Ransom

What is “Ransom:Win32/Vaultcrypt”?

Malware Removal

The Ransom:Win32/Vaultcrypt is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win32/Vaultcrypt virus can do?

  • Executable code extraction
  • Injection (inter-process)
  • Injection (Process Hollowing)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Reads data out of its own binary image
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Slovak
  • Executed a process and injected code into it, probably while unpacking
  • Steals private information from local Internet browsers
  • Exhibits behavior characteristic of Pony malware
  • Collects information about installed applications
  • Harvests information related to installed mail clients
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
a.tomx.xyz
prom-sk.com

How to determine Ransom:Win32/Vaultcrypt?


File Info:

crc32: 44CC6CB4
md5: 50dd785043ab8f09a9d0209aab36c692
name: 50DD785043AB8F09A9D0209AAB36C692.mlw
sha1: 86085a7bb46e328176343331bc1f0b98afcfbb5f
sha256: 6f8b200ef281ccc631046e79a8d468594873bcb093e6772e79b12f8db72503e1
sha512: d3318ed969c90c7934245f829a8e8c07bc7f8743a3191aeef21b165ca67c22bb288d80615bd79d7022437908763354b5e409bf723a8e20ef0ae1653e3513c7f9
ssdeep: 3072:7MXnkJeJuqppaG0tHjvgkJbgs0SEXoBAmr7SAW9WU+NASM:7wVWzDfbbnEXEAmr7tWoU0M
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright ? 2016
InternalName: WebCam
FileVersion: 1, 0, 0, 1
CompanyName:
PrivateBuild:
LegalTrademarks:
Comments:
ProductName: WebCam
SpecialBuild:
ProductVersion: 1, 0, 0, 1
FileDescription: WebCam
OriginalFilename: WebCam.exe
Translation: 0x0807 0x04e3

Ransom:Win32/Vaultcrypt also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Deliric.25
FireEyeGeneric.mg.50dd785043ab8f09
Qihoo-360Generic/Trojan.c2a
ALYacGen:Variant.Deliric.25
CylanceUnsafe
VIPRETrojan.Win32.Injector.cdgy (v)
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0055e3991 )
BitDefenderGen:Variant.Deliric.25
K7GWTrojan ( 0055e3991 )
Cybereasonmalicious.043ab8
BitDefenderThetaGen:NN.ZexaF.34590.hq3@a0nEDHkG
SymantecRansom.JuicyLemon
APEXMalicious
AvastWin32:Malware-gen
ClamAVWin.Trojan.Zusy-7810454-0
KasperskyHEUR:Trojan.Win32.Generic
AlibabaRansom:Win32/Vaultcrypt.131828f8
NANO-AntivirusTrojan.Win32.Fareit.eveknw
TencentTrojan-Ransom.Win32.PizzaCrypts.a
Ad-AwareGen:Variant.Deliric.25
TACHYONTrojan-PWS/W32.Fareit.129538
SophosMal/Generic-R + Mal/Zbot-UM
ComodoMalware@#1me9b9fucbzh7
F-SecureHeuristic.HEUR/AGEN.1133189
DrWebTrojan.KillProc.41653
ZillyaTrojan.Fareit.Win32.15697
TrendMicroRansom_CRYPVAULT.BAU
McAfee-GW-EditionGenericRXAA-HW!50DD785043AB
EmsisoftGen:Variant.Deliric.25 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.PSW.Fareit.etn
WebrootW32.Trojan.Gen
AviraHEUR/AGEN.1133189
Antiy-AVLTrojan[Spy]/Win32.Hesperbot
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Vaultcrypt
ArcabitTrojan.Deliric.25
SUPERAntiSpywareBackdoor.Bot/Variant
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Deliric.25
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win32.MDA.C1469515
Acronissuspicious
McAfeeGenericRXAA-HW!50DD785043AB
MAXmalware (ai score=100)
VBA32BScope.Trojan.Ekstak
MalwarebytesMalware.AI.1680240428
PandaTrj/CI.A
ESET-NOD32Win32/Filecoder.FH
TrendMicro-HouseCallRansom_CRYPVAULT.BAU
RisingTrojan.Crypto!8.364 (TFE:dGZlOgVdDbYnxBpJBQ)
YandexTrojan.GenAsa!Sa8CoKhBUpY
IkarusTrojan.Win32.Filecoder
eGambitUnsafe.AI_Score_100%
FortinetW32/Injector.CZPT!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Ransom:Win32/Vaultcrypt?

Ransom:Win32/Vaultcrypt removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment