Ransom Trojan

Trojan.Ransom.BLH information

Malware Removal

The Trojan.Ransom.BLH is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan.Ransom.BLH virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • A process attempted to delay the analysis task.
  • At least one IP Address, Domain, or File Name was found in a crypto call
  • A named pipe was used for inter-process communication
  • Reads data out of its own binary image
  • A process created a hidden window
  • Drops a binary and executes it
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Attempts to delete volume shadow copies
  • Attempts to repeatedly call a single API many times in order to delay analysis time
  • Modifies boot configuration settings
  • Installs itself for autorun at Windows startup
  • Exhibits possible ransomware file modification behavior
  • Creates a hidden or system file
  • EternalBlue behavior
  • Creates a copy of itself
  • Generates some ICMP traffic
  • Appends a known Sage ransomware file extension to files that have been encrypted
  • Collects information to fingerprint the system
  • Anomalous binary characteristics
  • Uses suspicious command line tools or Windows utilities

Related domains:

mbfce24rgn65bx3g.k5hjej9.com

How to determine Trojan.Ransom.BLH?


File Info:

crc32: 72CD2C7A
md5: afc47b0a117b24ba124f0f6531405418
name: AFC47B0A117B24BA124F0F6531405418.mlw
sha1: 9f7d644e0b85c96539e68e12b52b810ac0bb6177
sha256: 44bb2eae6e0fb4515cb3e0ca30041c5d890c963bb82e415ab1755c997b138069
sha512: 556f3f1ad73e178f4e444709d8d8ed92aec19caf1c6e6324d14ca13a9b6a6dd17cb77354028d53369794f070908750ee0670b7c57d0fb92d82929fed5f9717ed
ssdeep: 6144:MwKqKTIWySCGs/o70KGdmIN9zl30QbQnkfnU:MwKqKTCGsBKGdmIx30UfU
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright 2016 Adobe Systems Incorporated. All rights reserved.
InternalName: Adobe Application Manager
CompanyName: Adobe Systems Incorporated
ProductName: Adobe Application Manager
ProductVersion: 1.0.0.45
FileDescription: Adobe Application Manager
Translation: 0x0409 0x04b0

Trojan.Ransom.BLH also known as:

BkavW32.AIDetect.malware1
K7AntiVirusTrojan ( 00506bda1 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10307
CynetMalicious (score: 99)
ALYacTrojan.Ransom.BLH
CylanceUnsafe
ZillyaTrojan.SageCrypt.Win32.139
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_100% (W)
AlibabaTrojan:Win32/Kryptik.9a43da27
K7GWTrojan ( 00506bda1 )
Cybereasonmalicious.a117b2
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HAGO
APEXMalicious
AvastWin32:Malware-gen
KasperskyHEUR:Trojan.Win32.Generic
BitDefenderTrojan.Ransom.BLH
NANO-AntivirusTrojan.Win32.SageCrypt.elyzqn
MicroWorld-eScanTrojan.Ransom.BLH
TencentMalware.Win32.Gencirc.114add6a
Ad-AwareTrojan.Ransom.BLH
SophosML/PE-A + Troj/Sage-O
ComodoMalware@#39ij8a1hyfwai
BitDefenderThetaGen:NN.ZexaF.34758.pq1@a80bWIli
VIPRETrojan.Win32.Generic!BT
TrendMicroMal_Cerber-23
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.afc47b0a117b24ba
EmsisoftTrojan.Ransom.BLH (B)
SentinelOneStatic AI – Malicious PE
AviraHEUR/AGEN.1127225
eGambitGeneric.Malware
Antiy-AVLTrojan/Generic.ASMalwS.1EAD82B
MicrosoftRansom:Win32/Milicry!bit
ArcabitTrojan.Ransom.BLH
AegisLabTrojan.Win32.Generic.4!c
GDataTrojan.Ransom.BLH
TACHYONRansom/W32.SageCrypt.259840
AhnLab-V3Trojan/Win32.SageCrypt.C1815213
McAfeeGenericR-JKZ!AFC47B0A117B
MAXmalware (ai score=100)
VBA32BScope.Trojan.Encoder
PandaTrj/CI.A
TrendMicro-HouseCallMal_Cerber-23
RisingTrojan.Generic@ML.100 (RDML:gTkw8kzCOgx07mnjZ96g5w)
IkarusTrojan.Win32.Crypt
FortinetW32/Generic.AC.3D6482!tr
AVGWin32:Malware-gen
Paloaltogeneric.ml

How to remove Trojan.Ransom.BLH?

Trojan.Ransom.BLH removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment