Ransom

How to remove “Ransom:MacOS/FileCoder”?

Malware Removal

The Ransom:MacOS/FileCoder is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:MacOS/FileCoder virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Uses Windows utilities for basic functionality
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • A ping command was executed with the -n argument possibly to delay analysis
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Deletes executed files from disk
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ransom:MacOS/FileCoder?


File Info:

name: 1CD367CA3985D0602642.mlw
path: /opt/CAPEv2/storage/binaries/8e253211cf0cc20bba7e660f3f6e1e97dec2246429f1d23b64951039f20249cf
crc32: C4EEDA28
md5: 1cd367ca3985d0602642c8f7055d0560
sha1: e52e16928796e01be77799c0d3a419a898b1d141
sha256: 8e253211cf0cc20bba7e660f3f6e1e97dec2246429f1d23b64951039f20249cf
sha512: e1a7e0422525f76adffbea9e8d2ae73ca140f06bc0daa0c87375ddc2a7131d85dfe7be4806878f5385caff564b8978f78602a2a8157ee402c04d772b1c3376f6
ssdeep: 49152:vw80cTsjkWaUH5zOvasXRF1Jy4mcwDMFjZCh3cK:I8sjkynsBnJo0j8hv
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T192A5F12273DDC370CBAA9173BF6AB7016EBF38650630B85B1F881D7DA910161166D7A3
sha3_384: 7ea5a60bcfea349628ae2722dba11463391ebd0db587487303abc3868b79ad0b57b113b61868deb2434c720801af1d90
ep_bytes: e8b8d00000e97ffeffffcccccccccccc
timestamp: 2016-11-09 19:57:02

Version Info:

Translation: 0x0809 0x04b0

Ransom:MacOS/FileCoder also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Ishtar.j!c
tehtrisGeneric.Malware
DrWebTrojan.DownLoader32.54218
MicroWorld-eScanTrojan.GenericKD.3705394
ClamAVWin.Ransomware.Ishtar-5
SkyhighBehavesLike.Win32.Generic.vc
McAfeeArtemis!1CD367CA3985
MalwarebytesMalware.AI.870972921
VIPRETrojan.GenericKD.3705394
SangforRansom.Win32.Ishtar.V433
K7AntiVirusTrojan ( 004fccef1 )
AlibabaTrojan:Win32/Autoit.ali2000008
K7GWTrojan ( 004fccef1 )
Cybereasonmalicious.28796e
ArcabitTrojan.Generic.D388A32
VirITTrojan.Win32.Dnldr32.DCFI
SymantecTrojan Horse
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Ishtar.B
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Ishtar.y
BitDefenderTrojan.GenericKD.3705394
NANO-AntivirusTrojan.Win32.Ishtar.eiveoj
AvastWin32:Trojan-gen
TencentWin32.Trojan.Filecoder.Xdkl
EmsisoftTrojan.GenericKD.3705394 (B)
F-SecureHeuristic.HEUR/AGEN.1320378
TrendMicroRansom_ISHTAR.F116KE
SophosMal/Generic-R
IkarusTrojan.Win32.Filecoder
JiangminTrojan.Ishtar.e
WebrootW32.Trojan.GenKD
GoogleDetected
AviraHEUR/AGEN.1320378
XcitiumMalware@#1x8xipbwj1kvv
MicrosoftRansom:MacOS/FileCoder
ZoneAlarmTrojan-Ransom.Win32.Ishtar.y
GDataTrojan.GenericKD.3705394
VaristW32/Autoit.IYYO-1460
AhnLab-V3Trojan/Win32.Ishtar.R190422
VBA32Trojan.Autoit.Wirus
TACHYONRansom/W32.Ishtar.2103892
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_ISHTAR.F116KE
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Malware.11730479.susgen
FortinetW32/Ishtar.B!tr
AVGWin32:Trojan-gen
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:MacOS/FileCoder?

Ransom:MacOS/FileCoder removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment