MALWARE-OTHER --
MALWARE-OTHER Win.Ransomware.MegaLocker ransom note transfer over SMB
This event is generated when the text "All of your files were protected by a strong encryption with AES cbc-128 using MegaLocker Virus." is found in SMB v2 packet. It's an indicator of the MegaLocker ransomware which remotely encrypts files in a compromised SAMBA server. Impact: Details: "All of your files were protected by a strong encryption with AES cbc-128 using MegaLocker Virus." is part of the text of the ransom note dropped by the MegaLocker ransomware. Ease of Attack:
No information provided
No public information
No known false positives
Cisco Talos Intelligence Group
No rule groups
None
No information provided
None