Threat Database Ransomware Gandcrab.ABO Ransomware

Gandcrab.ABO Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 13,252
Threat Level: 100 % (High)
Infected Computers: 14
First Seen: May 4, 2023
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Gandcrab.ABO Ransomware on your system indicates a serious security threat that requires immediate attention. Ransomware is a type of malware designed to encrypt and hold your files for ransom, causing significant disruption to your work and personal life. Understanding the nature of this threat and taking prompt action is crucial to minimizing its impact and preventing future occurrences.

What Is Gandcrab.ABO Ransomware?

Ransomware, like Gandcrab.ABO Ransomware, is a malicious software that uses encryption to deny access to a victim's files. It is typically spread through phishing emails, exploited vulnerabilities in software, or infected software downloads. Once inside a system, it begins to encrypt files, making them inaccessible to the user. The attackers then demand a ransom in exchange for the decryption key, claiming it will restore access to the encrypted files.

How Gandcrab.ABO Ransomware Operates

Gandcrab.ABO Ransomware operates by infiltrating a system, often through user interaction or exploitation of system vulnerabilities. Upon successful infiltration, it starts scanning the system for files to encrypt. The encryption process uses complex algorithms, making it difficult for users to access their files without the decryption key. The malware then displays a ransom note, providing instructions on how to pay the ransom and supposedly recover the encrypted files. It's worth noting that paying the ransom does not guarantee file recovery and only incentivizes further malicious activity.

Symptoms of Infection

Symptoms of a Gandcrab.ABO Ransomware infection can include the inability to access files, files having unusual extensions appended to their names, and the presence of a ransom note or demand for payment. Systems may also exhibit slower performance due to the resource-intensive nature of the encryption process. Recognizing these symptoms early can help in taking swift action to mitigate the damage.

How to Remove Gandcrab.ABO Ransomware

  1. Boot your computer in Safe Mode with Networking to prevent the malware from loading and to allow for internet access. This will make it easier to download and install removal tools.
  2. Download and install a reputable anti-malware tool, such as SpyHunter, designed to detect and remove ransomware. Perform a full scan of your system to identify and remove all traces of the malware.
  3. Uninstall any suspicious programs that may have been installed without your knowledge. These could be Trojans or other malware that assisted in the ransomware's installation.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings. This can help remove any malicious extensions or settings that the malware may have altered.
  5. Reboot your computer and perform another full scan with your anti-malware tool to ensure that all malware has been removed. This step is crucial in verifying the system's cleanliness and readiness for use.

Conclusion

The removal of Gandcrab.ABO Ransomware requires careful and immediate action to prevent further damage. By understanding how ransomware operates and following the steps outlined for removal, you can restore your system's security and protect your files from future threats. It's also essential to adopt preventive measures, such as regular backups, keeping software up-to-date, and being cautious with emails and downloads, to safeguard against ransomware infections. Remember, prevention and swift action are key in the fight against malware and ransomware threats.

Analysis Report

General information

Family Name: Gandcrab.ABO Ransomware
Signature status: No Signature

Known Samples

MD5: 36eb003c38cf7e1b1306553e66cf6106
SHA1: cd4bce5c277781af918dd28e5ddf019faff3a37e
SHA256: 0B64DE4CEA7FBFED007C80862E6FF51494861E81D1A30374ED65B3A8D1751B6E
File Size: 84.99 KB, 84992 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • No Version Info
  • ntdll
  • x86

Block Information

Total Blocks: 212
Potentially Malicious Blocks: 193
Whitelisted Blocks: 19
Unknown Blocks: 0

Visual Map

0 0 0 0 0 x x x x x x x x x x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 x x 0 1 0 0 0 0 x x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • GandCrab.ABW
  • Gandcrab.ABO

Files Modified

File Attributes
c:\windows\syswow64\eajqiinp.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\eajqiinp.exe Generic Write,Read Attributes
c:\windows\syswow64\lficlpen.dll Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32:: C:\WINDOWS\SysWow64\Lficlpen.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79eca078-17ff-726b-e811-213280e5c831}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79ECA078-17FF-726B-E811-213280E5C831} RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 �m �v����(�1�1HO@V�A��H[u_�zb"hk�ql(�{b��P�������������m�����$�8წ���&M�=�SB1_T�Vw��R���%�������AE��D��&��$���L RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Eajqiinp.exe

Trending

Most Viewed

Loading...