Ransom

Ransom:Win32/Ascrirac.A (file analysis)

Malware Removal

The Ransom:Win32/Ascrirac.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Ascrirac.A virus can do?

  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Drops a binary and executes it
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Steals private information from local Internet browsers
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Connects to Tor Hidden Services through a Tor gateway
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
5sse6j4kdaeh3yus.onion.cab
5sse6j4kdaeh3yus.tor2web.org

How to determine Ransom:Win32/Ascrirac.A?


File Info:

crc32: 05C4E41A
md5: 0d0cb6c8cb86b4b063b022cc8208196f
name: 0D0CB6C8CB86B4B063B022CC8208196F.mlw
sha1: 76ac0ca9ed50eeab7d5165c3cae4ab63ad6ccf4b
sha256: 96e42d0c7d8ca6584563208c2ca3c41c7356199b495c948bb5a963ef83c55c69
sha512: 8314a0cbddee5b1d32af032d6e694d94a0e5b228ff0ccc0fcbcff83e20e9f229651a72ce209c1a81fc4a1b67a38694153c43264e18794f6e6957a31363976bc3
ssdeep: 6144:ZYQ/9bno1GyI6g3VQQoUC8/bDLXhDTBzlHKAON1QLb26/VIF:ZYQmTIzVQQZP/jXhDTFlHKtQLb2GI
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Ransom:Win32/Ascrirac.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 004df5701 )
LionicTrojan.Win32.Dapato.a!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.888
CynetMalicious (score: 100)
ALYacGen:Heur.Ransom.REntS.Gen.1
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.10574
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
AlibabaRansom:Win32/Bitman.ead864b7
K7GWTrojan ( 004df5701 )
Cybereasonmalicious.8cb86b
ESET-NOD32a variant of Win32/Filecoder.TeslaCrypt.A
APEXMalicious
AvastWin32:CryptoLocker-C [Trj]
KasperskyTrojan-Ransom.Win32.Bitman.m
BitDefenderGen:Heur.Ransom.REntS.Gen.1
NANO-AntivirusTrojan.Win32.Dapato.dobeto
MicroWorld-eScanGen:Heur.Ransom.REntS.Gen.1
TencentWin32.Trojan.Bp-ransomware.Ejqz
Ad-AwareGen:Heur.Ransom.REntS.Gen.1
ComodoMalware@#zhfpc64ktxam
BitDefenderThetaGen:NN.ZexaF.34796.CqX@aqWYdVji
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_Ascrirac.R066C0DF221
FireEyeGeneric.mg.0d0cb6c8cb86b4b0
EmsisoftGen:Heur.Ransom.REntS.Gen.1 (B)
SentinelOneStatic AI – Suspicious PE
JiangminTrojan.Bitman.ayl
AviraTR/FileCoder.466945
Antiy-AVLTrojan/Generic.ASMalwS.E6753B
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Ascrirac.A
ArcabitTrojan.Ransom.REntS.Gen.1
GDataGen:Heur.Ransom.REntS.Gen.1
AhnLab-V3Malware/Win32.Generic.C834706
McAfeeArtemis!0D0CB6C8CB86
MAXmalware (ai score=82)
VBA32BScope.TrojanRansom.Bitman
PandaTrj/CI.A
TrendMicro-HouseCallRansom_Ascrirac.R066C0DF221
RisingTrojan.Generic@ML.85 (RDML:MDrI6N4iQn7NRwsxyrCEQg)
YandexTrojan.GenAsa!ma0tpPcnIDI
IkarusTrojan-Ransom.TeslaCrypt
MaxSecureTrojan.Malware.74621722.susgen
FortinetW32/TeslaCrypt.A!tr.ransom
AVGWin32:CryptoLocker-C [Trj]
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Bitman.HgIASOYA

How to remove Ransom:Win32/Ascrirac.A?

Ransom:Win32/Ascrirac.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment