Ransomware Research
Ishtar Ransomware
Ishtar is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on October 1, 2016, this ransomware has been actively targeting systems worldwide.
Quick Facts
- Ransomware Family
- Ishtar
- First Seen
- October 1, 2016
How Ishtar Ransomware Works
Targeted Files
http://www.bleepingcomputer.com/forums/t/633083/ishtar-ransomware-help-and-support-topic/
File Encryption Patterns
Ishtar modifies encrypted files using specific patterns to mark them as encrypted:
Prefixes added to encrypted files:
ISHTAR-
Ransom Note and Payment Demands
After encrypting files, Ishtar displays ransom notes demanding payment for file recovery:
README-ISHTAR.txt
Ransom message:
notes/README-ISHTAR.txt
Note locations:
Desktop
Roaming
Technical Indicators
Associated Executable Files
The following executable files are associated with Ishtar ransomware:
tju4viswirt.exe
Ishtar Ransomware.exe
Ishtar ransomware
Счет_отправлено_контрагенту_22_11.exe
ajd1bxIVnP3.exe
wK85Z70Bh15.exe
Ishtar Ransomware...exe
ransomware (7).exe
sn521.exe
O9aQLgI.exe
GU4kZ1T1.exe
AFLg36GT3.exe
4q9H71Rr.exe
n141p5WjWP.exe
NuuDyf17T.exe
Anketa sotrudnikov pretend na povushenie.exe
troj.exe.ee
2016_37.doc.exe
2016_37.doc.exe
4J0p7nrtE.exe
Elastio Can Help You
Don't let Ishtar ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This Ishtar ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Ishtar.
Last updated: July 30, 2025