Ransom Trojan

Trojan-Ransom.Win32.Cryptor.fep (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Cryptor.fep is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Cryptor.fep virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Anomalous file deletion behavior detected (10+)
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • The binary likely contains encrypted or compressed data.
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Writes a potential ransom message to disk
  • A process attempted to delay the analysis task by a long amount of time.
  • Attempts to modify proxy settings

How to determine Trojan-Ransom.Win32.Cryptor.fep?


File Info:

name: 500316724D48D630C85D.mlw
path: /opt/CAPEv2/storage/binaries/31c5abb531e8e0fc612239f9c91011a5a7cbce3bb6f820f0521021e05add9e49
crc32: E6CCA0B2
md5: 500316724d48d630c85dd7caec0b18e3
sha1: 55adc49dd4347069c58236c53b930e71e4a68f8e
sha256: 31c5abb531e8e0fc612239f9c91011a5a7cbce3bb6f820f0521021e05add9e49
sha512: f3aada9b9107d0320678e7beb80cf5ebe013a1e419d86ab120bf282c26d3edda4dc355747c1c357a5d460eabe30ad67938ea9a0737d5fc33c11795f0eae1c178
ssdeep: 768:Dcr+wTqogMcdd/qGWZjVtKKxRrLzmoio9o8lGA5iA74W3Bsp2SV3sK+nGcGTrGCB:D4gZ7WZjH3ij8f5ieSV35GdF
type: PE32 executable (console) Intel 80386, for MS Windows
tlsh: T1EC4302D9EC905331EF960BF5E885CC87FDAA17B082235CCB926DADD97B8C45A1113082
sha3_384: d1fc20b964c4bbaf6c666eb440b70b670008c289011940420e89a423b5c97cf0d1e04aef5d322e7a3c854a6e625812fe
ep_bytes: 6a00e889ffffff33c0c2040000000000
timestamp: 2021-09-04 18:00:27

Version Info:

0: [No Data]

Trojan-Ransom.Win32.Cryptor.fep also known as:

BkavW32.AIDetect.malware1
LionicTrojan.Win32.Cryptor.j!c
Elasticmalicious (high confidence)
ClamAVWin.Ransomware.Sugar-9938412-0
ALYacTrojan.Ransom.Filecoder
MalwarebytesRansom.Encoded01
SangforRansom.Win32.Cryptor.gen
K7AntiVirusTrojan ( 0058ac911 )
BitDefenderGen:Variant.Ransom.Sugar.17
K7GWTrojan ( 0058ac911 )
Cybereasonmalicious.24d48d
CyrenW32/Filecoder.CM.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.OJD
APEXMalicious
Paloaltogeneric.ml
CynetMalicious (score: 100)
KasperskyTrojan-Ransom.Win32.Cryptor.fep
AlibabaRansom:Win32/generic.ali2000010
MicroWorld-eScanGen:Variant.Ransom.Sugar.17
RisingRansom.Cryptor!8.10A9 (CLOUD)
Ad-AwareGen:Variant.Ransom.Sugar.17
EmsisoftGen:Variant.Ransom.Sugar.17 (B)
ZillyaTrojan.Cryptor.Win32.736
TrendMicroTROJ_FRS.0NA103B222
McAfee-GW-EditionBehavesLike.Win32.Generic.qc
FireEyeGeneric.mg.500316724d48d630
SophosMal/Generic-S
SentinelOneStatic AI – Malicious PE
GDataGen:Variant.Ransom.Sugar.17
AviraTR/Dropper.Gen
Antiy-AVLTrojan/Generic.ASMalwS.34D6DB3
GridinsoftRansom.Win32.AI.sa
ArcabitTrojan.Ransom.Sugar.17
MicrosoftRansom:Win32/FileCryptor.MAK!MTB
TACHYONRansom/W32.Enc.59392
AhnLab-V3Trojan/Win.Generic.C4525901
Acronissuspicious
McAfeeGenericRXQS-VX!500316724D48
MAXmalware (ai score=85)
VBA32BScope.TrojanRansom.Cryptor
CylanceUnsafe
PandaTrj/Genetic.gen
TrendMicro-HouseCallTROJ_FRS.0NA103B222
TencentWin32.Trojan.Filecoder.Sqtf
IkarusTrojan-Ransom.FileCrypter
eGambitGeneric.Malware
FortinetW32/Filecoder.OJD!tr.ransom
BitDefenderThetaAI:Packer.456DD6081E
AVGWin32:Malware-gen
AvastWin32:Malware-gen
CrowdStrikewin/malicious_confidence_100% (W)
MaxSecureTrojan.Malware.140086473.susgen

How to remove Trojan-Ransom.Win32.Cryptor.fep?

Trojan-Ransom.Win32.Cryptor.fep removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment