Ransomware Research
Globe Ransomware
Globe is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on October 1, 2016, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: Purge.
Quick Facts
- Ransomware Family
- Globe
- First Seen
- October 1, 2016
- Known Aliases
- Purge
How Globe Ransomware Works
Targeted Files
https://www.hybrid-analysis.com/sample/72ae2f706c7ad38e424549b45c1aee147e49d10248cbba8993e622097aa4c345?environmentId=100 Encrypts filenames -> bhX3kpOXbVSsxHMPbA0QSM.1
File Encryption Patterns
Globe modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..RSA2048
..purge
..globe
..xitreu@india.com
..GSupport2
..siri-down@india.com
..zendrz
..GSupport3
..grapn206@india.com
..UCRYPT
..decryptallfiles@india.com
..nazarbayev
..gangbang
..hnumkhotep@india.com.hnumkhotep
..decrypr_helper@india.com
..badadmin@india.com
..[data97@india.com].aa
..locked
..1
Ransom Note and Payment Demands
After encrypting files, Globe displays ransom notes demanding payment for file recovery:
How to restore files.hta
Ransom message:
notes/How to restore files.hta
Note locations:
EveryFolder
Read Me Please.hta
Ransom message:
notes/Read Me Please.hta
Note locations:
EveryFolder
How To Recover Encrypted Files.hta
Ransom message:
notes/How To Recover Encrypted Files.hta
Note locations:
EveryFolder
how_to_restore_files.html
Ransom message:
notes/how_to_restore_files.html
Note locations:
Desktop
Technical Indicators
Associated Executable Files
The following executable files are associated with Globe ransomware:
Helper.exe
lolka.exe1
uexplorer.exe
dump.exe
nazerke.exe
101.exe
name
aa
WcxQmph5Aq.docx
svchost.exe
fast.exe
Elastio Can Help You
Don't let Globe ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This Globe ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Globe.
Last updated: July 30, 2025