Redeemer Ransomware (.redeem)
#1
Redeemer Ransomware (.redeem) (2025. 01. 17. 456)
 
AppCheck Anti-Ransomware : Redeemer Ransomware (.redeem) Block Video


Distribution Method : Unknown
 
MD5 : e37a0ece30267233f1dddf3c2300393f
 
Major Detection Name : Ransom:Win32/Redeemer.MK!MTB (Microsoft), Ransom.Win32.REDEEM.YXBLV (Trend Micro)
 
Encrypted File Pattern : .redeem
 
Malicious File Creation Location :
 
  • C:\Windows\ProgramData
  • C:\Windows\ProgramData\calc.exe
  • C:\Windows\SQL
  • C:\Windows\SQL\taskhost.exe
  • C:\Windows\SQL\rem.bat
  • C:\Windows\svchost
  • C:\Windows\svchost\conhost.exe


Payment Instruction File : Read Me.TXT
 
Major Characteristics :
 
  • Offline Encryption
  • Disable system restore (vssadmin delete shadows /All /Quiet)
  • Deletes event log (wevtutil clear-log Application, wevtutil clear-log Security, wevtutil clear-log Setup, wevtutil clear-log System)


More Info HERE

Content lifted from CheckMAL site with permission
[-] The following 1 user says Thank You to jasonX for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
Kaspersky\VPN\KSOS 21.26 (MR26) & KES 1...
harlan4096 — 07:05
Audacity 3.7.8
Audacity 3.7.8 ...harlan4096 — 07:02
Google Chrome 149.0.7827.114/.115
Google Chrome 149....harlan4096 — 07:00
Microsoft Windows 11 Low Latency Profile...
Windows 11 June up...harlan4096 — 06:52
Microsoft: Windows 11 KB5094126, KB50939...
Windows June 2026 ...harlan4096 — 06:29

[-]
Birthdays
Today's Birthdays
avatar (40)Julioagopy
avatar (50)aolaupitt2558
Upcoming Birthdays
avatar (39)Tedscolo
avatar (46)brakasig
avatar (45)JamesReshy
avatar (47)Francisemefe
avatar (40)leoniDup
avatar (39)Patrizaancem
avatar (39)biobdam
avatar (40)storoBox
avatar (48)kinotHeemn
avatar (39)Ceballos1976
avatar (40)efynu
avatar (32)horancos

[-]
Online Staff
There are no staff members currently online.

>