Videos

Check out our video library AppCheck defending against newest ransomware, automatic recovery and real-time backup.

  • Distribution Method : Unknown
 
  • MD5 : 493edc98d300ffbfe3fb8d87e970f84f
 
  • Major Detection Name : Ransom.RobinHood (Malwarebytes), Ransom.HiddenTear!g1 (Norton)
 
  • Encrypted File Pattern : .Robinhood
 
  • Malicious File Creation Location :
     - C:\Users\%UserName%\AppData\Local\Temp\luncher.exe
     - C:\Users\%UserName%\AppData\Local\Temp\Microsoft.Win32.TaskScheduler.dll
     - C:\Users\%UserName%\AppData\Local\Temp\updater.exe
     - C:\Users\%UserName%\Desktop\ROBINHOOD-TIMER.exe
     - C:\Windows\System32\Tasks\MicrosoftServices
 
  • Payment Instruction File : READ_IT.txt
 
  • Major Characteristics :
     - Deletes encrypted files after 72 hours expires
     - Changes desktop background (C:\Users\%UserName%\AppData\Local\Temp\wallpaper1.bmp)

List

위로