Ransom

What is “Ransom:Win32/StopCrypt.PV!MTB”?

Malware Removal

The Ransom:Win32/StopCrypt.PV!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/StopCrypt.PV!MTB virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • Unconventionial language used in binary resources: Urdu (India)
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Network activity detected but not expressed in API logs
  • CAPE detected the RedLine malware family

Related domains:

wpad.local-net

How to determine Ransom:Win32/StopCrypt.PV!MTB?


File Info:

name: E798CF1863ED352BDAA0.mlw
path: /opt/CAPEv2/storage/binaries/0284e6c20d54b5be61fcad0caa1e03c42a9daa6ff853211480432ef5a8f52dc1
crc32: 431C5DA6
md5: e798cf1863ed352bdaa0e802452eea7f
sha1: 1781a41f7788413680f487af3af85ea8a192135b
sha256: 0284e6c20d54b5be61fcad0caa1e03c42a9daa6ff853211480432ef5a8f52dc1
sha512: 077d880e6c3671341092c9235089032a1501b08375abae48b0d1163d736ce4e435a87f39c6a6fd95760c10a5ed29c20b5aeb0d98c2c2afd19356c075af29d728
ssdeep: 6144:9/bzLyd8dvCr0qTRddAr7Z0uE6W7IvNQOUQnWw2P7:FvLGg+0qTRdMl7NvNjU8I
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T17C54F121F7E0CB35C6D36A30687097A18A7BB823E975809F371B222E4F712D09975797
sha3_384: ac95a6b1da437ed94ac9f0c9eb009fd1dc809d830bacee28dc56b5643945067920f4422d5e3d15580c3bb239abd534f1
ep_bytes: e8502a0000e989feffffcccccccccccc
timestamp: 2020-11-01 13:29:17

Version Info:

InternalName: bomgpiaruci.iwa
Copyright: Copyrighz (C) 2021, fudkat
ProductVersion: 13.54.77.27
Translation: 0x0114 0x046a

Ransom:Win32/StopCrypt.PV!MTB also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Multi.Generic.4!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealTrojan.AzorultPMF.S25008941
McAfeeLockbit-FSWW!E798CF1863ED
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_90% (W)
BitDefenderGen:Heur.Mint.Titirez.rq0@m1bXWkeG
K7GWTrojan ( 00589d2d1 )
K7AntiVirusTrojan ( 00589d2d1 )
CyrenW32/Kryptik.FUG.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNLX
APEXMalicious
AvastWin32:CrypterX-gen [Trj]
KasperskyHEUR:Trojan-Spy.Win32.Stealer.gen
AlibabaRansom:Win32/StopCrypt.6e687f96
MicroWorld-eScanGen:Heur.Mint.Titirez.rq0@m1bXWkeG
TencentWin32.Trojan-spy.Stealer.Alim
Ad-AwareGen:Heur.Mint.Titirez.rq0@m1bXWkeG
SophosML/PE-A + Troj/Krypt-BO
DrWebTrojan.PWS.Siggen3.7138
TrendMicroTROJ_GEN.R049C0PKT21
McAfee-GW-EditionBehavesLike.Win32.Lockbit.dc
FireEyeGeneric.mg.e798cf1863ed352b
EmsisoftTrojan.Crypt (A)
IkarusTrojan-Ransom.StopCrypt
GDataWin32.Trojan.BSE.11GYDBI
JiangminTrojanDropper.Scrop.cmq
AviraTR/AD.GenSHCode.igtrc
MAXmalware (ai score=83)
Antiy-AVLTrojan/Generic.ASMalwS.34D9C25
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.STOP.sa
MicrosoftRansom:Win32/StopCrypt.PV!MTB
AhnLab-V3Trojan/Win.FSWW.R453694
Acronissuspicious
VBA32Backdoor.Mokes
ALYacGen:Heur.Mint.Titirez.rq0@m1bXWkeG
MalwarebytesTrojan.MalPack
TrendMicro-HouseCallTROJ_GEN.R049C0PKT21
RisingTrojan.Kryptik!1.DAC3 (CLASSIC)
SentinelOneStatic AI – Malicious PE
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Lockbit.FSWW!tr
BitDefenderThetaGen:NN.ZexaF.34084.rq0@a0bXWkeG
AVGWin32:CrypterX-gen [Trj]
Cybereasonmalicious.f77884
Paloaltogeneric.ml

How to remove Ransom:Win32/StopCrypt.PV!MTB?

Ransom:Win32/StopCrypt.PV!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment