Threat Database Ransomware Thanos.A Ransomware

Thanos.A Ransomware

By CagedTech in Ransomware

Threat Scorecard

Threat Level: 100 % (High)
Infected Computers: 2
First Seen: March 2, 2022
Last Seen: February 19, 2026
OS(es) Affected: Windows

The detection of Thanos.A Ransomware on your system indicates a serious security threat that requires immediate attention. Ransomware is a type of malware designed to encrypt and hold your files for ransom, making it a significant concern for individuals and organizations alike. In this report, we will provide an overview of Thanos.A Ransomware, its mode of operation, symptoms of infection, and steps to remove it from your system.

What Is Thanos.A Ransomware?

Thanos.A Ransomware is a type of malware that belongs to the broader category of ransomware threats. Ransomware is designed to encrypt files on a victim's computer and demand a ransom in exchange for the decryption key. The primary goal of Thanos.A Ransomware is to extort money from its victims by restricting access to their files and threatening to delete them unless the ransom is paid.

How Thanos.A Ransomware Operates

Ransomware like Thanos.A Ransomware typically operates by exploiting vulnerabilities in software or using social engineering tactics to gain access to a victim's computer. Once inside, it scans the system for files to encrypt, using algorithms that make it difficult for users to access their data without the decryption key. The malware then displays a ransom note, demanding payment in cryptocurrency in exchange for the key. It's crucial to understand that paying the ransom does not guarantee that the decryption key will be provided or that the files will be restored.

Symptoms of Infection

Symptoms of a Thanos.A Ransomware infection can include the inability to access files, files being renamed with unusual extensions, and the presence of a ransom note or demand for payment. The system may also exhibit slower performance, and there might be signs of unauthorized access or changes to system settings. It's essential to act quickly upon noticing these symptoms to minimize damage.

How to Remove Thanos.A Ransomware

  1. Enter Safe Mode with Networking to prevent the malware from spreading or interfering with the removal process. This mode allows you to use the internet to download necessary tools while limiting the malware's ability to run.
  2. Perform a full scan of your system using a reputable anti-malware tool, such as SpyHunter. This step is crucial for identifying and removing all components of the malware.
  3. Uninstall suspicious programs that may be related to the Thanos.A Ransomware. Be cautious and only remove programs that you are certain are malicious or unnecessary.
  4. Reset your browsers, including Chrome, Firefox, and Edge, to their default settings. This can help remove any malicious extensions or settings changes made by the malware.
  5. Reboot your system and perform another scan to ensure that all malware components have been removed. This step is essential for verifying that the system is clean and secure.

Conclusion

The detection and removal of Thanos.A Ransomware require a thorough and careful approach to ensure that all components of the malware are eliminated and that your system is restored to a secure state. It's also important to take preventive measures, such as regularly backing up your data, keeping your software up to date, and being cautious with emails and downloads, to minimize the risk of future infections. By understanding how Thanos.A Ransomware operates and taking the necessary steps to remove it, you can protect your files and maintain the security and integrity of your computer system.

Analysis Report

General information

Family Name: Thanos.A Ransomware
Signature status: No Signature

Known Samples

MD5: dde53e9a922b2df284a2a98214febffd
SHA1: d93d4a90cc9d13dd53a1e91bf3886fb0d6af2896
SHA256: A5926B96975769653ECE840FB13216E250FC8A0D9A1BCE0D952E9D9DA94FF389
File Size: 146.94 KB, 146944 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have security information
  • File is .NET application
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Assembly Version 4.5.0.0
Company Name kZ2TLru7E NHR7ECwri
File Description Mozilla Firefox
File Version 4.5.0.0
Internal Name SMocd00tI
Legal Copyright Copyright 2019 62eqN3AjO
Legal Trademarks gYeRbQOXL bPN2N7MnV
Original Filename j4L9TldNi
Product Name KsfPiZpBD
Product Version 4.5.0.0

File Traits

  • .NET
  • ntdll
  • RijndaelManaged
  • SmartAssembly
  • x86

Block Information

Total Blocks: 234
Potentially Malicious Blocks: 143
Whitelisted Blocks: 91
Unknown Blocks: 0

Visual Map

x x x x x x x 0 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 x 0 0 x 0 x x 0 x x x x x x x x x x x 0 0 x x x x x x x x x x x x x 0 x x 0 0 x x x x x x x x x x x x x x x x x x 0 0 0 x x 0 x x 0 x 0 x 0 0 x x 0 0 0 0 0 x x x 0 0 0 x 0 0 0 x x x x x x x x x x x x x x x x 0 0 x 0 0 0 x x 0 0 0 0 0 x x x x x x x x x 0 x x x x 0 0 0 0 x x x 0 x x x x x x x x x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • MSIL.Agent.VM
  • SABS.A
  • Thanos.A

Files Modified

File Attributes
\device\namedpipe Generic Read,Write Attributes
\device\namedpipe Generic Write,Read Attributes
desktop-dlos3m3*\mailslot\net\netlogon Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 䋶厃ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 쇨呥ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 餄咜ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ⃘哤ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 컉哴ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 鑿哹ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ⺡唵ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 桛問ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 叱啛ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe ᤠ啠ꉩǜ RegNtPreCreateKey
Show More
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 喖ꉩǜ RegNtPreCreateKey
HKLM\system\controlset001\services\bam\state\usersettings\s-1-5-21-3119368278-1123331430-659265220-1001::\device\harddiskvolume2\windows\system32\conhost.exe 俵喸ꉩǜ RegNtPreCreateKey

Windows API Usage

Category API
User Data Access
  • GetComputerName
  • GetUserDefaultLocaleName
  • GetUserName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
  • CryptAcquireContext
Anti Debug
  • IsDebuggerPresent
  • NtQuerySystemInformation
Other Suspicious
  • AdjustTokenPrivileges
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
  • WriteConsole
Syscall Use
  • ntdll.dll!NtAlertThreadByThreadId
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtApphelpCacheControl
  • ntdll.dll!NtClearEvent
  • ntdll.dll!NtClose
  • ntdll.dll!NtConnectPort
  • ntdll.dll!NtCreateEvent
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateMutant
  • ntdll.dll!NtCreateSection
Show More
  • ntdll.dll!NtCreateSemaphore
  • ntdll.dll!NtDuplicateObject
  • ntdll.dll!NtEnumerateValueKey
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenKeyEx
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtOpenSection
  • ntdll.dll!NtOpenSemaphore
  • ntdll.dll!NtProtectVirtualMemory
  • ntdll.dll!NtQueryAttributesFile
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationThread
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQueryKey
  • ntdll.dll!NtQueryPerformanceCounter
  • ntdll.dll!NtQuerySecurityAttributesToken
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReleaseMutant
  • ntdll.dll!NtReleaseWorkerFactoryWorker
  • ntdll.dll!NtRequestWaitReplyPort
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForAlertByThreadId
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWaitForWorkViaWorkerFactory
  • ntdll.dll!NtWaitLowEventPair
  • ntdll.dll!NtWorkerFactoryWorkerReady
  • ntdll.dll!NtWriteFile
  • UNKNOWN
Process Terminate
  • TerminateProcess
Network Winsock2
  • WSAStartup

Shell Command Execution

"taskkill" /F /IM RaccineSettings.exe
WriteConsole: ERROR: The proce
"reg" delete "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /V "Raccine Tray" /F
WriteConsole: ERROR:
WriteConsole: The system was u
Show More
"reg" delete HKCU\Software\Raccine /F
WriteConsole: ERROR:
WriteConsole: The system was u
"schtasks" /DELETE /TN "Raccine Rules Updater" /F
"sc.exe" config Dnscache start= auto
"sc.exe" config SQLTELEMETRY start= disabled
"sc.exe" config FDResPub start= auto
"sc.exe" config SSDPSRV start= auto
"netsh" advfirewall firewall set rule group=\"Network Discovery\" new enable=Yes
"sc.exe" config SQLTELEMETRY$ECWDB2 start= disabled
"sc.exe" config SstpSvc start= disabled
"sc.exe" config upnphost start= auto
"sc.exe" config SQLWriter start= disabled

Related Posts

Trending

Most Viewed

Loading...