Trojan

Trojan.RaccryptPMF.S25821534 information

Malware Removal

The Trojan.RaccryptPMF.S25821534 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.RaccryptPMF.S25821534 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • Enumerates the modules from a process (may be used to locate base addresses in process injection)
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid
  • CAPE detected the RedLine malware family

How to determine Trojan.RaccryptPMF.S25821534?


File Info:

name: 520E90300C99DE08645A.mlw
path: /opt/CAPEv2/storage/binaries/ee23f4d44cf618e05d480cb1dc2c7db45a64e1d9bad45d98412b6981e576d661
crc32: BE44B328
md5: 520e90300c99de08645a714f6bde9fcf
sha1: 71bc9f1dda1481f9f769781050ec34d49c1631e0
sha256: ee23f4d44cf618e05d480cb1dc2c7db45a64e1d9bad45d98412b6981e576d661
sha512: 8dbed907e1a430b73432450ea548fe81346d9f102b16e58fe607f0a25d629d1d0e74a3493cdde1adc60d160afbd55658e1fa3048381cb28b3741e20f8eec2213
ssdeep: 6144:ZpLl5oRwbXFY9IwfcTJHF0pFW/5fnOCixB/tJ2l7ITsq:Zpx5oRyX5wUNHF0iR6x/J2l7
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T1D484F1DDB5F2F472C19634718825CB917A7BB822DA70609B337D276F5FB02C14A26316
sha3_384: 71ff90f0ff7af74b7f5fcc2e32ee04d32cb03c13833379dd10c52d489b07f1b0f468fe0410d55210711d2dd8fd07bfcc
ep_bytes: e8b5360000e979feffff8bff558bec8b
timestamp: 2021-06-01 17:49:48

Version Info:

InternationalName: bomgvioci.iwa
Copyright: Copyrighz (C) 2021, fudkort
ProjectVersion: 3.14.72.77
Translation: 0x0129 0x07bc

Trojan.RaccryptPMF.S25821534 also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Stealer.l!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKD.47959097
FireEyeGeneric.mg.520e90300c99de08
CAT-QuickHealTrojan.RaccryptPMF.S25821534
ALYacTrojan.GenericKD.47959097
MalwarebytesTrojan.MalPack.GS
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0058c5691 )
AlibabaRansom:Win32/StopCrypt.6688af19
K7GWTrojan ( 0058c5691 )
Cybereasonmalicious.dda148
CyrenW32/Kryptik.FWV.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HNVG
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Dropper.Lockbit-9917808-0
KasperskyHEUR:Trojan.Win32.Agent.gen
BitDefenderTrojan.GenericKD.47959097
AvastWin32:CrypterX-gen [Trj]
TencentMalware.Win32.Gencirc.11dfc2a2
Ad-AwareTrojan.GenericKD.47959097
EmsisoftTrojan.GenericKD.47959097 (B)
ComodoMalware@#mj021dceyu5l
DrWebTrojan.MulDrop19.20472
ZillyaTrojan.Kryptik.Win32.3663046
TrendMicroTROJ_GEN.R002C0PLS21
McAfee-GW-EditionBehavesLike.Win32.Generic.fh
SophosMal/Generic-S + Mal/Agent-AWV
SentinelOneStatic AI – Malicious PE
GDataWin32.Trojan.BSE.16VOW5Z
JiangminTrojan.Agent.dtsa
AviraTR/Crypt.Agent.zgdvu
Antiy-AVLTrojan/Generic.ASMalwS.350BCB7
KingsoftWin32.Troj.Undef.(kcloud)
ViRobotTrojan.Win32.Z.Agent.407552.IY
MicrosoftRansom:Win32/StopCrypt.MZD!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.FSWW.R461351
Acronissuspicious
McAfeeLockbit-FSWW!520E90300C99
MAXmalware (ai score=88)
VBA32BScope.Trojan.Agent
CylanceUnsafe
TrendMicro-HouseCallTROJ_GEN.R002C0PLS21
RisingSpyware.Stealer!8.3090 (C64:YzY0OmzlQozYtEy8)
IkarusTrojan.Win32.Crypt
FortinetW32/GenKryptik.ERHN!tr
BitDefenderThetaGen:NN.ZexaF.34160.yuW@aaL!i1aK
AVGWin32:CrypterX-gen [Trj]
PandaTrj/Genetic.gen
CrowdStrikewin/malicious_confidence_100% (W)

How to remove Trojan.RaccryptPMF.S25821534?

Trojan.RaccryptPMF.S25821534 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment