Rook ransomware encrypts its victims files with AES in ECB mode and instruct them to contact them at rook@onionmail.org for ransom negotiations. All encrypted files are appended with
.Rook Ransom extension. It is based on the leaked source code of
Babuk Ransomware.
Rook Ransomware Signatures
Family: Ransom:Win32/RookCrypt.PA!MTB
MD5: bec9b3480934ce3d30c25e1272f60d02
SHA256: f87be226e26e873275bde549539f70210ffe5e3a129448ae807a319cbdcf7789
Rook Ransomware Download