Blog

GlobeImposter Ransomware

An analysis of GlobeImposter Ransomware by Quick Heal Security Labs

  • 35
    Shares
 August 11, 2017

Estimated reading time: 5 minutes

GlobeImposter Ransomware has been increasingly active and observed recently to be appending different suffixes to files it encrypt. A few patterns observed are using 3 random numbers such as “.492, .490, .725, .726, and .707”, random alphanumeric words such as “.p1crypt, .A1crypt, .BRT92, and .mtk118” and suffixes like “.OCEAN, .SEA,...