Ransom

What is “Ransom.Loki.3353”?

Malware Removal

The Ransom.Loki.3353 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Loki.3353 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Performs HTTP requests potentially not found in PCAP.
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Tswana
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom.Loki.3353?


File Info:

name: EF799B5261FD69B56C8B.mlw
path: /opt/CAPEv2/storage/binaries/3c280f4b81ca4773f89dc4882c1c1e50ab1255e1975372109b37cf782974e96f
crc32: ED8B04DE
md5: ef799b5261fd69b56c8b70a3d22d5120
sha1: 65b43bfe8a5f2481d70b76ebd543b9f5b4baa0f6
sha256: 3c280f4b81ca4773f89dc4882c1c1e50ab1255e1975372109b37cf782974e96f
sha512: 02bf6df85b0df92047dd6b2fb24148486d531a80945bb7e7e1ee5d1da28a992d26f7f3111ae1994e76ca6c4685b6e4aa7707516a19dd0ee6beb6951ae64041fb
ssdeep: 3072:zy//ypzPN5mJg0uZHZ045x+HVLSQEOJHsMFlH1IJLB:zy/IlEPeAz5JH7rVI
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EE04AD2135D0C472C7B61530A427CBE45A7AF8F36A7C498777983B7E7E202C446B639A
sha3_384: 8c5b5eada2ee72fd067f7ec6687dfabaea9764fa858d152a1070a5e7c4045508fdc6c31d21d4895b993912eef08882c0
ep_bytes: e81e490000e978feffffcccccc8b4c24
timestamp: 2020-11-21 14:57:28

Version Info:

InternalName: sojbmoeminu.ihe
Copyright: Copyrighz (C) 2021, fudkagata
ProductVersion: 8.19.590.38
Translation: 0x0129 0x0171

Ransom.Loki.3353 also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Zenpak.4!c
tehtrisGeneric.Malware
MicroWorld-eScanGen:Variant.Ransom.Loki.3353
SkyhighBehavesLike.Win32.Lockbit.ch
McAfeeLockbit-FSWW!EF799B5261FD
Cylanceunsafe
VIPREGen:Variant.Ransom.Loki.3353
SangforRansom.Win32.Save.a
K7AntiVirusTrojan ( 005894161 )
AlibabaTrojan:Win32/Tnega.1a44f275
K7GWTrojan ( 005894161 )
Cybereasonmalicious.e8a5f2
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32Win32/Rozena.ABP
APEXMalicious
ClamAVWin.Packed.Generic-9894234-0
KasperskyHEUR:Trojan.Win32.Zenpak.pef
BitDefenderGen:Variant.Ransom.Loki.3353
AvastWin32:PWSX-gen [Trj]
TencentTrojan.Win32.Tofsee.xb
EmsisoftGen:Variant.Ransom.Loki.3353 (B)
F-SecureHeuristic.HEUR/AGEN.1318253
DrWebTrojan.MulDrop23.57816
ZillyaTrojan.Kryptik.Win32.3488576
TrendMicroTROJ_FRS.0NA103IM21
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.ef799b5261fd69b5
SophosTroj/Krypt-BO
SentinelOneStatic AI – Malicious PE
MAXmalware (ai score=100)
GDataGen:Variant.Ransom.Loki.3353
JiangminTrojan.Chapak.och
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1318253
VaristW32/Kryptik.LGA.gen!Eldorado
Antiy-AVLTrojan/Win32.Kryptik
Kingsoftmalware.kb.a.997
ArcabitTrojan.Ransom.Loki.DD19
ZoneAlarmHEUR:Trojan.Win32.Zenpak.pef
MicrosoftTrojan:Win32/Tnega!MSR
CynetMalicious (score: 100)
AhnLab-V3CoinMiner/Win.Glupteba.R441747
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36744.lq0@aKpjyqfO
ALYacTrojan.Agent.CobaltStrike
VBA32BScope.Trojan.Azorult
MalwarebytesGeneric.Malware.AI.DDS
PandaTrj/GdSda.A
TrendMicro-HouseCallTROJ_FRS.0NA103IM21
RisingTrojan.Kryptik!1.D9B3 (CLASSIC)
IkarusTrojan.Win32.Crypt
MaxSecureTrojan.Malware.73832973.susgen
FortinetW32/GenKryptik.FLKL!tr
AVGWin32:PWSX-gen [Trj]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom.Loki.3353?

Ransom.Loki.3353 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment