Ransom

About “Ransom.ChiChi” infection

Malware Removal

The Ransom.ChiChi is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.ChiChi virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Enumerates running processes
  • Manipulates data from or to the Recycle Bin
  • A process created a hidden window
  • The binary contains an unknown PE section name indicative of packing
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Uses Windows utilities for basic functionality
  • Attempts to delete or modify volume shadow copies
  • Deletes its original binary from disk
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Writes a potential ransom message to disk
  • Uses suspicious command line tools or Windows utilities

How to determine Ransom.ChiChi?


File Info:

name: 9830F350BFE14307AFE4.mlw
path: /opt/CAPEv2/storage/binaries/98482d217a0817af06217d4f02fc8bc48b31b4636ab8ef870dd2ad5056e43aea
crc32: CDDDDDED
md5: 9830f350bfe14307afe43cece54cce43
sha1: 4dcdfb0cc4a5de60a570392aafad244eb16390ea
sha256: 98482d217a0817af06217d4f02fc8bc48b31b4636ab8ef870dd2ad5056e43aea
sha512: 4d15a13eb7ed8572aebe8b8b83cb02114a3a8c3c6bb56efc704723f44491a7ce5dd3b1d5af03d84284fdefef5631c09890f7ce8b43f6869d6ced8b0e6f23e0d6
ssdeep: 12288:ux/s63oVvgWw6ISiEl+OeO+OeNhBBhhBB3+58Eb56X024Y4n23eu/BQsNbRvQbR5:uU+6mp+58yDfn23eu5vdobI
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134E41823768ABCF6C47146B06B7BA7DAA32EEC140760C5EF62D81619587C0D33A327D5
sha3_384: 2d41e875507034c34634ec9891b3d803294dac8a5e619c8b137e2fddb6da117b00210a87e16c0bb0d20ffb4ea497aebf
ep_bytes: e854060000e98efeffff3b0d14304800
timestamp: 2021-11-19 09:20:11

Version Info:

0: [No Data]

Ransom.ChiChi also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
McAfeeRDN/Ransom
CylanceUnsafe
K7AntiVirusTrojan ( 005786171 )
AlibabaRansom:Win32/generic.ali2000010
K7GWTrojan ( 005786171 )
Cybereasonmalicious.0bfe14
CyrenW32/Trojan.LTZU-5687
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.Babyk.A
APEXMalicious
Paloaltogeneric.ml
KasperskyUDS:Trojan-Ransom.Win32.Generic
BitDefenderGen:Heur.Ransom.REntS.Gen.1
AvastFileRepMalware
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
SophosMal/Generic-S
DrWebTrojan.Encoder.34721
TrendMicroRansom_Babuk.R002C0DLB21
McAfee-GW-EditionBehavesLike.Win32.Generic.jh
FireEyeGeneric.mg.9830f350bfe14307
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
SentinelOneStatic AI – Malicious PE
GDataGen:Heur.Ransom.REntS.Gen.1
AviraHEUR/AGEN.1131199
Antiy-AVLTrojan/Generic.ASMalwS.34E9E3E
GridinsoftRansom.Win32.Gen.sa
ViRobotTrojan.Win32.Z.Rents.680960
MicrosoftRansom:Win32/Babuk.MAK!MTB
CynetMalicious (score: 100)
BitDefenderThetaGen:NN.ZexaF.34084.PCW@aGrehLji
ALYacTrojan.Ransom.Babuk
MAXmalware (ai score=88)
VBA32BScope.TrojanRansom.Gen
MalwarebytesRansom.ChiChi
TrendMicro-HouseCallRansom_Babuk.R002C0DLB21
TencentWin32.Trojan.Filecoder.Hsrw
YandexTrojan.Schoolboy!Hcot32erexU
eGambitUnsafe.AI_Score_100%
FortinetW32/Filecoder_Babyk.A!tr.ransom
AVGFileRepMalware
PandaTrj/GdSda.A
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.300983.susgen

How to remove Ransom.ChiChi?

Ransom.ChiChi removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment