Threat Database Ransomware Gandcrab.BNB Ransomware

Gandcrab.BNB Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 13,347
Threat Level: 100 % (High)
Infected Computers: 16
First Seen: November 16, 2023
Last Seen: July 14, 2026
OS(es) Affected: Windows

The detection of Gandcrab.BNB Ransomware on your system indicates a serious security threat that requires immediate attention. Ransomware is a type of malware designed to encrypt and hold your files for ransom, causing disruption to your work and potentially leading to significant data loss. Understanding the nature of this threat and taking appropriate steps to remove it is crucial to restoring the security and integrity of your system.

What Is Gandcrab.BNB Ransomware?

Gandcrab.BNB Ransomware, as indicated by its name, falls under the category of ransomware threats. Ransomware typically operates by encrypting files on the infected system and then demanding a ransom in exchange for the decryption key. The ".BNB" suffix may indicate a specific variant or version, but without more detailed information, it's essential to focus on the general characteristics of ransomware and the steps needed to mitigate its effects.

How Gandcrab.BNB Ransomware Operates

Ransomware like Gandcrab.BNB Ransomware usually gains access to a system through various means, such as phishing emails, exploited vulnerabilities in software, or infected software downloads. Once inside, it begins to scan the system for files to encrypt, using encryption algorithms that make the files inaccessible to the user. The malware then displays a ransom note, demanding payment in cryptocurrency for the decryption key. It's worth noting that paying the ransom does not guarantee that the decryption key will be provided or that it will work correctly.

Symptoms of Infection

Symptoms of a ransomware infection can include the inability to access files, files having strange extensions appended to their names, and the presence of a ransom note or demands for payment. In some cases, the malware may also attempt to spread to other systems on the network or may exhibit other malicious behaviors designed to extort money from the victim.

  • Files become inaccessible or are encrypted with a strange extension.
  • A ransom note appears on the screen, demanding payment for decryption.
  • System performance may degrade due to the malware's activity.
  • Unusual network activity may be observed as the malware communicates with its command and control servers.

How to Remove Gandcrab.BNB Ransomware

  1. Boot your system into Safe Mode with Networking to limit the malware's ability to interfere with the removal process.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter, to detect and remove the malware.
  3. Uninstall any suspicious programs that may have been installed without your knowledge, as these could be related to the malware.
  4. Reset your web browsers (Chrome, Firefox, Edge) to their default settings to remove any malicious extensions or settings changes made by the malware.
  5. Reboot your system and perform another full scan to ensure that all remnants of the malware have been removed.

Conclusion

Removing Gandcrab.BNB Ransomware requires careful and systematic steps to ensure that the malware is fully eradicated from the system. It's also crucial to take preventive measures to avoid future infections, including keeping software up to date, using strong antivirus software, avoiding suspicious downloads and emails, and regularly backing up important files. By understanding how ransomware operates and taking proactive steps to secure your system, you can significantly reduce the risk of falling victim to these types of threats.

Analysis Report

General information

Family Name: Gandcrab.BNB Ransomware
Signature status: No Signature

Known Samples

MD5: d27320d5be793e379aa2a86523f5567e
SHA1: 10fff2b0620af4271770aee3493d377cbbe1ce93
SHA256: 0FAC2B4AA57DAF94E1A8021C96ABD297EC6865D7C846555FA99CF3E7441E8F78
File Size: 65.54 KB, 65536 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • 2+ executable sections
  • No Version Info
  • ntdll
  • x86

Block Information

Total Blocks: 107
Potentially Malicious Blocks: 89
Whitelisted Blocks: 17
Unknown Blocks: 1

Visual Map

0 0 0 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x ? 0 x x 0 0 x x 0 1 0 0 0 0 x 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Gandcrab.BNB

Files Modified

File Attributes
c:\windows\syswow64\hapojdoc.dll Generic Write,Read Attributes
c:\windows\syswow64\hkimdp32.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\windows\syswow64\hkimdp32.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32:: C:\WINDOWS\SysWow64\Hapojdoc.dll RegNtPreCreateKey
HKLM\software\classes\wow6432node\clsid\{79feacff-ffce-815e-a900-316290b5b738}\inprocserver32::threadingmodel Apartment RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\shellserviceobjectdelayload::web event logger {79FEACFF-FFCE-815E-A900-316290B5B738} RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • WinExec

Shell Command Execution

C:\WINDOWS\system32\Hkimdp32.exe

Trending

Most Viewed

Loading...