Ransom

Ransom:Win64/Azov.psyA!MTB (file analysis)

Malware Removal

The Ransom:Win64/Azov.psyA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ransom:Win64/Azov.psyA!MTB virus can do?

  • Sample contains Overlay data
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Ransom:Win64/Azov.psyA!MTB?


File Info:

name: 51A2AA9946034A059613.mlw
path: /opt/CAPEv2/storage/binaries/32e71cdeda4fbc06dc40ebda6ba032cdddf1b26e9a5afcfa6cdd6b7a0f07a2cf
crc32: FE9BAD27
md5: 51a2aa9946034a0596138544300c3459
sha1: 579915df61de0fe2d6c8b29673537beb81129264
sha256: 32e71cdeda4fbc06dc40ebda6ba032cdddf1b26e9a5afcfa6cdd6b7a0f07a2cf
sha512: 5b5d3e69a875af716e2f00d938f0e64f5ad7de3bf52cfc9116aa7c738e5949a9a19671f80bd77c97e15ac1e751514623d5d49f2b4b4de211c84a3b25eed0de94
ssdeep: 49152:qI1jFGmRMwVaTRK019lsXB8y2pZ0zWlF01NVZTFZ1bBzP7n1Y8/17MVfw1QSXm+y:qIjFK01XZTFFqRlw6a+0Y
type: PE32+ executable (GUI) x86-64, for MS Windows
tlsh: T171065B03E2F941E8F0BAD678DB258736D972BC854B34A1DF129056191E76FE09F38722
sha3_384: a6333e82301c4f6041423711665720e1697c248462394f0b2a0e4fe67a2b9444cb5e0517f852394958ce5e67ecc24cd2
ep_bytes: e848feffffc82000004c897c24f84883
timestamp: 2021-08-11 22:26:42

Version Info:

CompanyName: Microsoft Corporation
FileDescription: Microsoft Edge Installer
FileVersion: 92.0.902.73
InternalName: setup_exe
LegalCopyright: Copyright Microsoft Corporation. All rights reserved.
OriginalFilename: setup.exe
ProductName: Microsoft Edge Installer
ProductVersion: 92.0.902.73
CompanyShortName: Microsoft
ProductShortName: Microsoft Edge Installer
LastChange: cad199e39220991414cd71868a619fff614880c7
Official Build: 1
Translation: 0x0409 0x04b0

Ransom:Win64/Azov.psyA!MTB also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Lazy.260700
FireEyeGen:Variant.Lazy.260700
ALYacGen:Variant.Lazy.260700
VIPREGen:Variant.Lazy.260700
K7AntiVirusTrojan ( 0059aa0b1 )
BitDefenderGen:Variant.Lazy.260700
K7GWTrojan ( 0059aa0b1 )
VirITWin64.AzovWiper.A
CyrenW64/Ipamor.A
SymantecML.Attribute.HighConfidence
ESET-NOD32Win64/Filecoder.GG
KasperskyTrojan.Win64.AsowWiper.co
AlibabaTrojan:Win64/AsowWiper.5434bdc6
AvastWin32:Azov-A [Wpr]
TencentTrojan-Ransom.Win32.Ulise.16000592
EmsisoftGen:Variant.Lazy.260700 (B)
DrWebWin32.HLLP.Azov.2
TrendMicroRansom.Win64.AZVO.SMYXCJ5
McAfee-GW-EditionBehavesLike.Win64.Dropper.wh
SophosTroj/Azov-A
GDataGen:Variant.Lazy.260700
JiangminTrojan.Blocker.urx
Antiy-AVLGrayWare/Win32.Filecoder.gg
ArcabitTrojan.Lazy.D3FA5C
ZoneAlarmTrojan.Win64.AsowWiper.co
MicrosoftRansom:Win64/Azov.psyA!MTB
GoogleDetected
AhnLab-V3Malware/Win.Ransom.R533933
Acronissuspicious
McAfeeArtemis!51A2AA994603
MAXmalware (ai score=80)
RisingRansom.Agent!8.6B7 (TFE:2:U9tOTBNOHOO)
IkarusTrojan-Ransom.FileCrypter
FortinetW64/Filecoder.GG!tr
AVGWin32:Azov-A [Wpr]
DeepInstinctMALICIOUS

How to remove Ransom:Win64/Azov.psyA!MTB?

Ransom:Win64/Azov.psyA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment