- Home
- Detectable Ransomware
- MBRlock
Ransomware Research
MBRlock Ransomware
MBRlock is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on February 1, 2018, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: Hax, Haxlocker, Dexcrypt.
Quick Facts
- Ransomware Family
- MBRlock
- First Seen
- February 1, 2018
- Known Aliases
- HaxHaxlockerDexcrypt
How MBRlock Ransomware Works
Ransom Note and Payment Demands
After encrypting files, MBRlock displays ransom notes demanding payment for file recovery:
Ransom message:
notes/note.txt
Note locations:
Boot
Technical Indicators
Associated Executable Files
The following executable files are associated with MBRlock ransomware:
Free Minecraft 1.20.exe
Free Minecraft 1.20 - Copy (53).exe
System.dll
Trojan.Ransom.MBRLock.exe
Trojan.Ransom.MBRLock.3.exe
MBRLock.exe
275958-347c5f92-a215-4b36-94e5-27eca103fa72
799406-1d82617f-e1e8-4faf-ad6c-b33991211f85
425682-a4cafc74-22e4-4362-a11e-b74e36655f10
Ransomware MBRLock.bin
Ransomware MBRLock.exe
Hax.exe
dfc56a704b5e031f3b0d.exe
covid21.exe
[trojan]mbrlocker.exe
CyberPunk2077%20Crack%20Legit%20No%20Scam.exe
mbr lock.bin
Coolimag_gpj.bin
finalwords.exe
dttcodexgigas.6d07b9fc6d46e9109153383e5630cd8a078dd921
program.exe
executable.exe
1.exe
cmd
Cmd.Exe
CMD.exe
DiskKiller-Clean.exe
Elastio Can Help You
Don't let MBRlock ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This MBRlock ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like MBRlock.
Last updated: July 30, 2025