- Distribution Method : Mail attachment (.doc)
- MD5 : 24fe30bf331331e8a07f97b369b33906
- Major Detection Name : Trojan.Ransom.GlobeImposter (ALYac), Ransom_FAKEGLOBE.ASUUG (Trend Micro)
- Encrypted File Pattern : .911
- Malicious File Creation Location : C:\Users\Public\<Random>.exe
- Payment Instruction File : !SOS!.html
- Major Characteristics :
- Offline Encryption
- Fake Globe / PSCrypt Ransomware series
- Use a valid "Northcat Ltd" Digital Signatures
- Disable system restore (vssadmin.exe Delete Shadows /All /Quiet)
List