Malware

Razy.869479 (file analysis)

Malware Removal

The Razy.869479 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.869479 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • The executable is compressed using UPX
  • Authenticode signature is invalid
  • Attempts to modify proxy settings

How to determine Razy.869479?


File Info:

name: 50FB07104C775BDEE9C9.mlw
path: /opt/CAPEv2/storage/binaries/9286819e652d7f8982312dd54559c2d60a070e8d0d375691973380eed6c812d0
crc32: 5E7674BD
md5: 50fb07104c775bdee9c9f17c2e714d7d
sha1: b4aade9c1729817ec28759a963ca7adb5ec4fbfd
sha256: 9286819e652d7f8982312dd54559c2d60a070e8d0d375691973380eed6c812d0
sha512: 7c3a7d9ed9bc43cd5c48b578c8daf59f126d304e50fae72e596420adfc7c5aef613a351a162d57ad2e944cc9bdbcdb381cba704c1adc427f078e65e7c47f4390
ssdeep: 196608:0XUnJXVScnsVvC2Pi0mZPW90dTA116pYLPYWxSD4mXbEB3HCJYaXDF8BfHdt4yPu:0XQ9VfnoC2EZW90dcb6paYBDxXbc8F8U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T189C633F7AD19A871E4B84D3C7429FB84041F7372A1DE513E8E9ACAE1913ECF161A1607
sha3_384: 1d752ab7416de8cc33003be8a6a1d5f4a8ed3861d4260ae813d39f755918c69fa1138eb295fbbca507b014a34b0d63b7
ep_bytes: 60be00c040068dbe0050fff95783cdff
timestamp: 2015-09-15 22:35:13

Version Info:

FileVersion: 1.0.0.0
FileDescription: 360
ProductName: 文档
ProductVersion: 1.0.0.0
CompanyName: 360
LegalCopyright: 文档
Comments: 文档
Translation: 0x0804 0x04b0

Razy.869479 also known as:

LionicTrojan.Multi.Generic.lpZC
Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.869479
FireEyeGeneric.mg.50fb07104c775bde
McAfeeArtemis!50FB07104C77
SangforSuspicious.Win32.Razy.869479
BitDefenderThetaGen:NN.ZexaF.34182.@pKfa0OP!gmb
CyrenW32/Trojan.CLL.gen!Eldorado
TrendMicro-HouseCallTROJ_GEN.R002H0CB622
BitDefenderGen:Variant.Razy.869479
TencentWin32.Trojan.Qqthief.Auto
VIPRETrojan.Win32.Generic!BT
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
GDataGen:Variant.Razy.869479
AviraHEUR/AGEN.1243822
Antiy-AVLTrojan/Generic.ASCommon.FA
KingsoftWin32.Troj.Undef.(kcloud)
GridinsoftRansom.Win32.Wacatac.sa
ArcabitTrojan.Razy.DD4467
VBA32BScope.Trojan.Casur
MAXmalware (ai score=85)
MalwarebytesMalware.Heuristic.1003
APEXMalicious
RisingMalware.Heuristic!ET#81% (RDMK:cmRtazpuQvlkqdUaQn0wdMkDdyln)
FortinetW32/CoinMiner.65CA!tr

How to remove Razy.869479?

Razy.869479 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment