Malware

Razy.812456 (file analysis)

Malware Removal

The Razy.812456 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.812456 virus can do?

  • Attempts to connect to a dead IP:Port (1 unique times)
  • Presents an Authenticode digital signature
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Collects information to fingerprint the system

Related domains:

downloader.aldtop.com
client.aldtop.com

How to determine Razy.812456?


File Info:

crc32: 353EA760
md5: b58466e2cbdf5837879e138224f80713
name: B58466E2CBDF5837879E138224F80713.mlw
sha1: 60f462b9939932883456137b2b37a2bb381e88e1
sha256: 01c055adba87bfbb7973e239c8bf8aaf7f15e027d51884e48671faf97c53155c
sha512: c7268d786b54ca289540848d5eabc5ef05151f54fe0898c2a1f5aa4572f2492045068cdbd9279311092a1816f0fd8ee83ec564582493628f5255a5591aee76a3
ssdeep: 24576:Pn7EM0Q9t4hoyU1OqK9l88Zu+xpOLTqO+Qj5Sd:QM1mUjK388ZzpOLKQjwd
type: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed

Version Info:

LegalCopyright: Copyright (C) 2018
InternalName: FastDownloader.exe
FileVersion: 3.2.0.8
CompanyName: -
ProductName: x8f6fx4ef6x4e0bx8f7dx5668
ProductVersion: 3.2.0.8
FileDescription:
OriginalFilename: FastDownloader.exe
Translation: 0x0804 0x04b0

Razy.812456 also known as:

K7AntiVirusRiskware ( 0049f6ae1 )
Elasticmalicious (high confidence)
DrWebAdware.Downware.19825
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Downer
ALYacGen:Variant.Razy.812456
CylanceUnsafe
SangforPUP.Win32.Downer.mt
CrowdStrikewin/malicious_confidence_100% (D)
AlibabaDownloader:Win32/Downer.6518dec8
K7GWRiskware ( 0049f6ae1 )
Cybereasonmalicious.2cbdf5
CyrenW32/Trojan.XUHI-3162
SymantecML.Attribute.HighConfidence
APEXMalicious
AvastWin32:WormX-gen [Wrm]
Kasperskynot-a-virus:Downloader.Win32.Agent.mquf
BitDefenderGen:Variant.Razy.812456
NANO-AntivirusTrojan.Win32.Razy.iuoihf
MicroWorld-eScanGen:Variant.Razy.812456
Ad-AwareGen:Variant.Razy.812456
SophosDowner (PUA)
FireEyeGen:Variant.Razy.812456
EmsisoftGen:Variant.Razy.812456 (B)
SentinelOneStatic AI – Suspicious PE
JiangminDownloader.Agent.oro
WebrootW32.Adware.Gen
eGambitUnsafe.AI_Score_87%
MicrosoftPUA:Win32/Downer
GridinsoftAdware.Agent.sd!c
ArcabitTrojan.Razy.DC65A8
GDataGen:Variant.Razy.812456
AhnLab-V3PUP/Win32.RL_Downloader.R367892
McAfeeArtemis!B58466E2CBDF
MAXmalware (ai score=86)
VBA32Downloader.Agent
MalwarebytesPUP.Optional.ChinAd
PandaTrj/CI.A
TrendMicro-HouseCallTROJ_GEN.R002H0CDR21
RisingAdware.Downloader!1.CB5D (CLOUD)
IkarusPUA.RiskWare.Downer
FortinetRiskware/Downer.DD89
AVGWin32:WormX-gen [Wrm]

How to remove Razy.812456?

Razy.812456 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment