You can check the latest ransomware information.
[ Cs137 Ransomware ]
[Virus/malicious code activity report: Cs137 ransomware]
A security breach suspected to be in the form of Cs137 ransomware has occurred.
We would like to provide the following information and warning regarding the situation.
Cs137 ransomware
The ransomware in question is called Cs137, and although the filename and extension are the same, it appears to be encrypting all targets.
How it works
File version
[Figure 1 Ransomware executable file compiler information]
[Figure 2 File information in Windows properties]
Ransomware behavior characteristics
CS137 is a ransomware developed in C++, and based on the analysis results so far, it is classified as a threat with atypical characteristics that does not involve actual ransom demands. Its main purpose appears to be testing or delivering warning messages to security research institutes and sandbox analysis environments, rather than data encryption.
[Figure 3 Global mutex static code to prevent duplicate execution]
Infection results
After encryption is complete, a guide file is created in each folder with the name .README.txt with a random 6-digit number. Each encrypted file is encrypted without changing its name.
[Figure 4 Infection results]
White Defender Response
It also supports real-time automatic restoration of files that are encrypted before the malicious actions and blocking of WhiteDefender ransomware.
[Figure 5 Blocking Message]
Go watch the Cs137 blocking video