Ransom.CryptXXX

description-logo Description

Malware

Symptoms

System Compromise: User files possibly encrypted and rendered unusable.

Analysis

This detection is related to some Ransomware that intends to encrypt user files, forcing victim host to pay for the decryption keys. The attacker usually spreads README.txt and/or README.html or something similar filenamed on the affected machine wherein it contains instructions for the ransom payment for the encyrpted files, usually the common mode of payment is bitcoin transfer.

recommended-action-logoInstructions

If required, the signature's action can be set to "Block". Use Anti-Virus software to scan and clean the system.

Telemetry logoTelemetry