Joke.MSIL.FakeRansom.AB
December 22, 2020
ALIASES:
Joke/FakeFilecoder.ouvlf (ANTIVIR); HEUR:Hoax.MSIL.FakeRansom.gen (KASPERSKY)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:


Threat Type: Joke Program
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Joke Program arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
TECHNICAL DETAILS
File Size: 123,904 bytes
File Type: EXE
Initial Samples Received Date: 10 Dec 2020
Arrival Details
This Joke Program arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
This Joke Program does the following:
- Once executed, a GUI will be displayed indicating that the files in the machine are being encrypted and a decryptor tool will be provided once the ransom has been paid.
- Once the "Pay Now" button is clicked, a window will pop out indicating that this is just a demo file, not an actual malware.
