Threat Database Trojans Trojan.Ransomlock.AE


By GoldSparrow in Trojans

Threat Scorecard

Threat Level: 90 % (High)
Infected Computers: 8
First Seen: May 10, 2013
Last Seen: February 1, 2022
OS(es) Affected: Windows

Trojan.Ransomlock.AE is a Trojan that blocks the desktop of the affected computer and does not allow the victim to use the PC. Trojan.Ransomlock.AE covers a screen of an infected computer with a full-screen image/alert and asks the attacked computer user to pay a supposed fine to restore access to the PC. Trojan.Ransomlock.AE may be distributed through a website, which contains an exploit kit. Once run, Trojan.Ransomlock.AE may create the malevolent file. Trojan.Ransomlock.AE may create the registry entry so that it can run automatically every time you start Windows. Trojan.Ransomlock.AE may also make other modifications to the Windows Registry. Trojan.Ransomlock.AE then gathers system information from the corrupted PC, which incorporates operating system version and user ID. Trojan.Ransomlock.AE then uploads the information to one of the command-and-control (C&C) servers.

File System Details

Trojan.Ransomlock.AE may create the following file(s):
# File Name Detections
1. %CurrentFolder%\[THREAT FILE NAME]

Registry Details

Trojan.Ransomlock.AE may create the following registry entry or registry entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Winlogon\"Userinit" = "%Windir%\userinit.exe,%SystemDrive%\[BINARY CONTENT]"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"Sysyem Cleaner" = "%CurrentFolder%\[THREAT FILE NAME]"


Most Viewed
