Malware

Razy.627365 malicious file

Malware Removal

The Razy.627365 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.627365 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • A file was accessed within the Public folder.
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Attempts to access Bitcoin/ALTCoin wallets
  • Harvests credentials from local FTP client softwares
  • Installs WinPCAP
  • Anomalous binary characteristics
  • Yara rule detections observed from a process memory dump/dropped files/CAPE

How to determine Razy.627365?


File Info:

name: 21697B8869BE74573277.mlw
path: /opt/CAPEv2/storage/binaries/a94e209cb17d7f52789e720e3a7a5af83fb357049047ca8b6037a5e6d34cc160
crc32: F270E1A9
md5: 21697b8869be745732776de6a9fc4f79
sha1: a4d086a019c50da60e9bcf396615a1d7396ab148
sha256: a94e209cb17d7f52789e720e3a7a5af83fb357049047ca8b6037a5e6d34cc160
sha512: 637ca1795f5f458998cd3b5d4e975f6ca2b8c0274819718a3a9a8d48b4d6d0ccaffcc8609b5fa67a0f38684cc09b35675b6c292aa7c37b0b5f62646ecaa83766
ssdeep: 12288:vTPTtlQAsWBcuvHDm13ZkVhL1/wW9zLNYbDz+qqZiCfZW5Tm5cH3SmJUQj:vXbcuv2pm5Zr/SqqkigW5TmoSTQj
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T190F433368403ADA4D13B913A595F4E77E60C7E038A209B7C922C7B7E4AB93C24D84F56
sha3_384: 9e2b94ae07974c6df17e2a3d9241d70bf37389e13fb46f0bb52642e2f63dee562e6e537975699c8cabbe449efd38fdf7
ep_bytes: 68fc3f40008304240468143140005f83
timestamp: 2013-01-02 14:20:41

Version Info:

0: [No Data]

Razy.627365 also known as:

BkavW32.Common.A1DCC020
LionicTrojan.Win32.Generic.lmka
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.627365
CAT-QuickHealTrojan.Urausy.C
SkyhighBehavesLike.Win32.VirRansom.bc
McAfeeBackDoor-FJW
MalwarebytesGeneric.Malware.AI.DDS
ZillyaTrojan.Tepfer.Win32.30838
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0040f2c01 )
AlibabaVirTool:Win32/Obfuscator.95e50dee
K7GWTrojan ( 0040f2c01 )
CrowdStrikewin/malicious_confidence_100% (W)
ArcabitTrojan.Razy.D992A5
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.ATDT
CynetMalicious (score: 100)
APEXMalicious
ClamAVWin.Trojan.Kryptik-2162
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.627365
NANO-AntivirusTrojan.Win32.Slym.bfrrwb
SUPERAntiSpywareTrojan.Agent/Gen-RogueRel
AvastWin32:LockScreen-SL [Trj]
TencentMalware.Win32.Gencirc.13b7026a
EmsisoftGen:Variant.Razy.627365 (B)
F-SecureTrojan.TR/Agent.4478945
DrWebBackDoor.Slym.1387
VIPREGen:Variant.Razy.627365
TrendMicroTROJ_GEN.R002C0CIJ23
Trapminemalicious.high.ml.score
FireEyeGeneric.mg.21697b8869be7457
SophosMal/Zbot-KR
SentinelOneStatic AI – Malicious PE
JiangminTrojan/Tepfer.Gen
VaristW32/SuspPack.EX.gen!Eldorado
AviraTR/Agent.4478945
MAXmalware (ai score=100)
Antiy-AVLTrojan[PSW]/Win32.Tepfer
Kingsoftmalware.kb.a.1000
XcitiumTrojWare.Win32.Kryptik.ATK@4tkxxm
MicrosoftBackdoor:Win32/Kelihos.F
ViRobotTrojan.Win32.Z.Razy.767488.A
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.627365
GoogleDetected
AhnLab-V3Trojan/Win32.Tepfer.R50859
Acronissuspicious
BitDefenderThetaGen:NN.ZexaF.36792.UuW@a0Z7wSh
ALYacGen:Variant.Razy.627365
TACHYONTrojan-PWS/W32.Tepfer.767488.BJ
VBA32Heur.Trojan.Hlux
Cylanceunsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_GEN.R002C0CIJ23
RisingStealer.Fareit!8.170 (TFE:2:7YMh6vjzolB)
YandexTrojan.Kryptik!pgsU0laUIgY
IkarusGen:Heur
MaxSecureTrojan.Malware.5230597.susgen
FortinetW32/Krypt.HAHA!tr
AVGWin32:LockScreen-SL [Trj]
Cybereasonmalicious.019c50
DeepInstinctMALICIOUS

How to remove Razy.627365?

Razy.627365 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment