Bv: Mykings-S [Trj]

What is BV:Mykings-S [Trj] infection?

In this short article you will certainly find about the interpretation of BV:Mykings-S [Trj] and its negative impact on your computer system. Such ransomware are a kind of malware that is specified by on-line frauds to require paying the ransom by a sufferer.

In the majority of the cases, BV:Mykings-S [Trj] virus will instruct its targets to initiate funds move for the purpose of reducing the effects of the amendments that the Trojan infection has presented to the sufferer’s device.

BV:Mykings-S [Trj] Summary

These adjustments can be as adheres to:

  • SetUnhandledExceptionFilter detected (possible anti-debug);
  • Yara rule detections observed from a process memory dump/dropped files/CAPE;
  • Dynamic (imported) function loading detected;
  • The binary likely contains encrypted or compressed data.;
  • Authenticode signature is invalid;
  • Network activity detected but not expressed in API logs;
  • Ciphering the papers located on the victim’s hard disk — so the target can no more use the information;
  • Preventing regular access to the victim’s workstation;

BV:Mykings-S [Trj]

The most normal networks whereby BV:Mykings-S [Trj] Ransomware Trojans are infused are:

  • By methods of phishing e-mails;
  • As an effect of individual winding up on a resource that holds a destructive software;

As soon as the Trojan is effectively injected, it will certainly either cipher the data on the target’s PC or protect against the device from working in a correct manner – while likewise putting a ransom note that states the demand for the sufferers to effect the settlement for the purpose of decrypting the papers or recovering the file system back to the first condition. In the majority of circumstances, the ransom money note will turn up when the client restarts the PC after the system has already been harmed.

BV:Mykings-S [Trj] circulation channels.

In numerous edges of the world, BV:Mykings-S [Trj] grows by jumps as well as bounds. Nonetheless, the ransom notes and methods of obtaining the ransom quantity may vary depending on particular local (local) setups. The ransom money notes and techniques of obtaining the ransom quantity may differ depending on specific neighborhood (regional) setups.

For instance:

    Faulty notifies about unlicensed software program.

    In specific areas, the Trojans usually wrongfully report having spotted some unlicensed applications made it possible for on the victim’s tool. The sharp after that requires the user to pay the ransom.

    Faulty declarations concerning unlawful web content.

    In nations where software application piracy is less preferred, this method is not as effective for the cyber scams. Alternatively, the BV:Mykings-S [Trj] popup alert may falsely declare to be originating from a law enforcement establishment and will report having situated kid porn or various other prohibited data on the device.

    BV:Mykings-S [Trj] popup alert may wrongly claim to be obtaining from a legislation enforcement institution and also will certainly report having situated kid pornography or other illegal data on the gadget. The alert will likewise contain a need for the user to pay the ransom.

Technical details

File Info:

name: 78BA929A83D1CE80EA14.mlwpath: /opt/CAPEv2/storage/binaries/886034370cc7ae22935ee8a92547614ac8d8e525b088cc5d1fe38101f79b5e28crc32: 9D4D53F4md5: 78ba929a83d1ce80ea149e46290f8405sha1: 5b3c74044638e64b7c30570a744e3f73c23fa1casha256: 886034370cc7ae22935ee8a92547614ac8d8e525b088cc5d1fe38101f79b5e28sha512: 104c382e2e6b507d22114df279769a16b3d84a4a9e77c6a09a4d7eb14fa1e13e1e1d94e86acf2f9f0e5abffcd6e96027e9b2a30e8919843134189dff5a3ff919ssdeep: 196608:gCKy3w7PbENm3rZpF00nUsxS/DsxDF0A4hbxU53FPRXvlCY:j3sztnFLHA83NRXvlCYtype: PE32 executable (GUI) Intel 80386, for MS Windowstlsh: T14D76230263E69035FFABA2339B5AB20657BD7D244533C52F43982DB9B8701B1267D723sha3_384: c885a89678ca58935fc05696c1fb58e95b93f25e9fde7b7df279503fd312fc40b4796c0542e2570aba0cdd754fe92c3eep_bytes: e8c8d00000e97ffeffffcccccccccccctimestamp: 2021-11-21 07:37:00

Version Info:

Translation: 0x0809 0x04b0

BV:Mykings-S [Trj] also known as:

GridinSoftTrojan.Ransom.Gen
BkavW32.AIDetect.malware2
LionicHacktool.Win32.Gamehack.3!e
Elasticmalicious (high confidence)
MicroWorld-eScanAIT.Heur.Miner.6.97C80424.Gen
FireEyeGeneric.mg.78ba929a83d1ce80
ALYacAIT.Heur.Miner.6.97C80424.Gen
K7AntiVirusTrojan ( 005797341 )
AlibabaTrojan:Win32/Miner.a070e310
K7GWTrojan ( 005797341 )
Cybereasonmalicious.a83d1c
CyrenW32/AutoIt.UN.gen!Eldorado
SymantecTrojan.Gen.MBT
ESET-NOD32a variant of Win32/Packed.AutoIt.UX
TrendMicro-HouseCallTROJ_GEN.R002C0PKN21
KasperskyTrojan.Win32.Miner.bdq
BitDefenderAIT.Heur.Miner.6.97C80424.Gen
AvastBV:Mykings-S [Trj]
Ad-AwareAIT.Heur.Miner.6.97C80424.Gen
SophosMal/Generic-S
TrendMicroTROJ_GEN.R002C0PKN21
McAfee-GW-EditionBehavesLike.Win32.Generic.wc
AviraHEUR/AGEN.1100152
MAXmalware (ai score=89)
GridinsoftRansom.Win32.Gen.sa
MicrosoftTrojan:Win32/Sabsik.FL.B!ml
GDataAIT.Heur.Miner.6.97C80424.Gen (2x)
CynetMalicious ()
McAfeeArtemis!78BA929A83D1
MalwarebytesTrojan.BitCoinMiner
APEXMalicious
TencentWin32.Trojan.Miner.Ajvu
IkarusTrojan.Win64.Autoit
FortinetAutoIt/Miner.BDE!tr
AVGBV:Mykings-S [Trj]
Alexander Ross

Alexander Ross

Gaming, Esports & Interactive Media Writer

Alexander Ross has covered the video game industry for a decade, writing deep dives on game design, esports tournaments, VR developments, and gaming culture.

Share this article
Twitter Facebook Pinterest