Ransom

Ransom.Spora.9 (file analysis)

Malware Removal

The Ransom.Spora.9 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom.Spora.9 virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Reads data out of its own binary image
  • The binary likely contains encrypted or compressed data.
  • Executed a very long command line or script command which may be indicative of chained commands or obfuscation
  • A scripting utility was executed
  • Uses Windows utilities for basic functionality
  • Executed a process and injected code into it, probably while unpacking
  • Installs itself for autorun at Windows startup
  • Anomalous binary characteristics

How to determine Ransom.Spora.9?


File Info:

crc32: B94E7477
md5: ba5be2e479e18e89d9461ec7f0dfcfeb
name: BA5BE2E479E18E89D9461EC7F0DFCFEB.mlw
sha1: ce1d22820685fb95cffb7f94cbb0addf19eb1e4a
sha256: 9054866135305fbe6a5bd53ee6bbe7cc65791bb663987f50414245b71dbd91b6
sha512: 2ce09044604a73220d57912fae15698e0c9ee483faa694d353188aa3b6956646e0a14e2a7ce97ac9c59348fbcc87c3f548420e1603d08149479ee12f469fafdf
ssdeep: 1536:XcJ+R/Noj4dNmls/p7yPYEQrziCT+wz2Jntr0656qKRsXkTZryHnzZoU9f1xN:XckR/ij4dkl0p7dDzOJnK6AndZ+HdXBN
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom.Spora.9 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10474
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Spora.9
CylanceUnsafe
ZillyaTrojan.Generic.Win32.1335181
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.d550e8bc
K7GWTrojan ( 004f85d91 )
K7AntiVirusTrojan ( 004f85d91 )
SymantecRansom.Cryptolocker
ESET-NOD32a variant of Win32/Kryptik.HGWB
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Ransomware.Spora-9827371-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ransom.Spora.9
NANO-AntivirusTrojan.Win32.Ransom.evheqo
ViRobotTrojan.Win32.VaultCrypt.113786
MicroWorld-eScanGen:Variant.Ransom.Spora.9
TencentMalware.Win32.Gencirc.10b6736b
Ad-AwareGen:Variant.Ransom.Spora.9
SophosML/PE-A + Mal/Zbot-UM
ComodoMalware@#b6ril5suzyav
F-SecureHeuristic.HEUR/AGEN.1124237
BitDefenderThetaGen:NN.ZexaF.34608.gqX@auLVBCg
VIPRETrojan.Win32.Injector.cdgy (v)
TrendMicroRansom_HPJUSINOMEL.SM
McAfee-GW-EditionBehavesLike.Win32.Generic.cc
FireEyeGeneric.mg.ba5be2e479e18e89
EmsisoftGen:Variant.Ransom.Spora.9 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Inject.nwp
AviraHEUR/AGEN.1124237
eGambitUnsafe.AI_Score_99%
Antiy-AVLTrojan/Win32.AGeneric
MicrosoftRansom:Win32/Spora
ArcabitTrojan.Ransom.Spora.9
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.Spora.9
McAfeeGeneric.cus
MAXmalware (ai score=100)
VBA32BScope.TrojanRansom.Spora
MalwarebytesMalware.AI.2909795424
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPJUSINOMEL.SM
RisingTrojan.Miuref!8.B7E (CLOUD)
YandexTrojan.GenAsa!Z6HHYWpVF4M
IkarusBackdoor.Siggen
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Injector.DKMW!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Trojan.Generic.HgIASOYA

How to remove Ransom.Spora.9?

Ransom.Spora.9 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment