Home Malware Programs Ransomware MOLE Ransomware

MOLE Ransomware

Posted: April 13, 2017

Threat Metric

Threat Level: 10/10
Infected PCs: 1,218
First Seen: April 13, 2017
Last Seen: April 18, 2022
OS(es) Affected: Windows

The MOLE Ransomware is a new member of a Trojan family referred to as either CryptoMix or CryptMix Ransomware. Trojans within this group use a currently-unbreakable encryption method to encode and block your files, for which they extort ransom money. Users should avoid the delivery-themed e-mail links of this Trojan's campaign, along with having anti-malware products for eliminating the MOLE Ransomware or its installers in a preventative fashion.

What's Burrowing into Your File Data Today

Once again, con artists are exploiting e-mail as a favorable means of distributing new file-encrypting Trojans to victims, with the associated messages posing as notifications from the USPS. Instead of attaching the Trojan directly, the e-mails display links leading to fake plugins for the Microsoft Office program. Unprotected users clicking these links expose their browsers to an instance of the RIG Exploit Kit, which installs the MOLE Ransomware. Malware experts also note ties between this EK and other Trojan campaigns, usually with similar, encryption-based payloads.

The MOLE Ransomware is a Windows-specific Trojan that disables its installation on virtual or sandbox environments, which often are useful for threat analysis. If it does detect a suitable system environment, the MOLE Ransomware launches an install routine that includes a fake 'Color Calibration' pop-up to trick the user into giving it UAC admin privileges. Then, it launches the following attacks:

  • The MOLE Ransomware conducts some network communications to provide its threat actor with a customized ID number for the infected PC, in addition to receiving an RSA-1024 encryption key that it saves locally.
  • Using an AES-256 algorithm, the MOLE Ransomware encrypts media on all drives, such as documents, and renames them with a pattern of thirty-two hexadecimal characters and the '.MOLE' extension. The latter feature overwrites the original filenames.
  • The MOLE Ransomware disables essential Windows services and features, including startup recovery, the Windows Defender, the Windows Update and the Background Intelligent Transfer Service.
  • Like most file-encrypting Trojans of the past two years, the MOLE Ransomware also erases your Shadow Copies, which victims could use for recovering their encrypted files from default system backups.

Stopping an Expensive Mix-up of Your Files

The MOLE Ransomware's method of collecting a payoff for its attack is somewhat less sophisticated than the rest of its payload and uses nothing more than a Notepad message it places in every folder that has encrypted content. Victims have the option of contacting the e-mail addresses in the MOLE Ransomware's instructions and paying an unspecified ransom or risking the potential destruction of their files. Malware analysts have yet to find any vulnerabilities in the MOLE Ransomware's encryption method, which places importance on having backups dating to before an infection.

Even though some PC users may choose to protect themselves by using virtual environments, this safety measure is often impractical and doesn't stop all file-encrypting threats. Anti-malware programs with high rates of detecting similar Trojans also may delete the MOLE Ransomware or, preferably, block the RIG Exploit Kit's drive-by-downloads. Since its install process requires misinformed consent from the user in multiple locations, simply being cautious about what prompts and links you click eliminates much of the risk in the MOLE Ransomware's current infection vectors.

Ransom-based Trojans are extremely dependent on mistakes from the people they're attacking. Use that weakness to your advantage and avoid assuming that anything that looks safe can't harm your computer or the files you save on it.

Technical Details

File System Modifications

Tutorials: If you wish to learn how to remove malware components manually, you can read the tutorials on how to find malware, kill unwanted processes, remove malicious DLLs and delete other harmful files. Always be sure to back up your PC before making any changes.

The following files were created in the system:



%SystemDrive%\system16\svnsir32.exe File name: svnsir32.exe
Size: 267.77 KB (267776 bytes)
MD5: 99cbe33113569d3e5497f37edc870b7f
Detection count: 157
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\system16
Group: Malware file
Last Updated: August 3, 2017
C:\system16\svwinsi32.exe File name: svwinsi32.exe
Size: 887.29 KB (887296 bytes)
MD5: ad20dcb42355b9c2ba552e8bb5f1930d
Detection count: 86
File type: Executable File
Mime Type: unknown/exe
Path: C:\system16
Group: Malware file
Last Updated: August 3, 2017
C:\system16\svnsir32.exe File name: svnsir32.exe
Size: 267.77 KB (267776 bytes)
MD5: c8d79fbe326908645fd36e677cbda2f0
Detection count: 85
File type: Executable File
Mime Type: unknown/exe
Path: C:\system16
Group: Malware file
Last Updated: August 3, 2017
%SystemDrive%\system16\svwinsi32.exe File name: svwinsi32.exe
Size: 238.08 KB (238080 bytes)
MD5: 3862eeef4876dc4fe4ea3ae8f4a47772
Detection count: 75
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\system16
Group: Malware file
Last Updated: January 8, 2020
ff993bf1045d316feddcdb9fad538ac954a23903db130487393f9c3ae510aea1.exe File name: ff993bf1045d316feddcdb9fad538ac954a23903db130487393f9c3ae510aea1.exe
Size: 159.74 KB (159744 bytes)
MD5: a5d1968dd130c55f6d489e8cde0a063d
Detection count: 55
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 3, 2017
f1b94366f2f10ea20353a699e6baa1a9bb1b020542097bb92c523b9976235eb4.exe File name: f1b94366f2f10ea20353a699e6baa1a9bb1b020542097bb92c523b9976235eb4.exe
Size: 324.45 KB (324450 bytes)
MD5: ae7f92a75196e87aa8db98ff230df0d4
Detection count: 53
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 3, 2017
e517ee3143154a29be42ffbd9199913f74d8849331fcc676e83934de1a1de2ed.exe File name: e517ee3143154a29be42ffbd9199913f74d8849331fcc676e83934de1a1de2ed.exe
Size: 151.55 KB (151552 bytes)
MD5: 3eee60c87ff1c51f453899d7bd192d6d
Detection count: 52
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 3, 2017
8684d808cf2c7aeab453c95d8269ee3a4492adfcead1c93bef681de29192a1a1.exe File name: 8684d808cf2c7aeab453c95d8269ee3a4492adfcead1c93bef681de29192a1a1.exe
Size: 77.78 KB (77786 bytes)
MD5: bb3897302c220e6eb62334f7ac83e8a6
Detection count: 46
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 3, 2017
648eb39a5e77af2e2069e196a5709a93e81b29c74dbe2fa4ead4440e0f535e97.exe File name: 648eb39a5e77af2e2069e196a5709a93e81b29c74dbe2fa4ead4440e0f535e97.exe
Size: 90.11 KB (90112 bytes)
MD5: 48460c1f75469995a67349fe0766f776
Detection count: 44
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 3, 2017
4eb2d565b18d172a3b2b069ebf152dd6a1514e7b444eaffbbaff77f63984705c.exe File name: 4eb2d565b18d172a3b2b069ebf152dd6a1514e7b444eaffbbaff77f63984705c.exe
Size: 159.74 KB (159744 bytes)
MD5: 254abe18b689493a08c4fe12dd61c366
Detection count: 42
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 3, 2017
3ed7a05172c1bc52acec83f2ac17d1ad01e26d99e544804730f044c1042ce474.exe File name: 3ed7a05172c1bc52acec83f2ac17d1ad01e26d99e544804730f044c1042ce474.exe
Size: 232.29 KB (232290 bytes)
MD5: bc93bc9bf363e9c3b32dd484c61571ff
Detection count: 41
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: May 3, 2017
3b5b19ebe8d8b6c7e5b2ffd2cc194fad1ae6c9eade7646f48c595bd154f4b1e1.exe File name: 3b5b19ebe8d8b6c7e5b2ffd2cc194fad1ae6c9eade7646f48c595bd154f4b1e1.exe
Size: 85.5 KB (85504 bytes)
MD5: 132a4f45cd74a8dd906f0af3e582d0a9
Detection count: 40
File type: Executable File
Mime Type: unknown/exe
Group: Malware file
Last Updated: December 1, 2020
%APPDATA%\system16\svwinse.exe File name: svwinse.exe
Size: 409.6 KB (409600 bytes)
MD5: 1ec6fcd1afb5a07f0dff5fe97663e494
Detection count: 30
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\system16
Group: Malware file
Last Updated: June 27, 2017
%APPDATA%\system16\svwinse.exe File name: svwinse.exe
Size: 247.8 KB (247808 bytes)
MD5: 2f4489e85c3d6d81beeb90973c8c3b6c
Detection count: 16
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\system16
Group: Malware file
Last Updated: June 27, 2017
%SystemDrive%\system16\svwinsi32.exe File name: svwinsi32.exe
Size: 907.61 KB (907611 bytes)
MD5: adae879dc7a5b48a86ed1c588ab456fd
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\system16
Group: Malware file
Last Updated: August 3, 2017
%SystemDrive%\system16\svwinsi32.exe File name: svwinsi32.exe
Size: 265.72 KB (265728 bytes)
MD5: ba7c4d7859b000677158887480404116
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\system16
Group: Malware file
Last Updated: August 3, 2017
%SystemDrive%\system16\svwinsi32.exe File name: svwinsi32.exe
Size: 887.29 KB (887296 bytes)
MD5: a09251f74b1aae681c822b4ae12739ae
Detection count: 12
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\system16
Group: Malware file
Last Updated: August 3, 2017
%APPDATA%\system16\svwinse.exe File name: svwinse.exe
Size: 401.4 KB (401408 bytes)
MD5: 1cddf8fc941e4dfa6715a835abc13385
Detection count: 5
File type: Executable File
Mime Type: unknown/exe
Path: %APPDATA%\system16
Group: Malware file
Last Updated: June 27, 2017
%SystemDrive%\system16\svwinse27.exe File name: svwinse27.exe
Size: 332.28 KB (332288 bytes)
MD5: aaf93f435905fa40c4893abe3aa7cbb9
Detection count: 1
File type: Executable File
Mime Type: unknown/exe
Path: %SystemDrive%\system16
Group: Malware file
Last Updated: June 27, 2017

More files

Registry Modifications

The following newly produced Registry Values are:

File name without pathINSTRUCTION_FOR_HELPING_FILE_RECOVERY.TXT

Related Posts

Loading...