Threat Database Ransomware Teslacrypt.EC Ransomware

Teslacrypt.EC Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 16,257
Threat Level: 100 % (High)
Infected Computers: 322
First Seen: March 7, 2023
Last Seen: May 17, 2026
OS(es) Affected: Windows

The detection of Teslacrypt.EC Ransomware on your system indicates a serious security threat that requires immediate attention. Ransomware is a type of malware designed to encrypt and hold your files hostage, demanding payment in exchange for the decryption key. In this report, we will provide an overview of the Teslacrypt.EC Ransomware threat, its operating mechanisms, symptoms of infection, and most importantly, steps to remove it from your system.

What Is Teslacrypt.EC Ransomware?

Teslacrypt.EC Ransomware is identified as a ransomware threat, which implies its primary function is to encrypt files on the infected system and demand a ransom for their decryption. Ransomware like Teslacrypt.EC Ransomware can spread through various means, including phishing emails, infected software downloads, and vulnerabilities in operating systems and applications. Understanding the nature of this threat is crucial for taking appropriate measures to protect your data and system.

How Teslacrypt.EC Ransomware Operates

Ransomware typically operates by first gaining access to a system, often through user interaction such as opening a malicious email attachment or clicking on a link. Once inside, it scans the system for target files, which can include documents, images, videos, and other valuable data. These files are then encrypted using sophisticated algorithms, making them inaccessible to the user. The ransomware will display a ransom note, demanding payment, usually in cryptocurrency, in exchange for the decryption key. It's essential to note that paying the ransom does not guarantee the decryption of your files or that the attackers will not demand additional payments.

Symptoms of Infection

Symptoms of a Teslacrypt.EC Ransomware infection can include the inability to access your files, the presence of ransom notes or demands for payment on your desktop or in folders where your files were located, and significant slowdowns of your system as the malware encrypts your files. In some cases, you might notice unusual network activity or suspicious processes running in the background. Recognizing these symptoms early can help mitigate the damage by allowing for quicker action to isolate the threat and prevent further encryption of files.

How to Remove Teslacrypt.EC Ransomware

  1. Boot your system into Safe Mode with Networking. This will allow you to use the internet to download removal tools without the ransomware interfering.
  2. Download and run a full scan with a reputable anti-malware tool such as SpyHunter. Ensure the tool is updated to the latest version to increase the chances of detecting and removing the Teslacrypt.EC Ransomware.
  3. Uninstall any suspicious programs that you do not recognize or that were installed around the time of the infection. Be cautious and only remove programs you are sure are not necessary for your system's operation.
  4. Reset your web browsers (Chrome, Firefox, Edge, etc.) to their default settings. This can help remove any malicious extensions or settings that the ransomware might have altered.
  5. After completing the above steps, reboot your system and run another full scan with your anti-malware tool to ensure that the threat has been fully removed.

Conclusion

Dealing with a Teslacrypt.EC Ransomware infection requires careful and immediate action to prevent further damage. By understanding how ransomware operates and following the steps outlined for removal, you can take significant steps towards recovering your system and protecting your data. It's also crucial to implement preventive measures such as regular backups, avoiding suspicious downloads and emails, and keeping your system and software up to date to reduce the risk of future infections.

Analysis Report

General information

Family Name: Teslacrypt.EC Ransomware
Signature status: No Signature

Known Samples

MD5: 80a8c2be7c07cb1c74eab6a0166ba660
SHA1: 8d26f8f1f619de66de760e7c5a3cd90b07405f86
SHA256: 7C2286E5A810095FFA454CF5F93908382BECDE69BA6AFA559FF20566D2B5E29B
File Size: 127.58 KB, 127576 bytes
MD5: 6b225c37a44e91c171f601d1eb64d8b0
SHA1: d2d43b73d9f524589808148abff8673664726f58
SHA256: AF76E9BA8DF5A7BE628D3689890033EF8797DDCFFFBDB87AE25671469BA18A5B
File Size: 128.00 KB, 128000 bytes
MD5: bcc2c266aa16a71f31bca33010c85429
SHA1: 314127ff729a272fa4b77af82a2ad502bbf00f12
SHA256: CCCB01D6FF70151B0D85376F50A4CD06730F5197053AE637DC04AD842740980B
File Size: 128.00 KB, 128000 bytes
MD5: 5a772e8583f53d3e67d148b0c5cb49ae
SHA1: c86ce958313a3b3a4e4c851173387bda1e6836f8
SHA256: 058928CDA512B8A6758C395A2A0056DFC970786A970F80C4EDE5D280DA686C37
File Size: 62.40 KB, 62395 bytes
MD5: ccd55c7c2e6d132200aa4d3b20c9bfd6
SHA1: ba154297e914198c88bb2ab37b23487e1927f195
SHA256: A31E8CA3B37236D63FFDB700BB3DE512A2E03DD3716E32DDE1A16D97BF23910E
File Size: 126.49 KB, 126492 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has TLS information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
Show More
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Astersoft Sistemas Ltda
  • Code for Science & Society Inc.
  • Default organization
File Description
  • A Java project.
  • aster-cert-tool
  • openrefine
File Version
  • 3.9.3
  • 3.7.5
  • 1.0-SNAPSHOT
  • 1.0
Internal Name
  • Aster Cert Tool
  • clubeconstrudatasync
  • openrefine
Legal Copyright
  • Copyright (c) 2018 OpenRefine contributors, 2010 Google, Inc.
  • Copyright © 2020-2025 Default organization. All rights reserved.
  • Copyright © 2020-2026 Default organization. All rights reserved.
Legal Trademarks
  • Code for Science & Society Inc.
  • Default organization
Original Filename
  • aster-cert-tool.exe
  • construdatasync_console.exe
  • openrefine.exe
Product Name
  • Aster Cert Tool
  • clubeconstrudatasync
  • OpenRefine
Product Version
  • 3.9.3
  • 3.7.5
  • 1.0-SNAPSHOT
  • 1.0

File Traits

  • No Version Info
  • WinZip SFX
  • x86
  • ZIP (In Overlay)
  • ZIPinO

Block Information

Similar Families

  • ConvertAd.AR
  • Downloader.Agent.BTAI
  • Downloader.Agent.BTAL
  • Exploit.JD
  • Sofacy.B
Show More
  • Teslacrypt.EC

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\explorer::slowcontextmenuentries `$�!�:i��+00��� Gs]XM���"�2��FXD�':D��exA-��LG=�A��J� �C� RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\content::cacheprefix RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\cookies::cacheprefix Cookie: RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\internet settings\5.0\cache\history::cacheprefix Visited: RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 ,k8��8tX��B�8 �� �6 �v 5� �Z xy ����T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�0 RegNtPreCreateKey
HKLM\software\microsoft\windows nt\currentversion\notifications\data::418a073aa3bc1c75 -k8��8tX��B�8 �� �6 �v 5� �Z xy ����T�B�������������5����ee��Bx�< �!wz"Wc#�#��$kF$��%"�%:�%�&� &�x(�(X�)�`*J*9*�"*�^*�h+�[,��/9�/��0P%1`1�1HO1�D5�0 RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::failed_count RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::state  RegNtPreCreateKey
HKCU\software\microsoft\edge\thirdparty::statuscodes (NULL) RegNtPreCreateKey
HKCU\software\microsoft\edge\thirdparty::statuscodes  RegNtPreCreateKey
Show More
HKCU\software\microsoft\edge\elfbeacon::version 143.0.3650.80 RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::failed_count  RegNtPreCreateKey
HKCU\software\microsoft\edge\blbeacon::state  RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory
Process Shell Execute
  • CreateProcess
  • ShellExecute
Syscall Use
  • ntdll.dll!NtAccessCheck
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtAssociateWaitCompletionPacket
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDeleteValueKey
Show More
  • ntdll.dll!NtDuplicateToken
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenProcessTokenEx
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenThreadTokenEx
  • ntdll.dll!NtPowerInformation
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryLicenseValue
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityObject
  • ntdll.dll!NtQuerySystemInformation
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtReadRequestData
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtSetValueKey
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWriteFile
  • UNKNOWN

Shell Command Execution

open https://www.java.com/pt-BR/download/
"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --edge-skip-compat-layer-relaunch --single-argument https://www.java.com/pt-BR/download/

Trending

Most Viewed

Loading...