Skip to main content
← Back to Demos
Malware beginner · 15 min

LockBit-style ransomware binary caught by signature engines

The Gentlemen ransomware group has claimed 478 victims, and Krebs on Security published a deep-dive investigation into its leadership and operations — evidence of how prolific file-encrypting extortion has become. Ransomware binaries typically enumerate and encrypt local and network files, demanding payment for the decryption key, an impact technique mapped to T1486. This demo shows how MetaDefender Metascan applies signatures and heuristics from 30+ anti-malware engines to catch a ransomware-style executable at the gateway before it can run. The demo file is the EICAR test string, a safe, industry-standard sample used to verify detection without deploying actual ransomware.

Attack Technique

Ransomware family

MITRE ATT&CK

T1486 ↗

Platforms

linuxwindows

File Types

.txt

MetaDefender Capabilities

Metascan

Incident Coverage

This attack technique maps to a real-world security incident — read the daily digest for details: Read the incident digest ↗

--- ---