Lilith Ransomware (.lilith)
#1
Lilith Ransomware (.lilith) (2025. 01. 04. 660)
 
AppCheck Anti-Ransomware : Lilith Ransomware (.lilith) Block Video

Distribution Method : Unknown
 
MD5 : b7a182db3ba75e737f75bda1bc76331a
 
Major Detection Name : Ransomware/Win.LILITHCRYPT.C5205307 (AhnLab V3), Trojan.Ransom.Lilith.B (BitDefender)
 
Encrypted File Pattern : .lilith
 
Payment Instruction File : Restore_Your_Files.txt
 
Major Characteristics :
 
  • Offline Encryption
  • Recovery Partition (M:\) + EFI System Partition (N:\) drives are activate.
  • Block processes execution (agntsvc.exe, dbsnmp.exe, ocssd.exe, oracle.exe, sql.exe, synctime.exe etc.)



More Info HERE

Content lifted from CheckMAL site with permission
[-] The following 1 user says Thank You to jasonX for this post:
  • harlan4096
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
That weird CAPTCHA could be a malware t...
I hate captchas. One...akiratoriyama — 08:01
Audacity 3.0.5
Audacity 3.7.3 ...Kool — 15:17
That weird CAPTCHA could be a malware tr...
Follow the 'I'm no...harlan4096 — 12:26
RogueKiller 16.1.1
V16.1.1 03/11/2025...harlan4096 — 12:21
Hasleo Backup Suite 5.2
Hasleo Backup Suit...harlan4096 — 12:20

[-]
Birthdays
Today's Birthdays
avatar (50)tersfargum
avatar (49)alfreExept
Upcoming Birthdays
avatar (43)gapedDow
avatar (37)snorydar
avatar (42)Hectorvot
avatar (50)knowhanPluts
avatar (38)Williamengiz
avatar (45)qaqapeti
avatar (43)battsourIonix
avatar (42)CedricSek
avatar (38)chasRex
avatar (32)uteluxix
avatar (46)piafcflene
avatar (38)Matthewkah
avatar (37)Charlesfibre
avatar (37)francisnj3
avatar (42)artmaGoork

[-]
Online Staff
There are no staff members currently online.

>