Ransomware (Suspicious)

This is a suspicious ransomware that manages to encrypt some files in the Download folder.

A similar sample is detected by Avast:
AnyRun analysis:

The sample was submitted to Avast more than once before.

The sample was submitted to Avast more than once before.
It was first uploaded to virustotal 2021-06-21

So i guess those that has not added signatur detection for it by now have a reason for not doing it

To protect against Muldrop BAT ransomware an important first line of precaution is not to open links from inside phishy looking mails.


I believe so too. But the confusing fact for me is that the only difference between the two samples I posted above is that one has this extra code at the start to elevate admin privilege.

@echo off
if _%1_==_payload_  goto :payload

    echo %~nx0: elevating self
    set vbs=%temp%\getadmin.vbs
    echo Set UAC = CreateObject^("Shell.Application"^)                >> "%vbs%"
    echo UAC.ShellExecute "%~s0", "payload %~sdp0 %*", "", "runas", 1 >> "%vbs%"
    del "%temp%\getadmin.vbs"
goto :eof


Everything else is the same. The sample doesn’t even require admin privilege and works fine without it. In fact, that’s how the original sample was, without the admin privilege code. The code was added by an amateur for testing purpose.
There must be a reason, I guess, for Avast and also Kaspersky not to add a signature but it’s still a bit confusing.

Good suggestion. I don’t do that. The sample was given to me by someone for testing.