Ransom Trojan

What is “Trojan-Ransom.Win32.SageCrypt.m”?

Malware Removal

The Trojan-Ransom.Win32.SageCrypt.m is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan-Ransom.Win32.SageCrypt.m virus can do?

  • Executable code extraction
  • Creates RWX memory
  • Reads data out of its own binary image
  • Creates an excessive number of UDP connection attempts to external IP addresses
  • The binary likely contains encrypted or compressed data.
  • EternalBlue behavior
  • Generates some ICMP traffic
  • Collects information to fingerprint the system
  • Anomalous binary characteristics

Related domains:

z.whorecord.xyz
mbfce24rgn65bx3g.rzunt3u2.com
mbfce24rgn65bx3g.er29sl.com
a.tomx.xyz

How to determine Trojan-Ransom.Win32.SageCrypt.m?


File Info:

crc32: 6CB10042
md5: a5f13f85014ef0fbdef580906b2db77f
name: A5F13F85014EF0FBDEF580906B2DB77F.mlw
sha1: f60d3a290cc9a1b4b6a83e267f335b77a638411f
sha256: 60e3173d7b7931edbdf4284a95cb597d9f1dc97eab7a8d0435716c6b5ba5b663
sha512: 0848a684551afb4c0b33ab7fd8edddb3353f999f20d34895021ff1c58a73b6714ac8f8a678799d4722a936725eca433c12221a697e18442ff377244dbefce7ab
ssdeep: 6144:+M1bR5erR7vwO4SF/DQMT1HgMJXXZbeVvc4dwxBEXJL7pOtNHGgH7JJ:+MNRYmErQwgGXJipc4dwxBEXJL7pOtNj
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

LegalCopyright: Copyright xa9 aksqh bqquwwoc kqw
InternalName: Caulswtcno
FileVersion: 4.300
CompanyName: H zgsc fqx foz
ProductName: Vsya pv q wrcfxuj
ProductVersion: 4.300
FileDescription: Iujnlav qqvow f av vvttzg
OriginalFilename: Caulswtcno
Translation: 0x0017 0x0002

Trojan-Ransom.Win32.SageCrypt.m also known as:

BkavW32.AIDetect.malware2
K7AntiVirusTrojan ( 005036521 )
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.10180
CynetMalicious (score: 100)
ALYacGen:Variant.Ransom.Sage.30
CylanceUnsafe
ZillyaTrojan.SageCrypt.Win32.2
CrowdStrikewin/malicious_confidence_80% (D)
K7GWTrojan ( 005036521 )
Cybereasonmalicious.5014ef
CyrenW32/Trojan.XDNM-9194
SymantecRansom.Cry
ESET-NOD32a variant of Win32/Kryptik.FSFF
APEXMalicious
AvastWin32:Trojan-gen
ClamAVWin.Ransomware.Sage-5744913-0
KasperskyTrojan-Ransom.Win32.SageCrypt.m
BitDefenderGen:Variant.Ransom.Sage.30
NANO-AntivirusTrojan.Win32.SageCrypt.ekuiyn
MicroWorld-eScanGen:Variant.Ransom.Sage.30
TencentMalware.Win32.Gencirc.10bb7fc0
Ad-AwareGen:Variant.Ransom.Sage.30
SophosML/PE-A + Troj/Ransom-EDF
ComodoMalware@#19q40kab0wvsy
BitDefenderThetaGen:NN.ZexaF.34170.sq1@aWUGfdgi
VIPRETrojan.Win32.Generic!BT
TrendMicroRansom_HPMILICRY.SM1
McAfee-GW-EditionGenericRXAW-UF!A5F13F85014E
FireEyeGeneric.mg.a5f13f85014ef0fb
EmsisoftGen:Variant.Ransom.Sage.30 (B)
SentinelOneStatic AI – Malicious PE
JiangminTrojan.SageCrypt.ly
AviraHEUR/AGEN.1118861
Antiy-AVLTrojan/Generic.ASMalwS.1E4EF86
KingsoftWin32.Troj.Undef.(kcloud)
MicrosoftRansom:Win32/Milicry
GDataGen:Variant.Ransom.Sage.30
AhnLab-V3Trojan/Win32.SageCrypt.C1764109
Acronissuspicious
McAfeeGenericRXAW-UF!A5F13F85014E
MAXmalware (ai score=100)
VBA32SScope.TrojanRansom.WannaCry
PandaTrj/GdSda.A
TrendMicro-HouseCallRansom_HPMILICRY.SM1
RisingRansom.Sage!1.AA7A (CLASSIC)
YandexTrojan.GenKryptik!lTblm+0uZBg
IkarusTrojan-Ransom.Sage
FortinetW32/Kryptik.FNGP!tr
AVGWin32:Trojan-gen
Paloaltogeneric.ml

How to remove Trojan-Ransom.Win32.SageCrypt.m?

Trojan-Ransom.Win32.SageCrypt.m removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment