Ransom Trojan

Trojan-Ransom.Win32.Foreign.okcb (file analysis)

Malware Removal

The Trojan-Ransom.Win32.Foreign.okcb is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.Foreign.okcb virus can do?

  • Executable code extraction
  • Injection with CreateRemoteThread in a remote process
  • Attempts to connect to a dead IP:Port (3 unique times)
  • Creates RWX memory
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • Unconventionial language used in binary resources: Portuguese (Brazilian)
  • The binary likely contains encrypted or compressed data.
  • Uses Windows utilities for basic functionality
  • Sniffs keystrokes
  • A process attempted to delay the analysis task by a long amount of time.
  • Creates or sets a registry key to a long series of bytes, possibly to store a binary or malware config
  • A system process is generating network traffic likely as a result of process injection
  • Installs itself for autorun at Windows startup
  • Creates a copy of itself
  • Creates a slightly modified copy of itself

Related domains:

z.whorecord.xyz
a.tomx.xyz
resolver1.opendns.com
myip.opendns.com
winserver-cdn.at

How to determine Trojan-Ransom.Win32.Foreign.okcb?


File Info:

crc32: 917421C2
md5: 301b87d11b03474fa8d37858ae2b4b12
name: updater.exe
sha1: 1a9447405d9c6647a892406766c93b10ff825437
sha256: c6cf5bb08cb44598b5d1e0c920f15036802ed4a8354600dec5372a5a2a217383
sha512: 0effeebe2e9d95985e082a9ef2b955f61997ae863878c4f1f723f54e5f3493a7ebb8e52aee3cba555bc5c7632ca09d85ef1ef3cf59717575b709a556f0626850
ssdeep: 12288:WDmYQWqReNX3l6uKbrUB3FSaI+KDnWaGIU/Ry0K/XNLJz8:WarHkljE2MaxKDnNU/U0K/9x
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

Translation: 0x0215 0x04e5

Trojan-Ransom.Win32.Foreign.okcb also known as:

MicroWorld-eScanTrojan.GenericKD.32949486
FireEyeGeneric.mg.301b87d11b03474f
CAT-QuickHealTrojan.Multi
Qihoo-360HEUR/QVM10.1.9D1D.Malware.Gen
McAfeeGenericRXJL-HP!301B87D11B03
CylanceUnsafe
SangforMalware
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderTrojan.GenericKD.32949486
K7GWTrojan ( 0055ea461 )
K7AntiVirusTrojan ( 0055ea461 )
Invinceaheuristic
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.HAFU
AvastWin32:MalwareX-gen [Trj]
GDataTrojan.GenericKD.32949486
KasperskyTrojan-Ransom.Win32.Foreign.okcb
AlibabaRansom:Win32/Foreign.c12b8a2e
AegisLabTrojan.Multi.Generic.4!c
RisingTrojan.Kryptik!1.C1B6 (CLOUD)
Ad-AwareTrojan.GenericKD.32949486
EmsisoftTrojan.GenericKD.32949486 (B)
F-SecureTrojan.TR/AD.Ursnif.qhspx
DrWebTrojan.Siggen9.3732
McAfee-GW-EditionBehavesLike.Win32.Generic.hc
SentinelOneDFI – Malicious PE
SophosMal/Generic-S
APEXMalicious
WebrootW32.Trojan.Gen
AviraTR/AD.Ursnif.qhspx
Endgamemalicious (high confidence)
ArcabitTrojan.Generic.D1F6C4EE
AhnLab-V3Trojan/Win32.MalPe.R309623
ZoneAlarmTrojan-Ransom.Win32.Foreign.okcb
MicrosoftTrojanSpy:Win32/Ursnif!MTB
Acronissuspicious
ALYacTrojan.GenericKD.32949486
MAXmalware (ai score=83)
MalwarebytesTrojan.MalPack.GS.Generic
PandaTrj/GdSda.A
IkarusTrojan.Win32.Crypt
eGambitUnsafe.AI_Score_97%
AVGWin32:MalwareX-gen [Trj]
Cybereasonmalicious.05d9c6
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.Foreign.okcb?

Trojan-Ransom.Win32.Foreign.okcb removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment