Ransom

Ransom:Win32/Filecoder.OJD!MTB malicious file

Malware Removal

The Ransom:Win32/Filecoder.OJD!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Filecoder.OJD!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Ransom:Win32/Filecoder.OJD!MTB?


File Info:

name: A53AF2540483DABAD5D8.mlw
path: /opt/CAPEv2/storage/binaries/7b4f572f0ca82e3ff1030ed2c0ddd50d82fc145d37123c0ec47a9e2f6e5724d0
crc32: 77DBDC4F
md5: a53af2540483dabad5d8eac13c672ed2
sha1: 1abfc3e85a43035a534fc377d838de9b7c1d0f25
sha256: 7b4f572f0ca82e3ff1030ed2c0ddd50d82fc145d37123c0ec47a9e2f6e5724d0
sha512: 6c279b316494b288d12dd84846d21b83749449150d0cd1297c34b6257f8b4fddf09c4323da332f0d6a98473508c5866cb6d8d76abea2df440d6ba60e0b4fa2ba
ssdeep: 1536:jCWnKGNXIsfYqEVmO/bNJccuZUT53v7pIe0PTBohEfqv:jJ3FIsYJbduZ253vFIeiTBf
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T12743F12A8DBFD3E7C2C10DBD01AB6A17A51132914C582BFA984E491AF1CB36A7735907
sha3_384: 6e561a276893e129a03db73992491ca9f4fcadf1a853bc9e1367f5d0aa4898feb62f96d67d952aa260992c20089bb2b1
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Ransom:Win32/Filecoder.OJD!MTB also known as:

BkavW32.AIDetect.malware2
Elasticmalicious (high confidence)
MicroWorld-eScanDeepScan:Generic.Malware.GF!prn!.B2759598
FireEyeGeneric.mg.a53af2540483daba
McAfeeGenericRXQS-VX!A53AF2540483
CylanceUnsafe
SangforRansom.Win32.Cryptor.gen
K7AntiVirusTrojan ( 0058ac911 )
AlibabaRansom:Win32/Filecoder.a56f1dba
K7GWTrojan ( 0058ac911 )
Cybereasonmalicious.40483d
BitDefenderThetaAI:Packer.3B23176F1E
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
TrendMicro-HouseCallTROJ_FRS.0NA103B222
Paloaltogeneric.ml
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan.Win32.Swisyn.fuub
BitDefenderDeepScan:Generic.Malware.GF!prn!.B2759598
AvastWin32:Malware-gen
TencentWin32.Trojan.Filecoder.Lkni
EmsisoftDeepScan:Generic.Malware.GF!prn!.B2759598 (B)
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.qc
SophosMal/Generic-S
IkarusTrojan-Ransom.FileCrypter
AviraTR/Dropper.Gen
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
GridinsoftRansom.Win32.AI.sa
MicrosoftRansom:Win32/Filecoder.OJD!MTB
ZoneAlarmTrojan.Win32.Swisyn.fuub
GDataDeepScan:Generic.Malware.GF!prn!.B2759598
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.C4525901
VBA32BScope.TrojanRansom.Cryptor
ALYacDeepScan:Generic.Malware.GF!prn!.B2759598
MalwarebytesMalware.AI.439913036
APEXMalicious
RisingRansom.Cryptor!8.10A9 (CLOUD)
YandexTrojan.Filecoder!r1NHDnc48cw
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Filecoder.OJD!tr.ransom
AVGWin32:Malware-gen
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_90% (W)

How to remove Ransom:Win32/Filecoder.OJD!MTB?

Ransom:Win32/Filecoder.OJD!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment