- Home
- Detectable Ransomware
- BigBobRoss
Ransomware Research
BigBobRoss Ransomware
BigBobRoss is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on January 1, 2019, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: Obfuscated, Cheetah.
Quick Facts
- Ransomware Family
- BigBobRoss
- First Seen
- January 1, 2019
- Known Aliases
- ObfuscatedCheetah
How BigBobRoss Ransomware Works
File Encryption Patterns
BigBobRoss modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..obfuscated
..encryptedALL
..djvu
..cheetah
..encrypted
Ransom Note and Payment Demands
After encrypting files, BigBobRoss displays ransom notes demanding payment for file recovery:
Read Me.txt
Ransom message:
notes/Read Me.txt
Note locations:
EveryFolder
How to recover your files.txt
Ransom message:
notes/How to recover your files.txt
Note locations:
EveryFolder
How to recover your files.url
Ransom message:
notes/How to recover your files.url
Note locations:
EveryFolder
Encrypt Message.txt
Ransom message:
notes/Encrypt Message.txt
Technical Indicators
Associated Executable Files
The following executable files are associated with BigBobRoss ransomware:
BigBobRoss.exe
test.exe
bedoneupx.exe
Obfuscated.exe
encrypterXD.exe
System.exe
windows64bit.exe
Recovery and Decryption Tools
Good news! Decryption tools are available for BigBobRoss ransomware:
0
1
Elastio Can Help You
Don't let BigBobRoss ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This BigBobRoss ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like BigBobRoss.
Last updated: September 30, 2025
Recent Ransomware
Explore other threats in our database