LooCipher Ransomware encrypts user data with AES, and then requires a ransom in BTC to return files. It spreads via spam email campaigns. It spread macro enabled word document called Info_BSV_2019.docm. Upon user enable the macros malicious executable is download with encrypt user data.
Update: LooChiper Ransomware Decryptor is available now.
LooCipher Macro Document Signatures
Family: HEUR:Trojan-Downloader.Script.Generic
MD5: 868a06468b0eb6d5e9777681a0cb2afe
SHA256: e824650b66c5cdd8c71983f4c4fc0e1ac55cd04809d562f3b6b4790a28521486
LooCipher Macro Document Download
LooCipher Ransomware Signatures
Family: Trojan:Win32/Sonoko.A!ms
MD5: 0c7e59536a7be4a446bbe8b4f22e5880
SHA256: 43cfb0a439705ab2bd7c46b39a7265ff0a14f7bd710b3e1432a9bdc4c1736c49
LooCipher Ransomware Download