logo

% Fake Ransomware Infection Under Widespread

ID: 53a7ceea-cf6c-5540-8ac3-2328c6aee8e1

STIX ID: report--53a7ceea-cf6c-5540-8ac3-2328c6aee8e1

Feed Name: Cyble Blog

Threat Score
70/100

Date Published: 2022-10-10

Date Updated: 2026-07-20

...
...

This report details a fake ransomware campaign delivered from an adult/phishing site: the sample (SHA256 fbb21d55...) drops multiple EXE/VBS/BAT components that rename user files to unusable names, place ransom notes, persist via the Startup folder, attempt to delete system drives, and contact a remote URL; the analysis includes technical behavior, code snippets, MITRE ATT&CK mappings, and a comprehensive set of IOCs (file hashes and filenames).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.