CatB Ransomware

General News

Summary

The malware consists of two files: version.dll, which is packed with UPX and is responsible for conducting the anti-VM checks, and oci.dll, the ransomware payload, which gets executed after being dropped. The threat will perform a Processor core check, verify the systems total available memory, and consider the size of the connected Hard Drive. The CatB Ransomware takes advantage of the GlobalMemoryStatusEx API function to retrieve the necessary information and will close itself if the returned results show less than 2GB of physical memory. The encryption of the victims data begins the moment that the CatB Ransomware payload file oci.dll is loaded as part of the msdtc.exe process. First, it will enumerate the existing discs and drives and only encrypt those that are part of its hardcoded list - Disks D:\, E:\, F:\, G:\, H:\, I:\, and all the files contained in C:\Users and its sub-folders.

Classifications

industries
Entertainment
applications
Customer Service & Support

AskAI Classifications

Labels
Cybersecurity Software Anti-Malware Software SaaS Security

Linked Companies

EnigmaSoft
$1M to $5M