Malware

Razy.711958 (file analysis)

Malware Removal

The Razy.711958 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.711958 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Azeri
  • The executable is compressed using UPX
  • Uses Windows utilities for basic functionality
  • Creates a hidden or system file
  • Attempts to modify proxy settings

Related domains:

ecosystem.unvocal.ru
duckandbear.top
www.bing.com

How to determine Razy.711958?


File Info:

crc32: 10AF9384
md5: ef695f9ca0f45fed17e8e6e28880b4f8
name: EF695F9CA0F45FED17E8E6E28880B4F8.mlw
sha1: 19821d7ba552ba474cc1d830937cb4e68a207761
sha256: 0da04fe45addaba03bd636af1c8ba90353c6b1eb0455bbdce67a50c80b0515aa
sha512: 57456650417f41484598c04e89ad2b245a80550afed36d7ac10ec5b7534b8e0e3746138e8e1fff0d5d7420a20e0f81a4471f871c5ae23c023f884c8685a79997
ssdeep: 3072:aIwZrXAeiapjpFjtKIor0P1kzT5NtonurJ+Nw7YsuAg0FujoIOKnx2LHouto6uWt:avf1HhKXr0P8T7+xAONlyHoSpogdGJpm
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, UPX compressed

Version Info:

LegalCopyright: Glorea
InternalName: Glorea
FileVersion: 815.40.30.21
CompanyName: Glorea
ProductName: Glorea
ProductVersion: 210.30.23.13
FileDescription: Glorea
OriginalFilename: Glorea
Translation: 0x0804 0x04b0

Razy.711958 also known as:

BkavW32.AIDetectVM.malware1
Elasticmalicious (high confidence)
FireEyeGeneric.mg.ef695f9ca0f45fed
CAT-QuickHealTrojan.Cryptinject
Qihoo-360HEUR/QVM10.1.0EE9.Malware.Gen
McAfeeArtemis!EF695F9CA0F4
CylanceUnsafe
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan-Downloader ( 005157091 )
BitDefenderGen:Variant.Razy.711958
K7GWTrojan-Downloader ( 005157091 )
CrowdStrikewin/malicious_confidence_100% (D)
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:Evo-gen [Susp]
CynetMalicious (score: 100)
Kasperskynot-a-virus:HEUR:AdWare.Win32.TOVus.gen
NANO-AntivirusTrojan.Win32.Tovkater.esgidz
MicroWorld-eScanGen:Variant.Razy.711958
RisingDownloader.Tovkater!8.E5CE (RDMK:cmRtazo0LwhpwsJufk4P4IFPPaAn)
Ad-AwareGen:Variant.Razy.711958
SophosMal/Generic-S
ComodoPacked.Win32.MUPX.Gen@24tbus
F-SecureAdware.ADWARE/Adware.Gen3
DrWebTrojan.DownLoader25.27784
TrendMicroTROJ_GEN.R03BC0GB121
McAfee-GW-EditionBehavesLike.Win32.Generic.dh
EmsisoftGen:Variant.Razy.711958 (B)
IkarusTrojan-Downloader.Win32.Tovkater
JiangminTrojanDownloader.Generic.awta
AviraADWARE/Adware.Gen3
MAXmalware (ai score=89)
Antiy-AVLGrayWare[AdWare]/Win32.AGeneric
MicrosoftTrojan:Win32/Glupteba!ml
ArcabitTrojan.Razy.DADD16
ZoneAlarmnot-a-virus:HEUR:AdWare.Win32.TOVus.gen
GDataGen:Variant.Razy.711958
AhnLab-V3Adware/Win32.InstallMonster.R229436
Acronissuspicious
VBA32BScope.Trojan.InstallMonster
ALYacGen:Variant.Razy.711958
MalwarebytesAdware.InstallMonster
ESET-NOD32Win32/TrojanDownloader.Tovkater.CK
TrendMicro-HouseCallTROJ_GEN.R03BC0GB121
TencentMalware.Win32.Gencirc.11b8c1d5
YandexTrojan.GenAsa!7pd5/udhH7Y
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_99%
FortinetW32/Tovkater.CK!tr
BitDefenderThetaGen:NN.ZexaF.34804.ru2@aS7FhBcG
AVGWin32:Evo-gen [Susp]
Cybereasonmalicious.ca0f45

How to remove Razy.711958?

Razy.711958 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment