Home Malware Programs Ransomware BadRabbit Ransomware

BadRabbit Ransomware

Posted: October 25, 2017

Threat Metric

Threat Level: 10/10
Infected PCs: 166
First Seen: October 25, 2017
Last Seen: November 29, 2023
OS(es) Affected: Windows


The BadRabbit Ransomware is a family of file-locking Trojans that can damage media by encrypting it, collect passwords to gain improved access to vulnerable systems, and display screen-locking ransom notes. Threat actors are installing the BadRabbit Ransomware with fake Flash updates that they may circulate on corrupted websites or through other means, such as spam e-mails. Users should protect their files by having anti-malware products capable of deleting the BadRabbit Ransomware on sight and maintaining adequate backup safeguards.

Trojan Bunnies Hopping Borders

The age of threat actors avoiding attacking Russian targets has long since passed, and the newfound vulnerability of the nation is, perhaps, best showcased with the BadRabbit Ransomware campaign. This series of attacks is similar to those of the '.wcry File Extension' Ransomware family structurally, although the BadRabbit Ransomware isn't a direct relative. Attacks that malware experts can confirm are for more than just Russian entities, but also Ukrainian subway systems, South Korea, Europe, and the United States.

The group of threat actors organizing the BadRabbit Ransomware's campaign distribute their threat as a fake patch for the Adobe's Flash, which is most likely installing through website exploit kits or e-mail-based vulnerabilities. The BadRabbit Ransomware uses a secure encoding method leveraging a combination of the AES and RSA ciphers to block the infected system's media, which includes documents, pictures, spreadsheets and archives. The enciphering routine also adds an extra, internal 'encrypted' marker to each file, in addition to the traditional practice of appending a new extension ('.encrypted').

When it completes its file-locking routine, the BadRabbit Ransomware restarts the computer and forces it to load a screen-locking startup screen that bypasses Windows. This screen gives the user a link to the threat actor's TOR website, for paying a ransom to purchase the BadRabbit Ransomware's decryption code. Although malware experts are noting that the BadRabbit Ransomware's initial ransom fee is unusually cheap at 0.05 Bitcoins, the website does include a time limit before raising it.

Snaring a Pest before It Snatches Your Files

With less than three hundred dollars required for paying, victims are likely to be tempted into submitting to the BadRabbit Ransomware's ransoming demands. However, the Trojan's insistence on Bitcoins always leaves open the chance that threat actors will accept their money without giving any decryption assistance back to the user. Another security risk malware experts point out as significant is the BadRabbit Ransomware's modular use of the Mimikatz app, which could help the crooks to collect login combinations and passwords to compromise new targets, especially locally networked ones.

The BadRabbit Ransomware's threat actors are highly active in distributing their threat to different targets, including Russian news agencies and other, for-profit business sectors. Besides the standard precautions, such as backing up your media, recommended defenses against the BadRabbit Ransomware include disabling the Windows WMI service temporarily if it's practical. With the decryption of any files that this threat locks being unlikely, all users should emphasize security practices that help them block and remove the BadRabbit Ransomware with anti-malware programs before its attack routine finishes.

The BadRabbit Ransomware campaign is relatively sophisticated and makes practical use of default Windows features for installing itself and conducting attacks afterward. With so many companies around the world already harmed by its activities, all PC workers with Internet access should be on guard for exploits that could let this Trojan hop into their networks.

Use SpyHunter to Detect and Remove PC Threats

If you are concerned that malware or PC threats similar to BadRabbit Ransomware may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.

* See Free Trial offer below. EULA and Privacy/Cookie Policy.

Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SYSTEMDRIVE%\Users\<username>\Downloads\Nueva carpeta\MalwareDatabase-master\ransomwares\Endermanch@BadRabbit.exe File name: Endermanch@BadRabbit.exe
Size: 441.89 KB (441899 bytes)
MD5: fbbdc39af1139aebba4da004475e8839
Detection count: 77
File type: Executable File
Mime Type: unknown/exe
Path: %SYSTEMDRIVE%\Users\<username>\Downloads\Nueva carpeta\MalwareDatabase-master\ransomwares\Endermanch@BadRabbit.exe
Group: Malware file
Last Updated: January 27, 2025
file.exe File name: file.exe
Size: 142.85 KB (142855 bytes)
MD5: 7b5b089320d83de636b9befa84c47c3e
Detection count: 65
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: October 29, 2017
C:\Users\<username>\Desktop\Malware\Bad Rabbit\bad-rabbit.exe File name: bad-rabbit.exe
Size: 142.84 KB (142848 bytes)
MD5: b14d8faf7f0cbcfad051cefe5f39645f
Detection count: 9
File type: Executable File
Mime Type: unknown/exe
Path: C:\Users\<username>\Desktop\Malware\Bad Rabbit\bad-rabbit.exe
Group: Malware file
Last Updated: September 1, 2023
%SYSTEMDRIVE%\Users\<username>\Desktop\2sun6578095111569408\579fd8a0385482fb4c789561a30b09f25671e86422f40ef5cca2036b28f99648 File name: 579fd8a0385482fb4c789561a30b09f25671e86422f40ef5cca2036b28f99648
Size: 410.76 KB (410760 bytes)
MD5: 1d724f95c61f1055f0d02c2154bbccd3
Detection count: 7
Path: %SYSTEMDRIVE%\Users\<username>\Desktop\2sun6578095111569408\579fd8a0385482fb4c789561a30b09f25671e86422f40ef5cca2036b28f99648
Group: Malware file
Last Updated: July 3, 2021

More files
Loading...
Spywareremove.com uses cookies to provide you with a better browsing experience and analyze how users navigate and utilize the Site. By using this Site or clicking on "OK", you consent to the use of cookies. Learn more.