Threat Database Trojans Trojan.Ransomcrypt.E

Trojan.Ransomcrypt.E

By Domesticus in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 8
First Seen: August 29, 2013
Last Seen: April 6, 2022
OS(es) Affected: Windows

Trojan.Ransomcrypt.E is a Trojan that encrypts particular documents on the compromised PC and blocks the desktop. Trojan.Ransomcrypt.E connects to the particular domains. Trojan.Ransomcrypt.E installs a self generated certificate and installs it as a ROOT CA and Trusted Publisher. Trojan.Ransomcrypt.E modifies boot configuration settings using BCDEDIT to load the unsigned driver: bcdedit.exe /set testsigning on. Trojan.Ransomcrypt.E connects to one of the particular web addresses to download the lock screen. Trojan.Ransomcrypt.E drops files from the specific web addresses. Trojan.Ransomcrypt.E only encrypts files on fixed drives. Trojan.Ransomcrypt.E blocks the screen and shows the bogus image/warning message. Trojan.Ransomcrypt.E asks the attacked computer user to pay a fine to restore access to the PC.

URLs

Trojan.Ransomcrypt.E may call the following URLs:

[http://]107.6.112.86/08da3196-0115-49e3[REMOVED]
[http://]107.6.112.86/a614ef1c-a9c8-48ad[REMOVED]
[http://]107.6.112.86/b273e158-8982-47e3[REMOVED]
[http://]107.6.112.86/b7cc7b7b-7502-4eec[REMOVED]
[http://]107.6.112.86/de/1024x76[REMOVED]
[http://]107.6.112.86/de/1152x86[REMOVED]
[http://]107.6.112.86/de/1280x102[REMOVED]
[http://]107.6.112.86/de/1280x80[REMOVED]
[http://]107.6.112.86/de/1366x76[REMOVED]
[http://]107.6.112.86/de/1440x90[REMOVED]
[http://]107.6.112.86/de/1600x90[REMOVED]
[http://]107.6.112.86/de/1680x105[REMOVED]
[http://]107.6.112.86/de/1920x108[REMOVED]
[http://]107.6.112.86/de/768x102[REMOVED]
[http://]107.6.112.86/de/default[REMOVED]
[http://]107.6.112.86/en/1024x76[REMOVED]
[http://]107.6.112.86/en/1152x86[REMOVED]
[http://]107.6.112.86/en/1280x102[REMOVED]
[http://]107.6.112.86/en/1280x80[REMOVED]
[http://]107.6.112.86/en/1366x76[REMOVED]
[http://]107.6.112.86/en/1440x90[REMOVED]
[http://]107.6.112.86/en/1600x90[REMOVED]
[http://]107.6.112.86/en/1680x105[REMOVED]
[http://]107.6.112.86/en/1920x108[REMOVED]
[http://]107.6.112.86/en/768x102[REMOVED]
[http://]107.6.112.86/en/default[REMOVED]
[http://]107.6.112.86/es/1024x76[REMOVED]
[http://]107.6.112.86/es/1152x86[REMOVED]
[http://]107.6.112.86/es/1280x102[REMOVED]
[http://]107.6.112.86/es/1280x80[REMOVED]
[http://]107.6.112.86/es/1366x76[REMOVED]
[http://]107.6.112.86/es/1440x90[REMOVED]
[http://]107.6.112.86/es/1600x90[REMOVED]
[http://]107.6.112.86/es/1680x105[REMOVED]
[http://]107.6.112.86/es/1920x108[REMOVED]
[http://]107.6.112.86/es/768x102[REMOVED]
[http://]107.6.112.86/es/default[REMOVED]
[http://]107.6.112.86/fr/1024x76[REMOVED]
[http://]107.6.112.86/fr/1152x86[REMOVED]
[http://]107.6.112.86/fr/1280x102[REMOVED]
[http://]107.6.112.86/fr/1280x80[REMOVED]
[http://]107.6.112.86/fr/1366x76[REMOVED]
[http://]107.6.112.86/fr/1440x90[REMOVED]
[http://]107.6.112.86/fr/1600x90[REMOVED]
[http://]107.6.112.86/fr/1680x105[REMOVED]
[http://]107.6.112.86/fr/1920x108[REMOVED]
[http://]107.6.112.86/fr/768x102[REMOVED]
[http://]107.6.112.86/fr/default[REMOVED]
[http://]107.6.112.86/it/1024x76[REMOVED]
[http://]107.6.112.86/it/1152x86[REMOVED]
[http://]107.6.112.86/it/1280x102[REMOVED]
[http://]107.6.112.86/it/1280x80[REMOVED]
[http://]107.6.112.86/it/1366x76[REMOVED]
[http://]107.6.112.86/it/1440x90[REMOVED]
[http://]107.6.112.86/it/1600x90[REMOVED]
[http://]107.6.112.86/it/1680x105[REMOVED]
[http://]107.6.112.86/it/1920x108[REMOVED]
[http://]107.6.112.86/it/768x102[REMOVED]
[http://]107.6.112.86/it/default[REMOVED]
[http://]107.6.112.86/pl/1024x76[REMOVED]
[http://]107.6.112.86/pl/1152x86[REMOVED]
[http://]107.6.112.86/pl/1280x102[REMOVED]
[http://]107.6.112.86/pl/1280x80[REMOVED]
[http://]107.6.112.86/pl/1366x76[REMOVED]
[http://]107.6.112.86/pl/1440x90[REMOVED]
[http://]107.6.112.86/pl/1600x90[REMOVED]
[http://]107.6.112.86/pl/1680x105[REMOVED]
[http://]107.6.112.86/pl/1920x108[REMOVED]
[http://]107.6.112.86/pl/768x102[REMOVED]
[http://]107.6.112.86/pl/default[REMOVED]
[http://]107.6.112.86/pt/1024x76[REMOVED]
[http://]107.6.112.86/pt/1152x86[REMOVED]
[http://]107.6.112.86/pt/1280x102[REMOVED]
[http://]107.6.112.86/pt/1280x80[REMOVED]
[http://]107.6.112.86/pt/1366x76[REMOVED]
[http://]107.6.112.86/pt/1440x90[REMOVED]
[http://]107.6.112.86/pt/1600x90[REMOVED]
[http://]107.6.112.86/pt/1680x105[REMOVED]
[http://]107.6.112.86/pt/1920x108[REMOVED]
[http://]107.6.112.86/pt/768x102[REMOVED]
[http://]107.6.112.86/pt/default[REMOVED]
[http://]93.115.93.16:9007/a[REMOVED]
[http://]93.115.93.16:9007/f[REMOVED]
[http://]93.115.93.16:9007/g[REMOVED]

Trending

Most Viewed

Loading...