A forum for reverse engineering, OS internals and malware analysis 

Forum for completed malware requests.
 #29676  by Prepare2GetRekt
 Fri Dec 02, 2016 10:19 am
Hello,

I'm currently looking for a Globe Ransomware sample.
There are many variants of this ransomware all using different extensions.
The one i'm looking for has the extention .zendrz and the contact email in the ransomware note is Gazerman@india.com
The virus file is most of the time named Trust.exe and it deletes itself after the encryption.
I want to have a sample of this ransomware so i can analyze it further.
I already have the decryptor which Gazerman@india.com sells for about 2BTC.

The attachment contains the Read_Me_Please.hta file which the virus drops in every folder where files are encrypted.
Attachments
(1.46 KiB) Downloaded 44 times
 #29677  by Antelox
 Fri Dec 02, 2016 11:47 am
The most recent ones which I have found.

BR,

Antelox