logo

Evil: A poor man’s ransomware in JavaScript

ID: b7464a6b-f794-54e0-82e3-1b699ed6cbc1

STIX ID: report--b7464a6b-f794-54e0-82e3-1b699ed6cbc1

Feed Name: CERT Polska

Threat Score
70/100

Date Published: 2017-01-18

Date Updated: 2026-04-19

Author: Jarosław Jedynak

...
...

This report analyzes the "Evil" ransomware discovered in January 2017: the malware is implemented in JavaScript, uses an external AESCrypt binary to perform strong encryption (files renamed with the .file0locked extension), obtains encryption keys from a remote server via an X-Token header (preventing local key recovery), removes executables from TEMP and startup locations to hinder analysis/recovery, and displays a ransom note directing victims to contact a provided email; a sample hash and other IOCs are included.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.