Ransom

Ransom:Win32/Filecoder.AA!MTB information

Malware Removal

The Ransom:Win32/Filecoder.AA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Filecoder.AA!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom:Win32/Filecoder.AA!MTB?


File Info:

name: CDB36DC4612F1CCC231F.mlw
path: /opt/CAPEv2/storage/binaries/f1c2d2f2cfe7d0a4ebfb87739c4233eb526efd1ea238ba68e27d166deb709a0c
crc32: 9BD9C17F
md5: cdb36dc4612f1ccc231fe54d8a3543d3
sha1: 8dfdf07f6aa9a6483582ae87d7249640c0ffd2a3
sha256: f1c2d2f2cfe7d0a4ebfb87739c4233eb526efd1ea238ba68e27d166deb709a0c
sha512: 7ce1c3f4c465b1ac16546506ce4550720f0c3e627ad35ad13ef91a7b96d286e3153df5c8a49ddfceac7e676da1e27c0144272650d77fa27ae4025986541b9914
ssdeep: 6144:ex2QdiglMFGfzIBeZO8Wf2cMRsCO/xZqqDLuz+4pQNnovTBSy:eAQsgScEydsCJqnuq46oky
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T18F745A3E96814436E0710AF58B66971C603F7E2019F55C5E2DEB4AFCCD3B6632A34B86
sha3_384: 3f5bccf81ee2a8d99d94c87409664e6456336befd6da1188c1b99b1857dac1553e941476d702d87bbca908ba113bb5a5
ep_bytes: 558becb9270000006a006a004975f951
timestamp: 2023-11-21 16:56:17

Version Info:

0: [No Data]

Ransom:Win32/Filecoder.AA!MTB also known as:

BkavW32.Common.9A3DFABA
LionicTrojan.Win32.Trigona.j!c
MicroWorld-eScanTrojan.GenericKD.71272461
FireEyeGeneric.mg.cdb36dc4612f1ccc
CAT-QuickHealRansom.Filecoder.S32258407
SkyhighBehavesLike.Win32.Dropper.fh
ALYacTrojan.Ransom.Filecoder
Cylanceunsafe
ZillyaTrojan.Generic.Win32.1853985
SangforRansom.Win32.Filecoder.Vant
K7AntiVirusRiskware ( 0040eff71 )
AlibabaRansom:Win32/Filecoder.361e2543
K7GWRiskware ( 0040eff71 )
Cybereasonmalicious.f6aa9a
BitDefenderThetaAI:Packer.446E02501F
VirITTrojan.Win32.Genus.UZD
SymantecML.Attribute.HighConfidence
Elasticmalicious (high confidence)
ESET-NOD32a variant of Win32/Filecoder.Trigona.A
CynetMalicious (score: 100)
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderTrojan.GenericKD.71272461
NANO-AntivirusTrojan.Win32.TrigonaRansom.khjevg
AvastWin32:RansomX-gen [Ransom]
TencentTrojan.Win32.Trigona.ka
TACHYONRansom/W32.DP-Agent.350720
SophosTroj/Ransom-HAE
F-SecureTrojan.TR/AD.TrigonaRansom.bdfta
DrWebTrojan.Encoder.38515
VIPRETrojan.GenericKD.71272461
Trapminesuspicious.low.ml.score
EmsisoftTrojan.GenericKD.71272461 (B)
IkarusTrojan-Ransom.Trigona
GDataTrojan.GenericKD.71272461
JiangminTrojan.Generic.hscjh
AviraTR/AD.TrigonaRansom.bdfta
Antiy-AVLTrojan[Ransom]/Win32.Filecoder
KingsoftWin32.Trojan-Ransom.Generic.a
ArcabitTrojan.Generic.D43F880D
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
MicrosoftRansom:Win32/Filecoder.AA!MTB
VaristW32/Filecoder.IM.gen!Eldorado
AhnLab-V3Ransomware/Win.Filecoder.R632385
McAfeeRansomware-HQS!CDB36DC4612F
MAXmalware (ai score=86)
VBA32TScope.Trojan.Delf
MalwarebytesRansom.FileCryptor
PandaTrj/Genetic.gen
RisingRansom.Trigona!8.18513 (TFE:4:x1AcuerNOpG)
MaxSecureTrojan.Malware.10307848.susgen
FortinetW32/Trigona.A!tr.ransom
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS
CrowdStrikewin/malicious_confidence_70% (W)

How to remove Ransom:Win32/Filecoder.AA!MTB?

Ransom:Win32/Filecoder.AA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment