Adware Reports malware removal guides and threat research Updated security instructions for Windows users
Threat report

Ransom.Loki.9408 malicious file

Published Apr 15, 2024 Ransom category 3 min read
Report context

What to verify before removal

Ransom.Loki.9408 malicious file should be handled as a recovery-sensitive report, not as a routine deletion task. Before removing files, isolate the affected system and compare the detection with the notes below so encrypted data, restore points, and backups are not damaged.

Start by comparing the local file name with 51E6E54008DEFA9ED2A5.mlw, then review the behavior notes for file-encryption activity, ransom notes, renamed documents, and unexpected recovery blockers. This helps separate a matching detection from a different file that only shares a similar alert name.

Observed file
51E6E54008DEFA9ED2A5.mlw
  • Compare the suspicious file name with 51E6E54008DEFA9ED2A5.mlw.
  • Confirm the detection name matches Ransom.Loki.9408 malicious file before removing related files.
  • Review the report for file-encryption activity, ransom notes, renamed documents, and unexpected recovery blockers so the cleanup is based on observed behavior, not only the label.
  • Disconnect the machine from the network before recovery work and avoid deleting encrypted samples until backups are checked.

The Ransom.Loki.9408 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

What Ransom.Loki.9408 virus can do?

  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid

How to determine Ransom.Loki.9408?


File Info:

name: 51E6E54008DEFA9ED2A5.mlw
path: /opt/CAPEv2/storage/binaries/cf1b9dcc7e8a2d87873d68c31fa7328fb5dc914e10ca0bf7bae6353e12fec3e7
crc32: FE632BB8
md5: 51e6e54008defa9ed2a5d9683b361fa8
sha1: 0bda9105048cb509325ab3313bd81f53dfb46e77
sha256: cf1b9dcc7e8a2d87873d68c31fa7328fb5dc914e10ca0bf7bae6353e12fec3e7
sha512: ac97245ceaa31835d79a64b155d1c6bf829b8ee0d23ca31b4abc0ab9e8c08d43ce6fd28fbac5f556247849e63b10eedb482e80f8860b6637f3f5bf05610ac3d4
ssdeep: 12288:wh7VUCcq5HCPIF9IM2eXuz6cnYus3DOKg9FhAKQgpq:Rfq5iPItuz6cYukOKgDh7pq
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T134B41290CD155D42C6BEDFB32C334A888F7E37D2C976D6D8190871D9E8E7201B986BA4
sha3_384: 025dd50dd1c75c14d731071cfbaf1f55e25b44c0aec023aaca6db5349f22a6c35b916d247965d37de9f3df77fb9af0e6
ep_bytes: ff250020400000000000000000000000
timestamp: 2022-10-25 01:55:42

Version Info:

Translation: 0x0000 0x04b0
Comments: Anchor
CompanyName: Oklahoma Tire & Supply Company
FileDescription: YASAT
FileVersion: 12.0.0.0
InternalName: WaQ.exe
LegalCopyright: Oklahoma Tire & Supply Company 2022
LegalTrademarks:
OriginalFilename: WaQ.exe
ProductName: YASAT
ProductVersion: 12.0.0.0
Assembly Version: 12.0.0.0

Ransom.Loki.9408 also known as:

Bkav W32.AIDetectMalware.CS
Elastic malicious (high confidence)
DrWeb Trojan.MulDrop21.4939
MicroWorld-eScan Gen:Variant.Ransom.Loki.9408
FireEye Generic.mg.51e6e54008defa9e
CAT-QuickHeal Trojan.Generic.TRFH526
Skyhigh BehavesLike.Win32.Generic.hc
ALYac Gen:Variant.Ransom.Loki.9408
Cylance unsafe
Sangfor Phishing.Win32.Save.DotNet
CrowdStrike win/malicious_confidence_100% (W)
Alibaba TrojanPSW:MSIL/Agensla.35122a5a
K7GW Riskware ( 00584baa1 )
K7AntiVirus Riskware ( 00584baa1 )
BitDefenderTheta Gen:NN.ZemsilF.36802.Gm0@aiOYMpl
VirIT Trojan.Win32.MSIL_Heur.A
Symantec Scr.Malcode!gdn34
ESET-NOD32 a variant of MSIL/Kryptik.AGVX
APEX Malicious
ClamAV Win.Dropper.Nanocore-9976124-0
Kaspersky HEUR:Trojan-PSW.MSIL.Agensla.gen
BitDefender Gen:Variant.Ransom.Loki.9408
NANO-Antivirus Trojan.Win32.Swotter.jtlqhd
Avast Win32:PWSX-gen [Trj]
Tencent Malware.Win32.Gencirc.13b95b8c
Emsisoft Gen:Variant.Ransom.Loki.9408 (B)
Google Detected
F-Secure Heuristic.HEUR/AGEN.1308783
VIPRE Gen:Variant.Ransom.Loki.9408
Trapmine malicious.moderate.ml.score
Sophos Troj/Tesla-BZR
Ikarus Trojan.Inject
Varist W32/MSIL_Kryptik.IFS.gen!Eldorado
Avira HEUR/AGEN.1308783
Antiy-AVL Trojan/MSIL.Kryptik
Microsoft Trojan:MSIL/AgentTesla.GBX!MTB
Arcabit Trojan.Ransom.Loki.D24C0
ZoneAlarm HEUR:Trojan-PSW.MSIL.Agensla.gen
GData Gen:Variant.Ransom.Loki.9408
AhnLab-V3 Trojan/Win.PWSX-gen.C5286161
McAfee RDN/Generic PWS.y
MAX malware (ai score=83)
VBA32 OScope.TrojanDropper.MSIL.Agent
Malwarebytes Generic.Malware.AI.DDS
Panda Trj/Chgt.AA
Rising Malware.Obfus/MSIL@AI.100 (RDM.MSIL2:Ok5U6H6+Wk2OWuIkBUVwQg)
SentinelOne Static AI – Suspicious PE
MaxSecure Trojan.Malware.300983.susgen
Fortinet MSIL/GenKryptik.GDOV!tr
AVG Win32:PWSX-gen [Trj]
DeepInstinct MALICIOUS

How to remove Ransom.Loki.9408?

Recommended second-opinion scan

Verify the infection before changing system settings

Use GridinSoft Anti-Malware to run a full scan, review detected persistence entries, and quarantine confirmed threats before restarting Windows.

Download GridinSoft Anti-Malware
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.