Threat Database Ransomware GandCrab.ABN Ransomware

GandCrab.ABN Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 18,834
Threat Level: 100 % (High)
Infected Computers: 5
First Seen: March 31, 2023
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of GandCrab.ABN Ransomware on your system indicates a serious security threat that requires immediate attention. Ransomware is a type of malware that encrypts files on a victim's device and demands a ransom in exchange for the decryption key. In this case, the presence of GandCrab.ABN Ransomware suggests that your system has been compromised, and your files may be at risk of being encrypted and held for ransom.

What Is GandCrab.ABN Ransomware?

GandCrab.ABN Ransomware is a type of ransomware that uses encryption to lock files on a victim's device. The malware is designed to spread quickly and quietly, often through exploit kits, phishing emails, or infected software downloads. Once inside a system, GandCrab.ABN Ransomware begins to scan for files to encrypt, using advanced algorithms to lock down documents, images, videos, and other types of data. The malware then displays a ransom demand, typically in the form of a pop-up window or a text file, instructing the victim on how to pay the ransom and recover their encrypted files.

How GandCrab.ABN Ransomware Operates

GandCrab.ABN Ransomware operates by exploiting vulnerabilities in software and human behavior. The malware may use social engineering tactics, such as fake emails or infected attachments, to trick users into installing the malware on their devices. Once installed, the malware communicates with its command and control servers to receive instructions and transmit encrypted data. GandCrab.ABN Ransomware may also use evasion techniques, such as code obfuscation and anti-debugging methods, to avoid detection by security software.

Symptoms of Infection

Common symptoms of GandCrab.ABN Ransomware infection include slowed system performance, encrypted files with unusual extensions, and ransom demands displayed on the screen. You may also notice that your files are no longer accessible, or that you are unable to open certain programs or applications. In some cases, the malware may also cause system crashes, freezes, or other types of instability.

  • Encrypted files with unusual extensions
  • Ransom demands displayed on the screen
  • Slowed system performance
  • System crashes or freezes
  • Unusual network activity

How to Remove GandCrab.ABN Ransomware

  1. Boot your system in Safe Mode with Networking to prevent the malware from loading and to allow for easier removal.
  2. Use a reputable anti-malware tool, such as SpyHunter, to perform a full scan of your system and detect any malicious files or programs.
  3. Uninstall any suspicious programs or applications that may be related to the malware.
  4. Reset your web browsers, including Chrome, Firefox, and Edge, to their default settings to remove any malicious extensions or add-ons.
  5. Reboot your system and perform a follow-up scan to ensure that the malware has been completely removed.

Conclusion

Removing GandCrab.ABN Ransomware from your system requires careful attention to detail and a thorough understanding of the malware's behavior. By following the steps outlined above, you can help to ensure that your system is cleaned and your files are protected. However, prevention is always the best defense against ransomware and other types of malware. By keeping your software up to date, using strong antivirus protection, and avoiding suspicious emails and downloads, you can reduce the risk of infection and keep your system safe from harm.

Analysis Report

General information

Family Name: GandCrab.ABN Ransomware
Signature status: No Signature

Known Samples

MD5: fc6ec79ba80b6a3545ffa0a38813a0c6
SHA1: 182de9f622e119f26e01de0fc7e601a087da88f9
SHA256: 28B4B88D0983BF022491C4F32461372AE0932AF997FFA975EFF9EDA35F1B5DF0
File Size: 58.37 KB, 58368 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • No Version Info
  • ntdll
  • x86

Block Information

Total Blocks: 222
Potentially Malicious Blocks: 94
Whitelisted Blocks: 128
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 x x 0 1 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Files Modified

File Attributes
c:\windows\syswow64\eikkjg32.dll Generic Write,Read Attributes
c:\windows\syswow64\qmiqiadd.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\qmiqiadd.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Eikkjg32.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Qmiqiadd.exe

Trending

Most Viewed

Loading...