Malware

Razy.956138 (file analysis)

Malware Removal

The Razy.956138 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Razy.956138 virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Reads data out of its own binary image
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Harvests cookies for information gathering
  • Anomalous binary characteristics

How to determine Razy.956138?


File Info:

name: 3A2F691DA6F0C8D62549.mlw
path: /opt/CAPEv2/storage/binaries/068908894c2f20c785e7974b360b5b0fe1410cca86b4913fef53773993cdc050
crc32: 901EC6B8
md5: 3a2f691da6f0c8d625497e715696ce2a
sha1: 874bf7c2bdd3d39b9505349d0878796fdcf985b5
sha256: 068908894c2f20c785e7974b360b5b0fe1410cca86b4913fef53773993cdc050
sha512: a79378c9919df70adf8a28546b45f87d0e596680a34d0a1512cda46355ab0207d550c048165c5154c01c74456cd2f73e55b172203e44644abc4d6c8d9e536bf1
ssdeep: 49152:mORqBZc7IYwHpPbsPhSCKdRdkpfmSKTUgixB7/gMEgw918QlKx9byuGUU:zqBZcTgtbsPIk9F3gi7IOwjCxXh
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18246F59E7CF8C79BC0279AF4C75DE3C1693FDC8A5612E1D6ACE68D806DA16C2C861344
sha3_384: 67063c387a9c04b3c0033e0a00cd0721a6b09abd28eefa641214b1b0e2d4467e7e1deb79ec7eddb7c34daf6072eeb3a4
ep_bytes: ff250020400000000000000000000000
timestamp: 2021-10-09 10:31:19

Version Info:

Translation: 0x0000 0x04b0
Comments:
CompanyName: HP Inc.
FileDescription: DataDestroyer
FileVersion: 1.0.0.0
InternalName: DataDestroyer.exe
LegalCopyright: Copyright © HP Inc. 2021
LegalTrademarks:
OriginalFilename: DataDestroyer.exe
ProductName: DataDestroyer
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

Razy.956138 also known as:

Elasticmalicious (high confidence)
MicroWorld-eScanGen:Variant.Razy.956138
FireEyeGeneric.mg.3a2f691da6f0c8d6
McAfeeArtemis!3A2F691DA6F0
CylanceUnsafe
SangforSuspicious.Win32.Save.a
SymantecML.Attribute.HighConfidence
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Malware.Generic-9877901-0
BitDefenderGen:Variant.Razy.956138
AvastWin32:Malware-gen
Ad-AwareGen:Variant.Razy.956138
EmsisoftGen:Variant.Razy.956138 (B)
McAfee-GW-EditionBehavesLike.Win32.Generic.th
SophosGeneric ML PUA (PUA)
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.PSE.1650V88
eGambitUnsafe.AI_Score_100%
ArcabitTrojan.Razy.DE96EA
MicrosoftTrojan:Win32/Wacatac.B!ml
CynetMalicious (score: 100)
AhnLab-V3Malware/Win.Generic.C4718200
BitDefenderThetaGen:NN.ZemsilF.34294.@x0@aG5tymp
ALYacGen:Variant.Razy.956138
MAXmalware (ai score=86)
TrendMicro-HouseCallTROJ_GEN.R002H09J921
RisingMalware.Heuristic!ET#77% (RDMK:cmRtazrM5n4S9PfcSeEnWp3znmmH)
FortinetW32/PossibleThreat
AVGWin32:Malware-gen

How to remove Razy.956138?

Razy.956138 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment