Malware

Razy.847374 (file analysis)

Malware Removal

The Razy.847374 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.847374 virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Creates RWX memory
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • Reads data out of its own binary image
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.

How to determine Razy.847374?


File Info:

crc32: DDA146BC
md5: ad387cc51ba3e836d04bbb9dca95ae50
name: AD387CC51BA3E836D04BBB9DCA95AE50.mlw
sha1: 1c103e3876a503a75605df60a316ae48738c72a3
sha256: cbfe2f27a0635efbbd19b7032ccb31af153db1a7ec8be1e8cdd597800f4f741d
sha512: 98ec7da6a639266a9a4a0a2d6bdcf4506984fb78181ce9ed187554594287cf82c1acc28880d86defb688d10f82a36eb614d028fd20a8cd49f7700c24a53d448a
ssdeep: 6144:gDLlXtjua34IIplI9nj/kSeV38Fk8UdNCV6LNbHwzTG5ggwRH:g/lAaI1lI9j/k9V38Fk8UTxNbU6bwt
type: PE32 executable (DLL) (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

Razy.847374 also known as:

Elasticmalicious (high confidence)
McAfeeArtemis!AD387CC51BA3
CrowdStrikewin/malicious_confidence_80% (W)
BitDefenderGen:Variant.Razy.847374
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 85)
KasperskyHEUR:Trojan.Win32.Trickpak.gen
MicroWorld-eScanGen:Variant.Razy.847374
RisingTrojan.Trickpak!8.122C7 (CLOUD)
Ad-AwareGen:Variant.Razy.847374
SophosMal/Generic-S
TrendMicroTROJ_FRS.VSNTBO21
McAfee-GW-EditionBehavesLike.Win32.Generic.fc
FireEyeGeneric.mg.ad387cc51ba3e836
EmsisoftGen:Variant.Razy.847374 (B)
SentinelOneStatic AI – Malicious PE
WebrootW32.Malware.Gen
AviraTR/Spy.TrickBot.ydcjt
MAXmalware (ai score=80)
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftTrojan:Win32/Wacatac.B!ml
ZoneAlarmHEUR:Trojan.Win32.Trickpak.gen
GDataWin32.Trojan-Spy.TrickBot.LKPS1R
ESET-NOD32a variant of Generik.MTMLTKV
TrendMicro-HouseCallTROJ_FRS.VSNTBO21
IkarusTrojan.SuspectCRC
FortinetW32/Kryptik.HJLB!tr
BitDefenderThetaGen:NN.ZedlaF.34590.vq4@aa5IA8j
AVGWin32:TrojanX-gen [Trj]
AvastWin32:TrojanX-gen [Trj]
Qihoo-360Win32/Heur.Generic.Hx4CfZAA

How to remove Razy.847374?

Razy.847374 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment