Ransom Trojan

Trojan-Ransom.Win32.Cryptor.feg (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Cryptor.feg is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.feg virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Possible date expiration check, exits too soon after checking local time
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization

How to determine Trojan-Ransom.Win32.Cryptor.feg?


File Info:

name: BB62265E269998FE3BC8.mlw
path: /opt/CAPEv2/storage/binaries/a373c1bd0989c3824565aff5e1d4b21d269c49e27a9c5aeac886b10ddc01e308
crc32: DA7E3454
md5: bb62265e269998fe3bc80173d13f543f
sha1: 284d4a61e852fee9efcbec4e2054a1f75a7be05f
sha256: a373c1bd0989c3824565aff5e1d4b21d269c49e27a9c5aeac886b10ddc01e308
sha512: 07d1fbc0db90a2b46e6303e4dba0cead78512b2f8844c6bbcb3144642be7823535313e270139b35bb4c018349bbcfc56eee3f388a83c8534b0a10bece1b3f3a5
ssdeep: 1536:CwtLBNKODY1J8ua/bnFcNZwRtIjHG0TzSFB7J90H1sk0:CwrkIYkNjnYGqi0iTDy
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T18D43F1B1EFA500F2D99B42BC64AFA006816A9369422577F141EE1D3CB2D73AC55E7032
sha3_384: fd2f9785c7d70461be0451bb475a581af4f59b634639da83cd8d8a1659f574a95e1989a86de0734157789ba80e05cb2e
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.feg also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Sugar.17
MalwarebytesRansom.Encoded01
SangforRansom.Win32.Cryptor.gen
K7AntiVirusTrojan ( 0058ac911 )
BitDefenderGen:Variant.Ransom.Sugar.17
K7GWTrojan ( 0058ac911 )
CrowdStrikewin/malicious_confidence_100% (W)
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
ClamAVWin.Ransomware.Sugar-9938412-0
KasperskyTrojan-Ransom.Win32.Cryptor.feg
AlibabaRansom:Win32/FileCryptor.b0ce872d
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
TencentWin32.Trojan.Filecoder.Pgwg
Ad-AwareGen:Variant.Ransom.Sugar.17
SophosMal/Generic-S
F-SecureTrojan.TR/Dropper.Gen
ZillyaTrojan.Cryptor.Win32.727
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.bb62265e269998fe
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
SentinelOneStatic AI – Malicious PE
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Ransom.Sugar.17
ZoneAlarmTrojan-Ransom.Win32.Cryptor.feg
GDataGen:Variant.Ransom.Sugar.17
TACHYONRansom/W32.Enc.59392
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
McAfeeGenericRXQS-VX!BB62265E2699
MAXmalware (ai score=88)
VBA32BScope.TrojanRansom.Cryptor
CylanceUnsafe
TrendMicro-HouseCallTROJ_FRS.0NA103B222
RisingRansom.Cryptor!8.10A9 (CLOUD)
IkarusTrojan-Ransom.FileCrypter
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
BitDefenderThetaAI:Packer.456DD6081E
AVGWin32:Malware-gen
Cybereasonmalicious.e26999
AvastWin32:Malware-gen
MaxSecureTrojan.Malware.139249074.susgen

How to remove Trojan-Ransom.Win32.Cryptor.feg?

Trojan-Ransom.Win32.Cryptor.feg removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment