Check out our video library AppCheck defending against newest ransomware, automatic recovery and real-time backup.

Avaddon Ransomware (.<4~15-Digit Random Extension> / <1~5-Digit Random>_readme.html)

  • Distribution Method : Automatic infection using exploit by visiting website
  • MD5 : ae7db665e8c67f88a183a1079c086f29
  • Encrypted File Pattern : .<4~15-Digit Random Extension>
  • Malicious File Creation Location :
     - C:\Users\%UserName%\AppData\Local\Temp\<Random>.exe
     - C:\Users\%UserName%\AppData\Roaming\Microsoft\<Random>.exe
  • Payment Instruction File : <1~5-Digit Random>_readme.html
  • Major Characteristics :
     - Offline Encryption
     - Turns off User Access Control (UAC)
     - EFI System Partition (X:\) and Recovery Partition (Y:\) drives are activate.
     - Block processes execution (MsDtSrvr.exe, QBCFMonitorService.exe, sqlmangr.exe, tomcat6.exe, winword.exe, wxServerView.exe etc.)
     - Disable system restore (wmic.exe SHADOWCOPY /nointeractive, vssadmin.exe Delete Shadows /All /Quiet)
     - Adds update to scheduler to execute "%AppData%\Microsoft\<Random>.exe" every 10 minutes