Ransom Trojan

Trojan.Ransom.BlackCat.B information

Malware Removal

The Trojan.Ransom.BlackCat.B is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BlackCat.B virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the BlackCat malware family
  • Anomalous binary characteristics

How to determine Trojan.Ransom.BlackCat.B?


File Info:

name: AEA5D3CCED6725F37E2C.mlw
path: /opt/CAPEv2/storage/binaries/3d7cf20ca6476e14e0a026f9bdd8ff1f26995cdc5854c3adb41a6135ef11ba83
crc32: AFBF2FA6
md5: aea5d3cced6725f37e2c3797735e6467
sha1: 087497940a41d96e4e907b6dc92f75f4a38d861a
sha256: 3d7cf20ca6476e14e0a026f9bdd8ff1f26995cdc5854c3adb41a6135ef11ba83
sha512: 5489753ae1c3ba0dbd3e0ce1b78b0ccba045e534e77fb87c80d56b16229f928c46a15721020142bbc6bd4d1ba5c295f4bec3596efa7b46c906889c156dadbd66
ssdeep: 49152:BEqvaaAjc2hdKjb8WXqE1PiEbE/TKMt3/RgaJ2wW:BbyaALKjwWXV1P9oVvwwW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T121B57C45F66391FDCD672930301EB23BE7301919421E9FA7EBED9D60FB2EB011909A19
sha3_384: 5a94307d2a63f32b9a0724372217094674072a9f824c930f028579af17c4066711db94fba601cea8124d42dbe2950690
ep_bytes: 83ec0cc70538e5620001000000e8bee5
timestamp: 2021-11-18 10:04:28

Version Info:

0: [No Data]

Trojan.Ransom.BlackCat.B also known as:

LionicTrojan.Win32.BlackCat.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
CAT-QuickHealRansom.Blackcat.S26416946
ALYacTrojan.Ransom.BlackCat
CylanceUnsafe
ZillyaTrojan.Filecoder.Win32.21193
SangforRansom.Win32.BlackCat.gen
K7AntiVirusTrojan ( 0058bae31 )
BitDefenderTrojan.Ransom.BlackCat.B
K7GWTrojan ( 0058bae31 )
Cybereasonmalicious.40a41d
SymantecRansom.Noberus
ESET-NOD32Win32/Filecoder.BlackCat.A
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.BlackCat-9934796-0
KasperskyHEUR:Trojan-Ransom.Win32.BlackCat.gen
MicroWorld-eScanTrojan.Ransom.BlackCat.B
RisingRansom.Blackcat!1.DB0B (CLOUD)
Ad-AwareTrojan.Ransom.BlackCat.B
EmsisoftTrojan.Ransom.BlackCat.B (B)
ComodoMalware@#350t0qsywecha
DrWebTrojan.Ransom.814
TrendMicroRansom.Win32.BLACKCAT.YXBLMA
McAfee-GW-EditionBehavesLike.Win32.Generic.vh
FireEyeGeneric.mg.aea5d3cced6725f3
SophosMal/Generic-R + Troj/Ransom-GMB
JiangminTrojan.BlackCat.a
WebrootW32.Ransom.Blackcat
AviraTR/Redcap.yolec
MAXmalware (ai score=89)
Antiy-AVLTrojan/Generic.ASMalwS.34E8B3D
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Filecoder!MSR
ArcabitTrojan.Ransom.BlackCat.B
ViRobotTrojan.Win32.Z.Ransom.2281472
GDataTrojan.Ransom.BlackCat.B
AhnLab-V3Trojan/Win.Generic.C4830638
McAfeeRansom-BlackCat!AEA5D3CCED67
VBA32TrojanRansom.BlackCat
MalwarebytesRansom.FileCryptor
TrendMicro-HouseCallRansom.Win32.BLACKCAT.YXBLMA
TencentWin32.Trojan.Filecoder.Lqor
IkarusTrojan-Ransom.FileCrypter
eGambitGeneric.Malware
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaCO.34232.lIW@aO3qhC
AVGWin32:RansomX-gen [Ransom]
Paloaltogeneric.ml
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.133591823.susgen

How to remove Trojan.Ransom.BlackCat.B?

Trojan.Ransom.BlackCat.B removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment