Ransom Trojan

Trojan.Ransom.AWN removal guide

Malware Removal

The Trojan.Ransom.AWN is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.AWN virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (1 unique times)
  • Enumerates user accounts on the system
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Looks up the external IP address
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Exhibits behavior characteristic of Cerber ransomware
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • Mimics the file times of a Windows system file
  • Installs itself for autorun at Windows startup
  • Creates a hidden or system file
  • EternalBlue behavior
  • Creates a copy of itself
  • Attempts to create or modify system certificates
  • Generates some ICMP traffic
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

ipinfo.io

How to determine Trojan.Ransom.AWN?


File Info:

crc32: 22077B0E
md5: ea6490525d4aba5482a2caf534280ebe
name: EA6490525D4ABA5482A2CAF534280EBE.mlw
sha1: 2a34bb0cd6986126be3cfc26403ac0b1129f8271
sha256: 00977da0c81b39ff253fc4e41c7d3d5d60e5cdc0029bb0cc61eaa8118427a24f
sha512: 8dcea6edd9544c285e5e87ac3b90df1489846b655ec067ba9e71cc406ea374a2b21ee629223a8db713ae00fb016e20909081d3371804d0f494bb21ca4c40415c
ssdeep: 1536:8B0bqfIwVTXtWgk6QoQxnSSgpMe9zcmAnFasTwzE5JuE0lgFmw:8BL1VTdWgkXoyhCrQFXwzuuE0lsmw
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: xa9 Uncombustible Wob
InternalName: bouget
FileVersion: 9.5
CompanyName: Uncombustible Wob
ProductName: bouget mohos
ProductVersion: 9.5
FileDescription: bouget slog
OriginalFilename: bouget.exe
Translation: 0x0409 0x04b0

Trojan.Ransom.AWN also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 0055e3ef1 )
LionicTrojan.Win32.Zerber.j!c
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.4691
CynetMalicious (score: 100)
ALYacTrojan.Ransom.AWN
CylanceUnsafe
ZillyaTrojan.Zerber.Win32.110
CrowdStrikewin/malicious_confidence_100% (W)
K7GWTrojan ( 0055e3ef1 )
Cybereasonmalicious.25d4ab
CyrenW32/Cerber.P.gen!Eldorado
ESET-NOD32Win32/Filecoder.Cerber.B
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Cerber-7725476-0
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.AWN
NANO-AntivirusTrojan.Win32.Encoder.fcdwxs
MicroWorld-eScanTrojan.Ransom.AWN
TencentMalware.Win32.Gencirc.10bf2caa
Ad-AwareTrojan.Ransom.AWN
SophosML/PE-A + Mal/Cerber-C
BitDefenderThetaGen:NN.ZexaF.34142.gi1@auvv0oki
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_CERBER.CBQ165U
McAfee-GW-EditionBehavesLike.Win32.Trojan.cc
FireEyeGeneric.mg.ea6490525d4aba54
EmsisoftTrojan.Ransom.AWN (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.Zerber.es
WebrootTrojan.Dropper.Gen
AviraHEUR/AGEN.1117621
Antiy-AVLTrojan/Generic.ASMalwS.18E9964
MicrosoftRansom:Win32/Cerber
ArcabitTrojan.Ransom.AWN
SUPERAntiSpywareTrojan.Agent/Gen-Malagent
GDataTrojan.Ransom.AWN
AhnLab-V3Trojan/Win32.Cerber.R182504
Acronissuspicious
McAfeeGenericRXAA-AA!EA6490525D4A
MAXmalware (ai score=89)
VBA32BScope.Trojan.Encoder
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_CERBER.CBQ165U
RisingTrojan.Generic@ML.94 (RDML:mgi51uu3LXC6Ug2b1vD9/A)
YandexTrojan.Zerber!edljiom+xLE
IkarusTrojan.Win32.Filecoder
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/Kryptik.EYKI!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan.Ransom.AWN?

Trojan.Ransom.AWN removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment