Ransom

Ransom:Win32/Filecoder.AA!MTB (file analysis)

Malware Removal

The Ransom:Win32/Filecoder.AA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Filecoder.AA!MTB virus can do?

  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Creates an autorun.inf file
  • Authenticode signature is invalid
  • Checks for the presence of known devices from debuggers and forensic tools
  • Checks for the presence of known devices from debuggers and forensic tools
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ransom:Win32/Filecoder.AA!MTB?


File Info:

name: BD1F3093D66047542649.mlw
path: /opt/CAPEv2/storage/binaries/3c73add3102c6892b47458f48633ccc47a8bb1c96b19519ffd7582c05687fbe4
crc32: E4E828D4
md5: bd1f3093d66047542649438ca2ff721b
sha1: ae07690dcf87cf72e6a4841d6bc36ac7de472b13
sha256: 3c73add3102c6892b47458f48633ccc47a8bb1c96b19519ffd7582c05687fbe4
sha512: 251d626b78c13476c9d5195e646294b1769a719919b80207d832b36e12503c86e705c74484aeae141ec5402bb58f3fb0888b927f2f5ee93e5c9cecd172575c9d
ssdeep: 3072:SFB3O3IRORghwODMJlz1dxoOXwupfTYEA8i70zCK9F2JBJalT74ix:UBZcIDqvysbpfsyU0FFOUl/Bx
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T100F3120098DD33D3F57432BE6E1A4279986ADC724ACD6C6C1F2EE96677390E3D50B10A
sha3_384: fe3124f8eef3cf1758ddd8f7547257b0d2f15b03a5efe5475556293accfa5225b401b9e046689262b24ec6fd96821830
ep_bytes: 60be00e043008dbe0030fcffc7870cfc
timestamp: 2023-11-21 16:56:17

Version Info:

0: [No Data]

Ransom:Win32/Filecoder.AA!MTB also known as:

MicroWorld-eScanGen:Variant.Genie.364
FireEyeGeneric.mg.bd1f3093d6604754
SkyhighBehavesLike.Win32.ObfuscatedPoly.cc
McAfeeArtemis!BD1F3093D660
Cylanceunsafe
SangforRansom.Win32.Trigona.Vcrk
AlibabaRansom:Win32/Filecoder.401bafbc
Cybereasonmalicious.dcf87c
ArcabitTrojan.Genie.364
BitDefenderThetaAI:Packer.A174AAFB1F
SymantecML.Attribute.HighConfidence
Elasticmalicious (moderate confidence)
ESET-NOD32a variant of Win32/Filecoder.Trigona.A
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Ransomware.Genie-10019460-0
KasperskyHEUR:Trojan-Ransom.Win32.Generic
BitDefenderGen:Variant.Genie.364
NANO-AntivirusTrojan.Win32.TrigonaRansom.khjevg
AvastWin32:RansomX-gen [Ransom]
TencentTrojan.Win32.Trigona.ka
TACHYONRansom/W32.DP-Agent.350720
DrWebTrojan.Encoder.38515
VIPREGen:Variant.Genie.364
EmsisoftGen:Variant.Genie.364 (B)
JiangminTrojan.Generic.hscjh
VaristW32/Filecoder.IM.gen!Eldorado
Antiy-AVLTrojan[Ransom]/Win32.Trigona
Kingsoftmalware.kb.b.946
MicrosoftRansom:Win32/Filecoder.AA!MTB
ZoneAlarmHEUR:Trojan-Ransom.Win32.Generic
GDataGen:Variant.Genie.364
GoogleDetected
VBA32TScope.Trojan.Delf
ALYacGen:Variant.Genie.364
MAXmalware (ai score=85)
MalwarebytesGeneric.Malware/Suspicious
PandaTrj/Genetic.gen
RisingRansom.Trigona!8.18513 (CLOUD)
YandexTrojan.Filecoder!8vAb2ZPiOSs
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Trigona.A!tr.ransom
AVGWin32:RansomX-gen [Ransom]
DeepInstinctMALICIOUS

How to remove Ransom:Win32/Filecoder.AA!MTB?

Ransom:Win32/Filecoder.AA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment