Ransom

About “Ransom:Win32/Pocrimcrypt!pz” infection

Malware Removal

The Ransom:Win32/Pocrimcrypt!pz is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Pocrimcrypt!pz virus can do?

  • A file was accessed within the Public folder.
  • Sample contains Overlay data
  • Performs HTTP requests potentially not found in PCAP.
  • Reads data out of its own binary image
  • Authenticode signature is invalid
  • CAPE detected the shellcode get eip malware family
  • Attempts to modify proxy settings
  • Creates a copy of itself
  • Touches a file containing cookies, possibly for information gathering
  • Anomalous binary characteristics
  • Yara detections observed in process dumps, payloads or dropped files

How to determine Ransom:Win32/Pocrimcrypt!pz?


File Info:

name: 5BE009D5A07669335E12.mlw
path: /opt/CAPEv2/storage/binaries/c5d9d12ade0813384ca6a7c67d738dd6b427d3d659755cd37fb0055b3b66ecb3
crc32: BBE152C3
md5: 5be009d5a07669335e120c35e3c860d4
sha1: ad3c4f6d6a038158a4db12b37c7665bb5a63b871
sha256: c5d9d12ade0813384ca6a7c67d738dd6b427d3d659755cd37fb0055b3b66ecb3
sha512: d13eb10aed77ddff4ba1cfca060e1493d261b85df91670e8b0079ce622a5ee62ffad8f0ea6bb1932dd5ec89bbcc0524c0a79e19cd5cb2e8390e416cd782c69d5
ssdeep: 12288:EhkDgouVA2nxKkorvdRgQriDwOIxmxiZnYQE7PJcE4aLuAVYgW7cMJV4Hk7cyXb:cRmJkcoQricOIQxiZY1iaLuAe/n4Hkr
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T108256A23A5BDC0E2F1AE3EB04A29B35556386D260235D197E3CF3DE1D973043D6296E2
sha3_384: e7c09b91f74a5227e288eff7858add031821e43a53d52d30bb4b14e89b7c2fdbc8d2a92aeb74c1158f8673d2570853c9
ep_bytes: e816900000e989feffffcccccccccc55
timestamp: 2012-01-29 21:32:28

Version Info:

FileDescription:
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
Translation: 0x0809 0x04b0

Ransom:Win32/Pocrimcrypt!pz also known as:

BkavW32.AIDetectMalware
LionicTrojan.Win32.Autoit.i!c
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Strictor.162566
FireEyeGeneric.mg.5be009d5a0766933
SkyhighBehavesLike.Win32.Ransomware.dh
McAfeeGeneric.bao
Cylanceunsafe
ZillyaTrojan.AutoIT.Win32.36991
SangforInfostealer.Win32.Autoit.Vnxn
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojanPSW:Win32/Pocrimcrypt.f16cd064
K7GWTrojan ( 0050728b1 )
K7AntiVirusTrojan ( 0050728b1 )
BitDefenderThetaAI:Packer.44AFF4E515
VirITTrojan.Win32.Autoit.L
SymantecTrojan.Gen
tehtrisGeneric.Malware
ESET-NOD32Win32/Autoit.BQ
APEXMalicious
CynetMalicious (score: 100)
KasperskyTrojan-PSW.Win32.Autoit.ti
BitDefenderGen:Variant.Strictor.162566
NANO-AntivirusTrojan.Win32.Autoit.eoxkdx
AvastWin32:Malware-gen
TencentWin32.Trojan-QQPass.QQRob.Zylw
EmsisoftGen:Variant.Strictor.162566 (B)
F-SecureHeuristic.HEUR/AGEN.1321697
VIPREGen:Variant.Strictor.162566
TrendMicroTSPY_INFOSTEAL.SM
SophosMal/Generic-S
IkarusTrojan-Ransom.Crypt888
GDataGen:Variant.Strictor.162566
JiangminTrojan.PSW.Autoit.ez
WebrootW32.Trojan.Gen
GoogleDetected
AviraHEUR/AGEN.1321697
KingsoftWin32.PSWTroj.Undef.a
XcitiumTrojWare.Win32.Injector.EUXI@4yxp37
ArcabitTrojan.Strictor.D27B06
ZoneAlarmTrojan-PSW.Win32.Autoit.ti
MicrosoftRansom:Win32/Pocrimcrypt!pz
VaristW32/Trojan.EIRZ-7402
AhnLab-V3Trojan/Win32.RL_Agent.R278204
VBA32Trojan.Autoit.F
ALYacTrojan.PSW.Autoit
MAXmalware (ai score=83)
MalwarebytesMalware.AI.833452655
PandaTrj/CI.A
RisingTrojan.Obfus/Autoit!1.BEDE (CLASSIC)
SentinelOneStatic AI – Suspicious PE
MaxSecureTrojan.Autoit.AZA
AVGWin32:Malware-gen
DeepInstinctMALICIOUS

How to remove Ransom:Win32/Pocrimcrypt!pz?

Ransom:Win32/Pocrimcrypt!pz removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment