- Distribution Method : Unknown
- MD5 : a92d50d33b423dbbfa53ecf59b237bbe
- Major Detection Name : a variant of Win32/Filecoder.FS (ESET), Ransom_PURGE.F117GB (Trend Micro)
- Encrypted File Pattern : <Random Filename>.[ost_inform@protonmail.com].scarab
- Malicious File Creation Location :
- C:\Users\%UserName%\AppData\Roaming\sevnz.exe
- C:\Users\%UserName%\IF YOU WANT TO GET ALL YOUR FILES BACK, PLEASE READ THIS.TXT
- Payment Instruction File : IF YOU WANT TO GET ALL YOUR FILES BACK, PLEASE READ THIS.TXT
- Major Characteristics :
- Offline Encryption
- Scarabey Ransomware series
- Disable system restore (wbadmin DELETE SYSTEMSTATEBACKUP -keepVersions:0, wmic SHADOWCOPY DELETE, vssadmin Delete Shadows /All /Quiet, bcdedit /set {default} recoveryenabled No, bcdedit /set {default} bootstatuspolicy ignoreallfailures)
List