Blog | G5 Cyber Security

Ransom32 look at the malicious package

Ransom32 is a new ransomware implemented in a very atypical style. It is delivered as an executable, that is in reality a autoextracting WinRAR archive. The heart of the ransomware is inside binary.bin a JavaScript compiled to a native code and loaded using function evalNWBin. After encrypting the files, the ransomagagag is displayed by the included. The client is operated via Tor client renamed to Ransom32 It uses a button Check a Check-Check payment in order to verify the payment has been received.”]

Source: https://blog.malwarebytes.com/threat-analysis/2016/01/ransom32-look-at-the-malicious-package/

Exit mobile version