Ransom_FAKEGLOBE.WIL
Windows
Threat Type: Ransomware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Ransomware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It is capable of encrypting files in the affected system.
TECHNICAL DETAILS
56,832 bytes
EXE
28 Mar 2018
Arrival Details
This Ransomware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Ransomware drops the following files:
- {encrypted folder}\how_to_back_files.html
- %System Root%\Users\Public\6C3A9BD68ECF74E53B20D067A4CACB896A9CCA3A61FB993B0EC5FC23F4C1C0BB
(Note: %System Root% is the Windows root folder, where it usually is C:\ on all Windows operating system versions.)
It drops the following copies of itself into the affected system:
- %AppDataLocal%\{Default File Name}.exe
(Note: %AppDataLocal% is the Application Data folder found in Local Settings, where it is usually C:\Documents and Settings\{user name}\Local Settings\Application Data on Windows 2000, Windows Server 2003, and Windows XP (32- and 64-bit); C:\Users\{user name}\AppData\Local on Windows Vista (32- and 64-bit), Windows 7 (32- and 64-bit), Windows 8 (32- and 64-bit), Windows 8.1 (32- and 64-bit), Windows Server 2008, and Windows Server 2012.)
Autostart Technique
This Ransomware modifies the following registry entry(ies) to enable its automatic execution at every system startup:
HKCU\Software\Microsoft\
Windows\CurrentVersion\RunOnce
BrowserUpdateCheck = %AppDataLocal%\{Default File Name}.exe
Other Details
This Ransomware is capable of encrypting files in the affected system.
Ransomware Routine
This Ransomware appends the following extension to the file name of the encrypted files:
- TRUE