notes/ReadME-M@r1a.txt
Location: RootDiscs, Desktop
M@r1a is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on October 1, 2018, this ransomware has been actively targeting systems worldwide.
M@r1a updates file modification timestamps after encryption.
M@r1a modifies encrypted files using specific patterns to mark them as encrypted:
After encrypting files, M@r1a displays ransom notes demanding payment for file recovery:
notes/ReadME-M@r1a.txt
Location: RootDiscs, Desktop
notes/ReadME-Encryptor.txt
Location: RootDiscs, Desktop
The following executable files are associated with M@r1a ransomware:
This M@r1a ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery, helping organizations defend against and recover from ransomware attacks like M@r1a.
The Hunt Engine uses Deep File Inspection to identify M@r1a across live data, replicated data, and backups. If this family is in your environment, Elastio finds it before encryption completes. Run a hunt against your recovery points to confirm.