Jump to content

Recommended Posts

  • Administrators

This should be LockBit:
https://www.virustotal.com/gui/file/0e66029132a885143b87b1e49e32663a52737bbff4ab96186e9e5e829aa2915f/detection

57/63 detections a month ago, detected by ESET as a variant Of Win32/Filecoder.NXQ. Detected by ESET since Jan 21 (not taking into account possible proactive protection upon execution by Ransomware shield, AMS, etc.).

Link to post
Share on other sites
On 3/14/2020 at 9:12 PM, Mike Rodriques said:

ESET  doesn't seem to be detecting or blocking

What file extension did the ransomware append to files that were encrypted? Lockbit also known as ABCD ransomware appends .abcd to its encrypted files: https://id-ransomware.blogspot.com/2019/10/abcd-ransomware.html

-EDIT- Appears the latest versions append the .lockbit extension to encrypted files. Also the most recent version is using a validity signed file. 

Edited by itman
Link to post
Share on other sites
Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    No registered users viewing this page.

×
×
  • Create New...