• Cyber Security
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware File Recovery
    • Ransomware Types
  • Ransomware Services
    • Ransomware Removal
    • Ransomware File Recovery
  • News
  • Tutorials
  • Ransomware TV

Maria Ransomware

November 22, 2018Simeon Georgiev

Maria Ransomware is yet another name in the increasingly growing list of ransomware. The ransomware was first sighted around the first week of November 2018. Some security analysts believe that it could be related to BlackHeart Ransomware, due to some similarities between both ransomware. Maria is designed to ensure that all Windows host (Windows XP, 7, 8, 10, Vista, Server) are compromised instantly after coming into contact with it.

To break stealthily into systems, Maria takes advantage of a multitude of infection strategies to hack computers. Its primary distribution strategy is the use of spam email campaigns where malicious files and hyperlinks are added in the emails. Since these file attachments contain macros, a fundamental understanding about their operation and disability is crucial.

When Maria enters the PCs of its victims; it begins by executing different operations. To lock user files, a combination of AES (Advanced Encryption Standard) and RSA is utilized. Data like corporate documents, sensitive photos, database files, presentations, and other critical pieces of information are made inaccessible due to encryption. Each of these files has an extension with the name of “.mariabc” which is appended at their end. When the encryption process culminates, it generates a window called “email protected” which is effectively the ransom note.

Similar to other conventional ransomware, Maria also asks for a ransom in exchange for a ransomware removal solution. This ransom is demanded via a pop-up window. The window says that Maria acknowledges the hack and provides an email address for communication. Communication can also be initiated on Telegram via @MAF420. The typical ransom amount is $50 which has to be paid in the form of Bitcoin. This transaction requires sending BTC on the cybercriminals wallet address. The perpetrators also warn their victims against using any ransomware removal solution or contacting authorities and cybersecurity firms for assistance.

Simeon Georgiev
https://www.linkedin.com/in/simeon--georgiev/
I am a Cyber Security Enthusiast from Bulgaria. I like to write about malware and ransomware and global cyber attacks. You can reach me on Twitter @sgeorgiev1995 or Email: [email protected]
Previous post Sicck Ransomware Next post CuteRansom Ransomware

Related Articles

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

January 27, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Ransomware: 4 Types of the Latest Trend in Cybercrimes

February 1, 2018Simeon Georgiev
Ransomware: 4 Types of the Latest Trend in Cybercrimes

NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

February 1, 2018Simeon Georgiev
NonPetya Ransomware Caused Millions of Dollars Worth of Damage to Maersk

Latest on Ransomware TV

https://vimeo.com/399908876?loop=0

Recent Posts

  • How to protect your organization against ransomware reinfections
  • AuKill Helps Ransomware Operators Disable EDR and Security Tools
  • AI-ransomware is a real threat, just not a realistic one yet
  • Rorschach is the new speed king in the ransomware space
  • The Role of Supply Chain Breaches in Ransomware Attacks

Stay Protected

Subscribe to our mailing list to get the latest cyber security and ransomware removal articles!

Thank you for subscribing.

Something went wrong.

Navigation

  • Cyber Security
    • Ransomware File Recovery
    • Ransomware Prevention
    • Ransomware Removal
    • Ransomware Types
  • News
  • Tutorials

Ransomware Attacks (Last 6M)

0

Connect & Protect

Facebook
Google+
LinkedIn
YouTube
Vimeo

More

  • BECOME A CONTRIBUTOR

MonsterCloud Reviews

© 2020 MonsterCloud.com. All Rights Reserved.