Ransom Trojan

About “Trojan-Ransom.Win32.BlackCat” infection

Malware Removal

The Trojan-Ransom.Win32.BlackCat is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.BlackCat virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • Guard pages use detected – possible anti-debugging.
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • CAPE detected the BlackCat malware family
  • Anomalous binary characteristics

How to determine Trojan-Ransom.Win32.BlackCat?


File Info:

name: FF56E700D15F3D944424.mlw
path: /opt/CAPEv2/storage/binaries/cefea76dfdbb48cfe1a3db2c8df34e898e29bec9b2c13e79ef40655c637833ae
crc32: DE4EA71E
md5: ff56e700d15f3d944424c295eae926d9
sha1: e17dc8062742878b0b5ced2145311929f6f77abd
sha256: cefea76dfdbb48cfe1a3db2c8df34e898e29bec9b2c13e79ef40655c637833ae
sha512: 7e8e0a60351fe66a422410651df15f4e15304339cbcccb25109de4d3aaf28b236c077eb5dc0ce21e3389f9bee8a3a184e0afa79c2f88d5a660c1f86c3247b1a7
ssdeep: 49152:BEqvaaAjc2hdKjb8WXqE1PiEbE/TKMt+/RgaJ2wW:BbyaALKjwWXV1P9o4vwwW
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T11AB57C45F66391FDCD672930301EB23BE7301919421E9FA7EBED9D60FB2EB011909A19
sha3_384: 7d97c78774e051237d3b721a54f581ac355d5888e1464bb32766b993392c0954f13dac8437161b8990003c520c0039b6
ep_bytes: 83ec0cc70538e5620001000000e8bee5
timestamp: 2021-11-18 10:04:28

Version Info:

0: [No Data]

Trojan-Ransom.Win32.BlackCat also known as:

LionicTrojan.Win32.BlackCat.4!c
CynetMalicious (score: 100)
CAT-QuickHealRansom.Blackcat.S26416946
ALYacTrojan.Ransom.BlackCat
CylanceUnsafe
SangforRansom.Win32.BlackCat.gen
K7AntiVirusTrojan ( 0058bae31 )
K7GWTrojan ( 0058bae31 )
CrowdStrikewin/malicious_confidence_100% (W)
SymantecRansom.Noberus
ESET-NOD32Win32/Filecoder.BlackCat.A
APEXMalicious
AvastWin32:RansomX-gen [Ransom]
ClamAVWin.Ransomware.BlackCat-9934796-0
KasperskyHEUR:Trojan-Ransom.Win32.BlackCat.gen
BitDefenderTrojan.GenericKD.47844846
MicroWorld-eScanTrojan.GenericKD.47844846
Ad-AwareTrojan.GenericKD.47844846
SophosTroj/Ransom-GMB
ComodoMalware@#1u2fezq0ezdta
DrWebTrojan.Ransom.814
ZillyaTrojan.Filecoder.Win32.21193
TrendMicroRansom.Win32.BLACKCAT.A
McAfee-GW-EditionBehavesLike.Win32.Rootkit.vh
FireEyeGeneric.mg.ff56e700d15f3d94
EmsisoftTrojan.GenericKD.47844846 (B)
IkarusTrojan-Ransom.FileCrypter
GDataTrojan.GenericKD.47844846
JiangminTrojan.BlackCat.a
WebrootW32.Ransom.Blackcat
AviraTR/Redcap.yolec
Antiy-AVLTrojan/Generic.ASMalwS.34E8B3D
KingsoftWin32.Troj.Undef.(kcloud)
ArcabitTrojan.Generic.D2DA0DEE
MicrosoftRansom:Win32/Aicat.A!ml
AhnLab-V3Trojan/Win.Generic.C4830638
McAfeeRansom-BlackCat!FF56E700D15F
MAXmalware (ai score=89)
VBA32TrojanRansom.BlackCat
MalwarebytesRansom.FileCryptor
TrendMicro-HouseCallRansom.Win32.BLACKCAT.A
RisingRansom.Blackcat!1.DB0B (CLOUD)
MaxSecureTrojan.Malware.133591823.susgen
FortinetW32/PossibleThreat
BitDefenderThetaGen:NN.ZexaCO.34212.lIW@aO3qhC
AVGWin32:RansomX-gen [Ransom]
Cybereasonmalicious.627428
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.BlackCat?

Trojan-Ransom.Win32.BlackCat removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment