Ransom.Linux.BLACKMATTER.RTS
Linux/BlackMatter.C!tr.ransom (FORTINET)
Linux

Threat Type: Ransomware
Destructiveness: No
Encrypted: Yes
In the wild: Yes
OVERVIEW
This Ransomware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It executes then deletes itself afterward.
It encrypts files with specific file extensions. It drops files as ransom note.
TECHNICAL DETAILS
Arrival Details
This Ransomware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Installation
This Ransomware drops the following files:
- tmp\main.log
It adds the following processes:
- esxcli network firewall set --enabled false -> Disables firewall
- esxcli vm process kill --type=force --world-id {ID} -> Terminates virtual machines
It executes then deletes itself afterward.
Process Termination
This Ransomware terminates the following processes if found running in the affected system's memory:
- vmsyslogd
Stolen Information
This Ransomware sends the gathered information via HTTP POST to the following URL:
- http://{BLOCKED}hacks.com/?{encrypted gathered information}
- http://{BLOCKED}den.com/?{encrypted gathered information}
Other Details
This Ransomware does the following:
- It does not terminate virtual machine processes with the following strings in its filepath:
- VMWare vCenter
- VMWare-VirtualSAN-Witness
Ransomware Routine
This Ransomware encrypts files with the following extensions:
- vmdk
- vmem
- vswp
- log
It appends the following extension to the file name of the encrypted files:
- {string generated from Machine GUID}
It drops the following file(s) as ransom note:
- {Encrypted Directory}\ReadMe.txt
SOLUTION
Scan your computer with your Trend Micro product to delete files detected as Ransom.Linux.BLACKMATTER.RTS. If the detected files have already been cleaned, deleted, or quarantined by your Trend Micro product, no further step is required. You may opt to simply delete the quarantined files. Please check the following Trend Micro Support pages for more information:
Did this description help? Tell us how we did.