Malware

Ser.Razy.12745 (file analysis)

Malware Removal

The Ser.Razy.12745 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Ser.Razy.12745 virus can do?

  • Executable code extraction
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • A process created a hidden window
  • Uses Windows utilities for basic functionality
  • Exhibits behavior characteristic of Cerber ransomware
  • Attempts to execute a binary from a dead or sinkholed URL
  • Writes a potential ransom message to disk
  • Attempts to modify proxy settings
  • Attempts to access Bitcoin/ALTCoin wallets
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

How to determine Ser.Razy.12745?


File Info:

crc32: F6509CB8
md5: c656c3943f38ee6910d6b5f147a521c4
name: C656C3943F38EE6910D6B5F147A521C4.mlw
sha1: 9dbec15ba272862860d7af775b943b1b02d8b98d
sha256: d4a2528db63da155e7079a8a99c545d6feaf6d48f847391227cf5b6fe0b2ee66
sha512: a2060ca3c688e9bf039c6ad6853057adaf7b9419df48454996e85df6cb9caa898bc3880e7c0ab6a39ae55368a3ccf21c625d676c8db4931007964db9d1316848
ssdeep: 6144:zKZl30feXONU/8uu4UqVta/CnXOxHQSy1TihBFtHmZ3+kGEQNbRITHy3Xkepu:zKYWnD1UqvFMHQOiZ3kL1Cy3UAu
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

CompanyName: Oracle Corporation
Translation: 0x0000 0x04b0

Ser.Razy.12745 also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 005224381 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10731
CynetMalicious (score: 100)
CAT-QuickHealRansom.Cerber.A4
ALYacGen:Variant.Ser.Razy.12745
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.1883
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaRansom:Win32/Cerber.ali1020013
K7GWTrojan ( 0050aa741 )
Cybereasonmalicious.43f38e
BaiduWin32.Trojan.Kryptik.alb
CyrenW32/Cerber.F.gen!Eldorado
SymantecPacked.Generic.459
ESET-NOD32a variant of Win32/Kryptik.FQRH
APEXMalicious
AvastWin32:Filecoder-BG [Trj]
ClamAVWin.Dropper.Bunitu-9106841-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderGen:Variant.Ser.Razy.12745
NANO-AntivirusTrojan.Win32.Zerber.enxkdi
MicroWorld-eScanGen:Variant.Ser.Razy.12745
TencentMalware.Win32.Gencirc.10b22ccc
Ad-AwareGen:Variant.Ser.Razy.12745
SophosML/PE-A + Mal/Cerber-B
ComodoTrojWare.Win32.Ransom.Cerber.BP@6xmdf4
BitDefenderThetaGen:NN.ZexaF.34628.Oq2@aONO8nfG
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPCERBER.SMALY5A
McAfee-GW-EditionBehavesLike.Win32.Dropper.jm
FireEyeGeneric.mg.c656c3943f38ee69
EmsisoftGen:Variant.Ser.Razy.12745 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Generic.geygd
WebrootW32.Ransom.Gen
AviraTR/Crypt.ZPACK.Gen7
eGambitUnsafe.AI_Score_99%
MicrosoftRansom:Win32/Cerber.J
ArcabitTrojan.Ser.Razy.D31C9
AegisLabTrojan.Win32.Zerber.j!c
ZoneAlarmHEUR:Trojan.Win32.Generic
GDataGen:Variant.Ser.Razy.12745
AhnLab-V3Win-Trojan/Cerber.Gen
Acronissuspicious
McAfeeRansomware-CBER!C656C3943F38
MAXmalware (ai score=84)
VBA32BScope.TrojanSpy.Zbot
MalwarebytesCerber.Ransom.Encrypt.DDS
PandaTrj/Genetic.gen
TrendMicro-HouseCallRansom_HPCERBER.SMALY5A
RisingTrojan.Kryptik!1.AACA (CLOUD)
YandexTrojan.GenAsa!mQAE2douGqo
IkarusTrojan.Crypt
FortinetW32/Kryptik.HGZD!tr
AVGWin32:Filecoder-BG [Trj]
Qihoo-360Win32/Ransom.Filecoder.HxQBuX8A

How to remove Ser.Razy.12745?

Ser.Razy.12745 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment