Ransom_LOCKYENC.DLDVGB

 Analysis by: Cris Nowell Pantanilla

 PLATFORM:

Windows

 OVERALL RISK RATING:
 REPORTED INFECTION:

  • Threat Type: Trojan

  • Destructiveness: No

  • Encrypted: Yes

  • In the wild: Yes

  OVERVIEW

Infection Channel:

Downloaded from the Internet


This is the Trend Micro detection for encrypted malicious ransomware that are downloaded and executed by other malware. Once this malware is decrypted by its component file, it will be executed. As a result, the behavior of the malware is exhibited on the affected machine.

This Trojan may be downloaded by other malware/grayware/spyware from remote sites.

It requires its main component to successfully perform its intended routine. This is the Trend Micro detection for files that exhibit certain behaviors.

  TECHNICAL DETAILS

File Size:

237,568 bytes

Memory Resident:

No

Initial Samples Received Date:

31 Oct 2016

Arrival Details

This Trojan may be downloaded by other malware/grayware/spyware from remote sites.

Other Details

This Trojan requires its main component to successfully perform its intended routine.

This is the Trend Micro detection for:

  • An encrypted Ransom_LOCKY downloaded by other malware.
  • Requires to be decrypted by its main component in order to perform its malicious backdoor routines.
  • Functions as Ransom_LOCKY after it is decrypted and loaded by its main loader.

  SOLUTION

Minimum Scan Engine:

9.800

FIRST VSAPI PATTERN FILE:

12.870.07

FIRST VSAPI PATTERN DATE:

31 Oct 2016

VSAPI OPR PATTERN File:

12.871.00

VSAPI OPR PATTERN Date:

01 Nov 2016

Step 1

Before doing any scans, Windows XP, Windows Vista, and Windows 7 users must disable System Restore to allow full scanning of their computers.

Step 2

Scan your computer with your Trend Micro product to delete files detected as Ransom_LOCKYENC.DLDVGB. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check this Knowledge Base page for more information.


Did this description help? Tell us how we did.