Malware

Razy.883920 (B) (file analysis)

Malware Removal

The Razy.883920 (B) is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.883920 (B) virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Repeatedly searches for a not-found process, may want to run with startbrowser=1 option
  • Reads data out of its own binary image
  • A process created a hidden window
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Deletes its original binary from disk
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Creates a slightly modified copy of itself

Related domains:

www.qZWPX3OtjX.com
pastebin.com
edgedl.me.gvt1.com

How to determine Razy.883920 (B)?


File Info:

crc32: 0C9E25CB
md5: 4e151eedcea7c87526e7895a9cfb816f
name: 4E151EEDCEA7C87526E7895A9CFB816F.mlw
sha1: feaa15f37f1c25221117c250dfb452532d07c6e3
sha256: 754020854084c5e35411673e7aeb22b5e63a64d037c45c43da1ad884f98bc2b5
sha512: cfe6f2ec4f942cd5aed313f58d26df4cbc23054cb643098a9a80202ff75dd6b8bfb89c0690586d519cb30596753d7598c2bd7faf7ebf743a4367cf22395fbef4
ssdeep: 12288:Ll0bUCQnezfDLkgUuCPJObdp+lCRYwLpCjV3bYRjjU:3CQnezfDLlp3ol8tsjqR8
type: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows

Version Info:

0: [No Data]

Razy.883920 (B) also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00577ea11 )
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Razy.883920
CylanceUnsafe
SangforSuspicious.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (D)
K7GWTrojan ( 00577ea11 )
Cybereasonmalicious.dcea7c
CyrenW32/Kryptik.EDI.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJIX
APEXMalicious
AvastWin32:Evo-gen [Susp]
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Razy.883920
NANO-AntivirusVirus.Win32.Gen.ccmw
MicroWorld-eScanGen:Variant.Razy.883920
Ad-AwareGen:Variant.Razy.883920
SophosML/PE-A + Troj/Agent-BGOS
BitDefenderThetaGen:NN.ZexaF.34170.HuZ@aKmWieh
McAfee-GW-EditionBehavesLike.Win32.RAHack.hc
FireEyeGeneric.mg.4e151eedcea7c875
EmsisoftGen:Variant.Razy.883920 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Crypt.XPACK.Gen
eGambitUnsafe.AI_Score_94%
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Razy.883920
AhnLab-V3Malware/Win32.RL_Generic.R293305
McAfeeGlupteba-FTSD!4E151EEDCEA7
MAXmalware (ai score=80)
VBA32BScope.Trojan.Wacatac
RisingTrojan.Kryptik!1.D284 (CLASSIC)
IkarusTrojan.Crypt
MaxSecureTrojan.Malware.121218.susgen
FortinetW32/Kryptik.ECM!tr
AVGWin32:Evo-gen [Susp]

How to remove Razy.883920 (B)?

Razy.883920 (B) removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment