Ransom

Ransom:Win32/Enestedel.B!rsm (file analysis)

Malware Removal

The Ransom:Win32/Enestedel.B!rsm is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Enestedel.B!rsm virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Compression (or decompression)
  • Attempts to connect to a dead IP:Port (4 unique times)
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • Attempts to modify desktop wallpaper
  • Executed a process and injected code into it, probably while unpacking
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Creates a hidden or system file
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

api.blockcypher.com
btc.blockr.io
bitaps.com
chain.so
crl3.digicert.com
ocsp.digicert.com

How to determine Ransom:Win32/Enestedel.B!rsm?


File Info:

crc32: 7C4B92EF
md5: 7c669c703e28d7d44d7f60a33d571991
name: 7C669C703E28D7D44D7F60A33D571991.mlw
sha1: 48a086fce53b2c276d650fd2494a4f8e3e53e6a1
sha256: f1d97e4d3c105851cf2a4d98ef6f0f075f9645e112ddd2665a81498bdaa005a8
sha512: b64a621b4eb21158e1835ba2c5cff7b047424765a2a9bee18d355bd55961aeb1fe549fbc67f8c9c4aa65b22f6a3347030eb66532fb1ea456f93acba2fe9634c3
ssdeep: 6144:70B2T/LmVMZxDX6OjXP2X7lxhRspsHx9ClgmsynpwhSoPD5mmP/fz:t/CVoxDqaP2X7nApOCnpwhScRP/fz
type: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive

Version Info:

0: [No Data]

Ransom:Win32/Enestedel.B!rsm also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.NSIS.Androm.CM
FireEyeGeneric.mg.7c669c703e28d7d4
CAT-QuickHealRansom.Cerber.A
Qihoo-360Trojan.Generic
McAfeeRDN/Generic.blo
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
SangforTrojan.Win32.Gen.sc
K7AntiVirusTrojan ( 005021581 )
BitDefenderTrojan.NSIS.Androm.CM
K7GWTrojan ( 005021581 )
Cybereasonmalicious.03e28d
SymantecRansom.Cerber
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Zerber.bagd
AlibabaRansom:Win32/Zerber.41f74679
NANO-AntivirusTrojan.Win32.DJNE.ekhelq
AegisLabTrojan.Win32.Zerber.4!c
RisingRansom.Zerber!8.518C (CLOUD)
Ad-AwareTrojan.NSIS.Androm.CM
SophosMal/Generic-R + Troj/Cerber-ACV
ComodoMalware@#167w2infvvkfe
F-SecureTrojan.TR/Injector.pbbvw
DrWebTrojan.Encoder.7453
ZillyaTrojan.Zerber.Win32.833
TrendMicroRansom_Enestedel.R002C0CBI21
McAfee-GW-EditionRDN/Generic.blo
EmsisoftTrojan.NSIS.Androm.CM (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan-Ransom.Agent.b
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1111168
MAXmalware (ai score=87)
Antiy-AVLTrojan/Win32.BTSGeneric
KingsoftWin32.Troj.Ransom.EW.(kcloud)
MicrosoftRansom:Win32/Enestedel.B!rsm
ArcabitTrojan.NSIS.Androm.CM
SUPERAntiSpywareRansom.Cerber/Variant
ZoneAlarmHEUR:Trojan-Ransom.Win32.Agent.gen
GDataTrojan.NSIS.Androm.CM
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.Inject.R193140
BitDefenderThetaGen:NN.ZedlaF.34590.bu4@a8Ig0Yp
ALYacTrojan.Ransom.Cerber
TACHYONTrojan/W32.Inject.240191
VBA32Hoax.Zerber
MalwarebytesMalware.AI.369909556
PandaTrj/CI.A
ESET-NOD32a variant of Win32/Injector.DJNE
TrendMicro-HouseCallRansom_Enestedel.R002C0CBI21
TencentWin32.Trojan.Cerber53.Alpa
YandexTrojan.Injector!X7a3z9k8xUU
IkarusTrojan.Win32.Injector
FortinetW32/Injector.DJNE!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (D)

How to remove Ransom:Win32/Enestedel.B!rsm?

Ransom:Win32/Enestedel.B!rsm removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment