Check out our video library AppCheck defending against newest ransomware, automatic recovery and real-time backup.

HelloXD Ransomware (.hello)

  • Distribution Method : Unknown
  • MD5 : a034f79273e3f61d34eeadf38f12dee2
  • Major Detection Name : Trojan.HelloXD.A (BitDefender), Win64.Trojan-Ransom.HelloXD.A (GData)
  • Encrypted File Pattern : .hello
  • Payment Instruction File : Hello.txt
  • Major Characteristics :
     - Offline Encryption
     - Disable and Blocks Task Manager (TaskMgr.exe)
     - Block processes execution (dbsnmp.exe, isqlplussvc.exe, oracle.exe, ProcessHacker.exe, procexp64.exe, Wireshark.exe etc.)
     - Stop multi services (AcrSch2Svc, BackupExecJobEngine, ccSetMgr, DefWatch, RTVscan, VeeamDeploymentService etc.)
     - Disable system restore (vssadmin.exe delete shadows /all /quiet)