Ransom

Ransom:Win32/Gandcrab.PA!MTB (file analysis)

Malware Removal

The Ransom:Win32/Gandcrab.PA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Gandcrab.PA!MTB virus can do?

  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Authenticode signature is invalid

How to determine Ransom:Win32/Gandcrab.PA!MTB?


File Info:

name: 4580E6154FD6170FAC8D.mlw
path: /opt/CAPEv2/storage/binaries/20f888e0415fd6d523b47c025f3838b6bb966682031baba97d4e048c1354e58b
crc32: 802DD068
md5: 4580e6154fd6170fac8d92daacb28686
sha1: 6adb90f3c4bce230bc0c19c6c9971e3981e9d7c6
sha256: 20f888e0415fd6d523b47c025f3838b6bb966682031baba97d4e048c1354e58b
sha512: 277d504c74505a3427cfd46358992b9307678220c22ac1643a15d72ff53db3a4e06dd33f104596e94ad265d7ea778db7b3473ef37faf66bf357b5d377f5e508e
ssdeep: 768:WhRAezmWw+cRq0j8P37j1NOxNKecIjcdygn3c0vkh:A/wl2PX1opcIjcdNJo
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T132F3070176E58476F4B64B321CB49B228E7DBC574E34AD5677C4134E0AF16E0AE20F7A
sha3_384: bf8752e3c9c3fe83794f37ceab50104a69003e78b0b422d0a50668d17504fefe3ed913434e27fd014ee514b8ef5fd8e2
ep_bytes: e86a120000e97bfeffff3b0d50308100
timestamp: 2018-05-07 21:38:10

Version Info:

0: [No Data]

Ransom:Win32/Gandcrab.PA!MTB also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Ransom.GandCrab.913
FireEyeGeneric.mg.4580e6154fd6170f
CAT-QuickHealTrojan.Mauvaise.SL1
McAfeeGenericRXGI-RO!4580E6154FD6
MalwarebytesMalware.AI.1878503659
BitDefenderGen:Variant.Ransom.GandCrab.913
Cybereasonmalicious.54fd61
ArcabitTrojan.Ransom.GandCrab.913
BitDefenderThetaAI:Packer.67386D131E
CyrenW32/Kryptik.HKH.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GXKS
APEXMalicious
KasperskyHEUR:Trojan.Win32.Generic
CynetMalicious (score: 100)
RisingRansom.GandCrab!8.F355 (TFE:5:uaUAWKpdsLC)
Ad-AwareGen:Variant.Ransom.GandCrab.913
SophosMal/Generic-S
ComodoTrojWare.Win32.Chapak.GO@7o85ni
F-SecureTrojan.TR/Crypt.EPACK.Gen2
VIPREGen:Variant.Ransom.GandCrab.913
McAfee-GW-EditionGenericRXGI-RO!4580E6154FD6
Trapminemalicious.high.ml.score
EmsisoftGen:Variant.Ransom.GandCrab.913 (B)
SentinelOneStatic AI – Suspicious PE
AviraTR/Crypt.EPACK.Gen2
MicrosoftRansom:Win32/Gandcrab.PA!MTB
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ransom.GandCrab.913
GoogleDetected
AhnLab-V3Trojan/Win32.Gandcrab.C2499364
ALYacGen:Variant.Ransom.GandCrab.913
MAXmalware (ai score=84)
CylanceUnsafe
PandaTrj/Genetic.gen
YandexTrojan.GenAsa!sEQ6NA0nfs4
IkarusTrojan-Ransom.GandCrab
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.GXKS!tr
AVGWin32:RansomX-gen [Ransom]
AvastWin32:RansomX-gen [Ransom]
CrowdStrikewin/malicious_confidence_90% (D)

How to remove Ransom:Win32/Gandcrab.PA!MTB?

Ransom:Win32/Gandcrab.PA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment