- Distribution Method : Unknown
- MD5 : f18b892c15af71b3cfd2b33dae1016ba
- Major Detection Name : Trojan/Win32.Gandcrab.R236694 (AhnLab V3), NSIS.Trojan-Ransom.GandCrab.M (GData)
- Encrypted File Pattern : .KRAB
- Malicious File Creation Location : C:\Users\%UserName%\AppData\Roaming\calumny.exe
- Message File : KRAB-DECRYPT.txt
- Major Characteristics :
- Offline Encryption
- Sodinokibi Ransomware series
- File encryption using "C:\Windows\System32\msiexec.exe + C:\Windows\SysWOW64\msiexec.exe"
- Disables the AhnLab V3 antivirus program.
- Block processes execution (agntsvc.exe, isqlplussvc.exe, dbsnmp.exe, msftesql.exe, oracle.exe, sqlagent.exe etc.)
- Disable system restore (wmic.exe shadowcopy delete)
List