notes/Help Restore.hta
Location: EveryFolder
GlobeImposter is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on December 1, 2016, this ransomware has been actively targeting systems worldwide. Security researchers also track this malware under the aliases: Fake Globe, GlobeImposter NextGen, FakeGlobeImposter, GlobeImposterImitator.
GlobeImposter updates file modification timestamps after encryption.
GlobeImposter modifies encrypted files using specific patterns to mark them as encrypted:
After encrypting files, GlobeImposter displays ransom notes demanding payment for file recovery:
notes/Help Restore.hta
Location: EveryFolder
notes/recover files.hta
Location: EveryFolder
notes/read_it.txt
Location: EveryFolder
notes/read-me.txt
Location: EveryFolder
notes/how_to_back_files.html
Location: EveryFolder
notes/RECOVERY_DARKBIT.txt
Location: EveryFolder
notes/Read___ME.html
Location: EveryFolder
notes/free_files!.html
Location: EveryFolder
notes/RECOVER-FILES.html
Location: EveryFolder
notes/MESSAGE.html
Location: EveryFolder
notes/#HOW_DECRYPT_FILES#.html
Location: EveryFolder
notes/$DECRYPT_YOUR_FILES$.html
Location: EveryFolder
notes/!back_files!.html
Location: EveryFolder
notes/here_your_files!.html
Location: EveryFolder
notes/Read_Me.html
Location: EveryFolder
notes/!your_files!.html
Location: EveryFolder
notes/YOU_FILES_HERE.txt
Location: EveryFolder
notes/!SOS!.html
Location: EveryFolder
notes/READ_IT.html
Location: EveryFolder
notes/HELP.hta
Location: Roaming
notes/instructions.html
Location: EveryFolder
notes/READ_ME.txt
Location: EveryFolder
notes/READ__ME.html
Location: EveryFolder
notes/Read_ME.html
Location: EveryFolder
notes/HOW_TO_BACK_FILES.txt
Location: EveryFolder
notes/support.html
Location: EveryFolder
notes/Restore-My-Files.txt
Location: EveryFolder
notes/HOW_RECOVER.html
Location: EveryFolder
notes/!INSTRUCTI0NS!.TXT
Location: EveryFolder
notes/how_to_open_files.html
Location: EveryFolder
notes/help you.txt
Location: EveryFolder
notes/Decryption INFO.html
Location: EveryFolder
notes/!!!HOW_TO_BACK_FILES!!!.html
Location: EveryFolder
The following executable files are associated with GlobeImposter ransomware:
Decryption tools may be available for GlobeImposter. Review the resources below:
This GlobeImposter ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery, helping organizations defend against and recover from ransomware attacks like GlobeImposter.
The Hunt Engine uses Deep File Inspection to identify GlobeImposter across live data, replicated data, and backups. If this family is in your environment, Elastio finds it before encryption completes. Run a hunt against your recovery points to confirm.