Ransom Trojan

UDS:Trojan-Ransom.Win32.Rack (file analysis)

Malware Removal

The UDS:Trojan-Ransom.Win32.Rack is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What UDS:Trojan-Ransom.Win32.Rack virus can do?

  • Executable code extraction
  • Attempts to connect to a dead IP:Port (2 unique times)
  • Creates RWX memory
  • A process attempted to delay the analysis task.
  • Reads data out of its own binary image
  • A process created a hidden window
  • HTTP traffic contains suspicious features which may be indicative of malware related traffic
  • Performs some HTTP requests
  • The binary likely contains encrypted or compressed data.
  • Attempts to delete volume shadow copies
  • Behavior consistent with a dropper attempting to download the next stage.
  • Installs itself for autorun at Windows startup
  • Attempts to modify proxy settings
  • Attempts to modify browser security settings
  • Creates a copy of itself
  • Harvests information related to installed mail clients
  • Collects information to fingerprint the system
  • Uses suspicious command line tools or Windows utilities

Related domains:

z.whorecord.xyz
a.tomx.xyz
yvibiwy.gyhigtotna.com
ipecho.net
uraregek.gyhigtotna.com
adamagojy.gyhigtotna.com
ujyworo.gyhigtotna.com
uqukuh.gyhigtotna.com
yhidovyv.gyhigtotna.com
ihotysohex.gyhigtotna.com
axzpfvac.gyhigtotna.com
ipiwgnrli.gyhigtotna.com
orotep.gyhigtotna.com
ynorywy.gyhigtotna.com
ijkvezuzeg.gyhigtotna.com
anmdaxszywe.gyhigtotna.com
ijeso.gyhigtotna.com
yhihaj.gyhigtotna.com
uxufo.gyhigtotna.com
igafaky.gyhigtotna.com
ojuwa.gyhigtotna.com
emyk.gyhigtotna.com
gredymetuh.gyhigtotna.com
avudur.gyhigtotna.com

How to determine UDS:Trojan-Ransom.Win32.Rack?


File Info:

crc32: 69F837BD
md5: f881a28ba12fb9c19af432c7ea1c6135
name: F881A28BA12FB9C19AF432C7EA1C6135.mlw
sha1: 99bc037f27b3c8194f7f8b9ba9c95763d25477e5
sha256: 46bc37df14130e5070a49ec736a2fe6fe8246709fa53064c2790c11be02331f4
sha512: ff834f9d8d1f7883d1d177c8783d49cd95a4c1cf1748b7caf5953e61b54b57806258bca069e941e8049e007177128e1182f9c09b961da9cae3f79d095ece2cd8
ssdeep: 6144:CwhswltXfkoKSc9w5DWAoHXEb8iHpgFWCOymnGo06Ra5:vswltzn5DmEgIpgFWdNRa5
type: PE32 executable (GUI) Intel 80386, for MS Windows

Version Info:

0: [No Data]

UDS:Trojan-Ransom.Win32.Rack also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
DrWebTrojan.Encoder.761
CynetMalicious (score: 100)
CAT-QuickHealTrojan.Mauvaise.SL1
ALYacGen:Variant.Ransom.Crypt0L0cker.5
CylanceUnsafe
SangforTrojan.Win32.Save.a
CrowdStrikewin/malicious_confidence_80% (D)
Cybereasonmalicious.ba12fb
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Filecoder.TorrentLocker.A
APEXMalicious
AvastFileRepMalware
ClamAVWin.Ransomware.Crytp0l0cker-6333843-1
KasperskyUDS:Trojan-Ransom.Win32.Rack.gen
BitDefenderGen:Variant.Ransom.Crypt0L0cker.5
MicroWorld-eScanGen:Variant.Ransom.Crypt0L0cker.5
Ad-AwareGen:Variant.Ransom.Crypt0L0cker.5
SophosMal/Generic-S
BitDefenderThetaAI:Packer.B97D80411F
McAfee-GW-EditionBehavesLike.Win32.Generic.dc
FireEyeGeneric.mg.f881a28ba12fb9c1
EmsisoftGen:Variant.Ransom.Crypt0L0cker.5 (B)
SentinelOneStatic AI – Malicious PE
AviraADWARE/MultiPlug.Gen4
Antiy-AVLTrojan/Generic.ASMalwS.1B32BF1
MicrosoftRansom:Win32/Teerac.I
ArcabitTrojan.Ransom.Crypt0L0cker.5
GDataGen:Variant.Ransom.Crypt0L0cker.5
AhnLab-V3Backdoor/Win32.Androm.R197441
Acronissuspicious
McAfeeGenericRXMX-XO!F881A28BA12F
MAXmalware (ai score=80)
VBA32BScope.TrojanRansom.Ranscrape
MalwarebytesMalware.AI.73287329
RisingTrojan.Generic@ML.99 (RDML:KoYX5RkJpFmODIcgIgsYlA)
IkarusTrojan-Ransom.Torrentlocker
MaxSecureTrojan.Malware.300983.susgen
FortinetW32/TorrentLocker.C!tr
AVGFileRepMalware
Qihoo-360HEUR/QVM10.1.C8A0.Malware.Gen

How to remove UDS:Trojan-Ransom.Win32.Rack?

UDS:Trojan-Ransom.Win32.Rack removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment