% Fake Ransomware Infection Under Widespread
ID: 53a7ceea-cf6c-5540-8ac3-2328c6aee8e1
STIX ID: report--53a7ceea-cf6c-5540-8ac3-2328c6aee8e1
Feed Name: Cyble Blog
Threat Score
This report details a fake ransomware campaign delivered from an adult/phishing site: the sample (SHA256 fbb21d55...) drops multiple EXE/VBS/BAT components that rename user files to unusable names, place ransom notes, persist via the Startup folder, attempt to delete system drives, and contact a remote URL; the analysis includes technical behavior, code snippets, MITRE ATT&CK mappings, and a comprehensive set of IOCs (file hashes and filenames).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
