- Home
Detectable Ransomware IEncrypt
Ransomware Research
IEncrypt Ransomware
IEncrypt is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on November 1, 2018, this ransomware has been actively targeting systems worldwide.
Quick Facts
- Ransomware Family
- IEncrypt
- First Seen
- November 1, 2018
How IEncrypt Ransomware Works
Targeted Files
https://app.any.run/tasks/4cca4af5-d93c-4ad2-8a6f-aaa22d9905d4/ https://app.any.run/tasks/a7187588-2462-4274-8b3e-33a0b794a7ad/ https://app.any.run/tasks/1ec8df83-9634-4856-96b4-b78955ba211b/ https://app.any.run/tasks/f803d450-766d-4c42-8e86-a58ba3719deb/
File Encryption Patterns
IEncrypt modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..kraussmfz
..cmsnwned
..ge0l0gic
..n3xtpharma
..3v3r1s
..0riz0n
..grupothermot3k
..parad1gm
..al1b1nal1
..un1que
..midwestsurinc
Ransom Note and Payment Demands
After encrypting files, IEncrypt displays ransom notes demanding payment for file recovery:
{origin_filename}.ge0l0gic_readme
Ransom message:
notes/DOC1.docx.ge0l0gic_readme
Note locations:
EveryFile
{origin_filename}.n3xtpharma_readme
Ransom message:
notes/ExcelMUI.msi.n3xtpharma_readme
Note locations:
EveryFile
{origin_filename}.3v3r1s_readme.txt
Note locations:
EveryFile
{origin_filename}.0riz0n_readme.txt
Ransom message:
notes/Autoruns.zip.0riz0n_readme
Note locations:
EveryFile
{origin_filename}.grupothermot3k_readme
Note locations:
EveryFile
{origin_filename}.parad1gm_readme
Note locations:
EveryFile
{origin_filename}.al1b1nal1_readme
Ransom message:
notes/AccessMUI.msi.al1b1nal1_readme
Note locations:
EveryFile
{origin_filename}.un1que_readme.txt
Ransom message:
notes/AccessMUI.msi.un1que_readme
Note locations:
EveryFile
{origin_filename}.midwestsurinc_readme
Ransom message:
notes/autoexec.bat.midwestsurinc_readme
Note locations:
EveryFile
Technical Indicators
Associated Executable Files
The following executable files are associated with IEncrypt ransomware:
IEncrypt
IEncrypt.dll
ntav2.exe
cms.bin
IEncrypt.exe
googleupdate.exe
o2flash.exe
locator.exe
snmptrap.exe
elevation_service.exe
FreeAudioConverter.exe
Ge0l0Gic.exe
DiagnosticsHub.StandardCollector.Service.exe
EABV73~1.EXE
fd0y2k~1:bin
perfhost.exe
tcpsvcs.exe
sppsvc.exe
xbgmsvc.exe
policyhost.exe
adentsmwservice.exe
windows
genericwcfexternalservice.exe
healthservice.exe
smsvchost.exe
armsvc.exe
wmiapsrv.exe
sqlagent.exe
svchost
3307.exe
KRZZGG~1:bin
ADOER15
msader15.dll
WmiApSrv.exe
wlooiz~1:bin
FNRDOL~1:BIN
qtatdd~1:bin
ehrecvr.exe
obxfnp~1:bin
LL.bin.exe
mpxil5~1:bin
uni.exe
wmvenc
wmvencod.dl
sqlbrowser.exe
Elastio Can Help You
Don't let IEncrypt ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This IEncrypt ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like IEncrypt.
Last updated: July 30, 2025