Evil: A poor man’s ransomware in JavaScript
ID: b7464a6b-f794-54e0-82e3-1b699ed6cbc1
STIX ID: report--b7464a6b-f794-54e0-82e3-1b699ed6cbc1
Feed Name: CERT Polska
This report analyzes the "Evil" ransomware discovered in January 2017: the malware is implemented in JavaScript, uses an external AESCrypt binary to perform strong encryption (files renamed with the .file0locked extension), obtains encryption keys from a remote server via an X-Token header (preventing local key recovery), removes executables from TEMP and startup locations to hinder analysis/recovery, and displays a ransom note directing victims to contact a provided email; a sample hash and other IOCs are included.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
