logo

PSCrypt ransomware: back in business

ID: e5ef4be2-57a3-5110-8f71-91ebf60e7938

STIX ID: report--e5ef4be2-57a3-5110-8f71-91ebf60e7938

Feed Name: Blaze's Security Blog

Threat Score
70/100

Date Published: 2018-05-07

Date Updated: 2026-04-19

Author: Bart

...
...

This report analyzes a new iteration of PSCrypt ransomware (derived from GlobeImposter) spread via phishing against Ukrainian users, detailing its encryption behavior (excluding specific folders, encrypting nearly all file types, clearing VSS and Event Logs), ransom notes (Ukrainian and English) demanding $150 in Bitcoin to wallet 1EoWxYTt7xCskTxjm47E2XNxgkZv1anDP9, attacker contact emails, and the .docs extension used on encrypted files; it notes no payments have been observed to the listed wallet.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.