Ransom

Ransom.Samsam.8 (file analysis)

Malware Removal

The Ransom.Samsam.8 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Samsam.8 virus can do?

  • Network activity detected but not expressed in API logs

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom.Samsam.8?


File Info:

crc32: D761493A
md5: 2eb524a9526bc681de1ed8d8989d044d
name: 2EB524A9526BC681DE1ED8D8989D044D.mlw
sha1: 232ae6cf35825771af8e4345ad4adeedbb249e7b
sha256: 4fa1cca1dd3f4c2ff75b42f4bd808758139ee4e34283592b745e179d7124dce0
sha512: 3566ba1a777ddf968c09f37ea6d8259f9ef2adac3b5d6385575fa16401e17de06d572be4fde2b3ff03aa11eb6b2555534f8a9219227255e107ac2c599bb1e1b8
ssdeep: 1536:4jqFsxP3UjHjREAuYpXh7dbu25j4dnycrzi/ni1:4eIfUAYJbu25WCq
type: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows

Version Info:

0: [No Data]

Ransom.Samsam.8 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.Samsam.8
FireEyeGeneric.mg.2eb524a9526bc681
ALYacGen:Variant.Ransom.Samsam.8
CylanceUnsafe
AegisLabTrojan.MSIL.Crypt.4!c
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 00529b1b1 )
BitDefenderGen:Variant.Ransom.Samsam.8
K7GWTrojan ( 00529b1b1 )
Cybereasonmalicious.9526bc
BitDefenderThetaGen:NN.ZemsilF.34590.eiW@ayPg2Bg
CyrenW32/MSIL_Kryptik.CUT.gen!Eldorado
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan.MSIL.Crypt.grcb
NANO-AntivirusTrojan.Win32.Crypt.fbexvn
RisingDropper.Generic!8.35E (CLOUD)
Ad-AwareGen:Variant.Ransom.Samsam.8
SophosMal/Generic-S
ComodoMalware@#2xp8qldgpixt0
F-SecureTrojan.TR/Dropper.Gen2
McAfee-GW-EditionArtemis
EmsisoftGen:Variant.Ransom.Samsam.8 (B)
IkarusTrojan.MSIL.Krypt
AviraTR/Dropper.Gen2
Antiy-AVLTrojan/Win32.TSGeneric
MicrosoftBackdoor:Win32/Bladabindi!ml
ArcabitTrojan.Ransom.Samsam.8
ZoneAlarmTrojan.MSIL.Crypt.grcb
GDataGen:Variant.Ransom.Samsam.8
CynetMalicious (score: 85)
AhnLab-V3Malware/Win32.RL_Generic.C4286659
McAfeeArtemis!2EB524A9526B
MAXmalware (ai score=95)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/CI.A
ESET-NOD32a variant of MSIL/Kryptik.OCR
TencentMsil.Trojan.Crypt.Hvjp
YandexTrojan.Crypt!lifDo2DOtK8
SentinelOneStatic AI – Malicious PE
FortinetMSIL/Kryptik.OYE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_80% (D)
Qihoo-360Win32/Trojan.a5b

How to remove Ransom.Samsam.8?

Ransom.Samsam.8 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment