Ransom

Ransom.GandCrab.283 (file analysis)

Malware Removal

The Ransom.GandCrab.283 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.GandCrab.283 virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine Ransom.GandCrab.283?


File Info:

name: 0F1F44DC14F14ED6BB5D.mlw
path: /opt/CAPEv2/storage/binaries/2fc1d64b8c2f7d635706782039939dfd472c253c830acec11ab528e4b28839e7
crc32: A2C2CBEB
md5: 0f1f44dc14f14ed6bb5d8f2de05918d0
sha1: fe1730799422a11bc55065f4db3eb5b68a6812f3
sha256: 2fc1d64b8c2f7d635706782039939dfd472c253c830acec11ab528e4b28839e7
sha512: ffe11a16ffaf16f1de05cb13fa391a9c02035ec25db1f581f209a051559019d3c6ec5403bb33efb6472c9a490868d66e94f3418d9e7968e5594d4a1f294350b2
ssdeep: 768:CT8xWttITWURE7jrejzT7wlrNNK9cujcdu2c0BdOS:CT86SWaEMQlqcujcdNL
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T16AE3090476E6C4F1E4B6463688F0A6118BBD7C529E34AE9B73D4224E1EF14E0A670F67
sha3_384: 42bf2c9425784ed4e565a50f3973b862a4b31c072cff54cf957684be94f53c4f211c4ff440d103e31c28c7e9bea83ae3
ep_bytes: e873120000e97bfeffff3b0d50101e01
timestamp: 2018-04-12 20:41:02

Version Info:

0: [No Data]

Ransom.GandCrab.283 also known as:

BkavW32.AIDetect.malware1
LionicHeuristic.File.Generic.00×1!p
MicroWorld-eScanGen:Variant.Ransom.GandCrab.283
FireEyeGeneric.mg.0f1f44dc14f14ed6
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Ransom.GandCrab.283
CylanceUnsafe
SangforRansom.Win32.GandCrab.Vx2t
AlibabaMalware:Win32/km_24a63.None
Cybereasonmalicious.c14f14
BitDefenderThetaGen:NN.ZexaF.34646.iqW@amE14ei
CyrenW32/Kryptik.HKH.gen!Eldorado
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Kryptik.GXKS
Paloaltogeneric.ml
KasperskyVHO:Trojan.Win32.Exnet.gen
BitDefenderGen:Variant.Ransom.GandCrab.283
CynetMalicious (score: 100)
AvastWin32:RansomX-gen [Ransom]
TencentTrojan.Win32.Chapak.waa
Ad-AwareGen:Variant.Ransom.GandCrab.283
EmsisoftGen:Variant.Ransom.GandCrab.283 (B)
VIPREGen:Variant.Ransom.GandCrab.283
TrendMicroRansom_GandCrab.R002C0DI522
McAfee-GW-EditionBehavesLike.Win32.Backdoor.cz
SentinelOneStatic AI – Suspicious PE
Trapminemalicious.moderate.ml.score
APEXMalicious
GDataGen:Variant.Ransom.GandCrab.283
AviraTR/ATRAPS.Gen4
MAXmalware (ai score=87)
ArcabitTrojan.Ransom.GandCrab.283
MicrosoftRansom:Win32/GandCrab!rfn
GoogleDetected
AhnLab-V3Malware/Win32.Generic.C2472080
McAfeeRansom-Gandcrab!0F1F44DC14F1
MalwarebytesMachineLearning/Anomalous.100%
RisingRansom.GandCrab!8.F355 (TFE:5:NRlxbhHiS1V)
YandexTrojan.GenAsa!io/7GV0G8eE
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/GandCrab.B!tr
AVGWin32:RansomX-gen [Ransom]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom.GandCrab.283?

Ransom.GandCrab.283 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment