFZ83xQ
IkarusTrojan-Ransom.FileCrypter
FortinetMSIL/InfiniteTear.C!tr.ransom
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/TrojanDropper.Sysn.HgIASQ0A

How to remove Ransom.BlackRuby?

Ransom.BlackRuby removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment