Ransom

Ransom:Win32/Satancrypt.A (file analysis)

Malware Removal

The Ransom:Win32/Satancrypt.A is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Satancrypt.A virus can do?

  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Turkish
  • The binary likely contains encrypted or compressed data.
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • Creates a copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz

How to determine Ransom:Win32/Satancrypt.A?


File Info:

crc32: A0EEB5D1
md5: bef73a13a21765a19592f58117a34c64
name: BEF73A13A21765A19592F58117A34C64.mlw
sha1: 8e204a0aac9d838637b09f3a146400e2a804b8eb
sha256: 3860162c1e081fc4b3629220c2ae692d168c16be2b4dc0ab3952e738ddd9405f
sha512: fcd5613abc4612cc18d5a973f458bd1fe43127376c5c6ea5922fef6834834c2a9d35e779fc8a75b6558fa3f41c79c410fc97b89cb9c45354bb1f5b420b6e226f
ssdeep: 3072:+0zc4QMRfNJ07hLt/7yPm2/EeKl+2rT2pNeZB0b7nx0RGs7GgaD1UA2n3KH23vJ:/gclGBNyPmLeOE
type: MS-DOS executable, MZ for MS-DOS

Version Info:

0: [No Data]

Ransom:Win32/Satancrypt.A also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0051c6a61 )
LionicTrojan.Win32.VBKrypt.lNlz
Elasticmalicious (high confidence)
DrWebTrojan.DownLoader25.54108
CynetMalicious (score: 100)
ALYacTrojan.Ransom.NATAS
CylanceUnsafe
ZillyaTrojan.Gen.Win32.1590
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_60% (D)
AlibabaRansom:Win32/Satancrypt.1743e387
K7GWTrojan ( 0051c6a61 )
Cybereasonmalicious.3a2176
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Generik.LNTITJ
APEXMalicious
AvastWin32:Malware-gen
KasperskyTrojan-Ransom.Win32.Gen.fzb
BitDefenderTrojan.GenericKDS.34980337
NANO-AntivirusTrojan.Win32.Dwn.euxirg
ViRobotTrojan.Win32.S.Dropper.209920.D
MicroWorld-eScanTrojan.GenericKDS.34980337
TencentWin32.Trojan.Raas.Auto
Ad-AwareTrojan.GenericKDS.34980337
SophosMal/Generic-S
ComodoMalware@#3hefkxl2biu7z
BitDefenderThetaGen:NN.ZexaF.34058.mmqaaO2NvNlO
TrendMicroRansom_NATAS.I
McAfee-GW-EditionBehavesLike.Win32.PWSZbot.dc
FireEyeGeneric.mg.bef73a13a21765a1
EmsisoftTrojan.GenericKDS.34980337 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Gen.oi
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.22BFA60
MicrosoftRansom:Win32/Satancrypt.A
ArcabitTrojan.GenericS.D215C1F1
GDataTrojan.GenericKDS.34980337
AhnLab-V3Trojan/Win32.Filecoder.R212665
Acronissuspicious
McAfeeArtemis!BEF73A13A217
MAXmalware (ai score=100)
VBA32Trojan-Ransom.Gen
PandaTrj/CI.A
TrendMicro-HouseCallRansom_NATAS.I
YandexTrojan.DownLoader!ua+kqUPEvhs
IkarusTrojan.Agent
MaxSecureTrojan.Malware.300983.susgen
FortinetGenerik.LNTITJ!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
Qihoo-360Win32/Ransom.Satan.HxIBEpsA

How to remove Ransom:Win32/Satancrypt.A?

Ransom:Win32/Satancrypt.A removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment