Ransom

About “Ransom.Hanta.1” infection

Malware Removal

The Ransom.Hanta.1 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Hanta.1 virus can do?

  • The binary likely contains encrypted or compressed data.
  • Network activity detected but not expressed in API logs
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Hanta.1?


File Info:

crc32: 0DF1B927
md5: 200f3f76865550af61768f809a975ded
name: 200F3F76865550AF61768F809A975DED.mlw
sha1: 323c8c69f3c0116286c1ac547c1f875858f777df
sha256: bd01582ffd4db33539ebe7eb733e3825d429729348d41a64ce14b7d7d7cdc12a
sha512: ee04c1f2a69f27b98101acef39d31eff564333799851effa145c91c69def9dad3035275559f5ed578cab9a712e2c00d43915fd986ef2371eebc6a7a187ac88de
ssdeep: 12288:7h3BpyqFiNd9RxbF6VnGSW1u0LZrN/ptfTd3kmnq45Z/G+QkBWliGc4uvJbxADo:7hehF61GfM0LbpVT1k6VKsci/vJbt
type: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

Translation: 0x0000 0x04b0
LegalCopyright: Copyright xa9 2021
Assembly Version: 1.0.0.0
InternalName: hanta_2_0_offline.exe
FileVersion: 1.0.0.0
CompanyName:
LegalTrademarks:
Comments:
ProductName: hanta_2_0
ProductVersion: 1.0.0.0
FileDescription: hanta_2_0
OriginalFilename: hanta_2_0_offline.exe

Ransom.Hanta.1 also known as:

K7AntiVirusTrojan ( 0057bcd91 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacTrojan.Ransom.HiddenTear
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:MSIL/Generic.5a880e39
K7GWTrojan ( 0057bcd91 )
Cybereasonmalicious.9f3c01
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of MSIL/Packed.Confuser.EB
APEXMalicious
AvastFileRepMalware
KasperskyHEUR:Trojan.MSIL.Agent.gen
BitDefenderGen:Variant.Ransom.Hanta.1
MicroWorld-eScanGen:Variant.Ransom.Hanta.1
TencentMsil.Trojan.Agent.Hlxv
Ad-AwareGen:Variant.Ransom.Hanta.1
SophosML/PE-A
BitDefenderThetaGen:NN.ZemsilF.34688.Yu0@ayTlFgh
FireEyeGeneric.mg.200f3f76865550af
EmsisoftGen:Variant.Ransom.Hanta.1 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Agent.uckvm
eGambitUnsafe.AI_Score_98%
MicrosoftTrojan:Win32/AgentTesla!ml
GridinsoftTrojan.Heur!.030130A1
ArcabitTrojan.Ransom.Hanta.1
AegisLabTrojan.MSIL.Agent.4!c
GDataGen:Variant.Ransom.Hanta.1
AhnLab-V3Ransomware/Win.MSIL.C4448857
McAfeeRDN/Ransom
MAXmalware (ai score=82)
VBA32CIL.HeapOverride.Heur
MalwarebytesRansom.Hanta
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_GEN.R002H09E421
RisingTrojan.Agent!8.B1E (CLOUD)
IkarusTrojan.MSIL.Agent
FortinetW32/Agent!tr
AVGFileRepMalware
Paloaltogeneric.ml

How to remove Ransom.Hanta.1?

Ransom.Hanta.1 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment