<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/">
	<channel>
		<title><![CDATA[Geeks for your information - CheckMAL Videos]]></title>
		<link>https://www.geeks.fyi/</link>
		<description><![CDATA[Geeks for your information - https://www.geeks.fyi]]></description>
		<pubDate>Tue, 12 May 2026 02:51:53 +0000</pubDate>
		<generator>MyBB</generator>
		<item>
			<title><![CDATA[AppCheck Ransomware Block Videos 01 to 02 2025]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20638</link>
			<pubDate>Tue, 25 Feb 2025 12:01:26 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1295">jasonX</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20638</guid>
			<description><![CDATA[<div style="text-align: left;" class="mycode_align"> <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">Stop Ransomware (.xcvf) 2025. 01. 30.197</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/RBOY-t-kJkk" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/ggFBW0X.png" loading="lazy"  alt="[Image: ggFBW0X.png]" class="mycode_img" /></div>
<br />
<br />
<br />
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">TargetCompany Ransomware (.FARGO2) 2025. 01. 30.218</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/boVHu_7l8xU" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/yF0VrOZ.png" loading="lazy"  alt="[Image: yF0VrOZ.png]" class="mycode_img" /></div>
<br />
<br />
<br />
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">BianLian Ransomware (.bianlian) 2025. 02. 08.154</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/rCFJOpvld0I" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/UMl9zNW.png" loading="lazy"  alt="[Image: UMl9zNW.png]" class="mycode_img" /></div>
<br />
<br />
<br />
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">LockBit v3.0 Ransomware (.BBNvvvgMC) 2025. 02. 09.185</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/jaIxGlVgliY" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/eX84g6i.png" loading="lazy"  alt="[Image: eX84g6i.png]" class="mycode_img" /></div>
<br />
<br />
<br />
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">Stop Ransomware (.sijr) 2025. 02. 20.95</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/5Hy1G5kmmi0" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/2b0M1GU.png" loading="lazy"  alt="[Image: 2b0M1GU.png]" class="mycode_img" /><br />
<br />
<span style="font-style: italic;" class="mycode_i"><span style="font-size: small;" class="mycode_size">Data and info derived/lifted from CheckMAL with permission</span></span></div>
</div>]]></description>
			<content:encoded><![CDATA[<div style="text-align: left;" class="mycode_align"> <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">Stop Ransomware (.xcvf) 2025. 01. 30.197</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/RBOY-t-kJkk" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/ggFBW0X.png" loading="lazy"  alt="[Image: ggFBW0X.png]" class="mycode_img" /></div>
<br />
<br />
<br />
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">TargetCompany Ransomware (.FARGO2) 2025. 01. 30.218</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/boVHu_7l8xU" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/yF0VrOZ.png" loading="lazy"  alt="[Image: yF0VrOZ.png]" class="mycode_img" /></div>
<br />
<br />
<br />
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">BianLian Ransomware (.bianlian) 2025. 02. 08.154</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/rCFJOpvld0I" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/UMl9zNW.png" loading="lazy"  alt="[Image: UMl9zNW.png]" class="mycode_img" /></div>
<br />
<br />
<br />
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">LockBit v3.0 Ransomware (.BBNvvvgMC) 2025. 02. 09.185</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/jaIxGlVgliY" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/eX84g6i.png" loading="lazy"  alt="[Image: eX84g6i.png]" class="mycode_img" /></div>
<br />
<br />
<br />
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">Stop Ransomware (.sijr) 2025. 02. 20.95</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/5Hy1G5kmmi0" frameborder="0" allowfullscreen="true"></iframe><br />
<br />
<img src="https://i.imgur.com/2b0M1GU.png" loading="lazy"  alt="[Image: 2b0M1GU.png]" class="mycode_img" /><br />
<br />
<span style="font-style: italic;" class="mycode_i"><span style="font-size: small;" class="mycode_size">Data and info derived/lifted from CheckMAL with permission</span></span></div>
</div>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Lilith Ransomware (.lilith)]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20531</link>
			<pubDate>Mon, 27 Jan 2025 09:25:19 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1295">jasonX</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20531</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align">
<span style="font-weight: bold;" class="mycode_b">Lilith Ransomware (.lilith) (2025. 01. 04. 660)</span></div>
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">AppCheck Anti-Ransomware : Lilith Ransomware (.lilith) Block Video</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/gH3-OWyxMR8" frameborder="0" allowfullscreen="true"></iframe></div>
<br />
<span style="font-weight: bold;" class="mycode_b">Distribution Method :</span> Unknown<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">MD5 :</span> b7a182db3ba75e737f75bda1bc76331a<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Detection Name :</span> Ransomware/Win.LILITHCRYPT.C5205307 (AhnLab V3), Trojan.Ransom.Lilith.B (BitDefender)<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Encrypted File Pattern :</span> .lilith<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Payment Instruction File :</span> Restore_Your_Files.txt<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Characteristics :</span><br />
 <ul class="mycode_list"><li>Offline Encryption<br />
</li>
<li>Recovery Partition (M:\) + EFI System Partition (N:\) drives are activate.<br />
</li>
<li>Block processes execution (agntsvc.exe, dbsnmp.exe, ocssd.exe, oracle.exe, sql.exe, synctime.exe etc.)<br />
</li>
</ul>
<br />
<br />
<br />
<span style="font-weight: bold;" class="mycode_b"><a href="https://www.checkmal.com/video/read/6793/?p=1" target="_blank" rel="noopener" class="mycode_url">More Info HERE</a></span><br />
<br />
<span style="font-style: italic;" class="mycode_i"><span style="font-size: small;" class="mycode_size">Content lifted from CheckMAL site with permission</span></span>]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align">
<span style="font-weight: bold;" class="mycode_b">Lilith Ransomware (.lilith) (2025. 01. 04. 660)</span></div>
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">AppCheck Anti-Ransomware : Lilith Ransomware (.lilith) Block Video</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/gH3-OWyxMR8" frameborder="0" allowfullscreen="true"></iframe></div>
<br />
<span style="font-weight: bold;" class="mycode_b">Distribution Method :</span> Unknown<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">MD5 :</span> b7a182db3ba75e737f75bda1bc76331a<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Detection Name :</span> Ransomware/Win.LILITHCRYPT.C5205307 (AhnLab V3), Trojan.Ransom.Lilith.B (BitDefender)<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Encrypted File Pattern :</span> .lilith<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Payment Instruction File :</span> Restore_Your_Files.txt<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Characteristics :</span><br />
 <ul class="mycode_list"><li>Offline Encryption<br />
</li>
<li>Recovery Partition (M:\) + EFI System Partition (N:\) drives are activate.<br />
</li>
<li>Block processes execution (agntsvc.exe, dbsnmp.exe, ocssd.exe, oracle.exe, sql.exe, synctime.exe etc.)<br />
</li>
</ul>
<br />
<br />
<br />
<span style="font-weight: bold;" class="mycode_b"><a href="https://www.checkmal.com/video/read/6793/?p=1" target="_blank" rel="noopener" class="mycode_url">More Info HERE</a></span><br />
<br />
<span style="font-style: italic;" class="mycode_i"><span style="font-size: small;" class="mycode_size">Content lifted from CheckMAL site with permission</span></span>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[Redeemer Ransomware (.redeem)]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20530</link>
			<pubDate>Mon, 27 Jan 2025 09:22:51 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1295">jasonX</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20530</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align">
<span style="font-weight: bold;" class="mycode_b">Redeemer Ransomware (.redeem) (2025. 01. 17. 456)</span></div>
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">AppCheck Anti-Ransomware : Redeemer Ransomware (.redeem) Block Video</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/ixB8rUgMICE" frameborder="0" allowfullscreen="true"></iframe></div>
<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Distribution Method :</span> Unknown<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">MD5 :</span> e37a0ece30267233f1dddf3c2300393f<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Detection Name :</span> Ransom:Win32/Redeemer.MK!MTB (Microsoft), Ransom.Win32.REDEEM.YXBLV (Trend Micro)<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Encrypted File Pattern :</span> .redeem<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Malicious File Creation Location :</span><br />
 <ul class="mycode_list"><li>C:\Windows\ProgramData<br />
</li>
<li>C:\Windows\ProgramData\calc.exe<br />
</li>
<li>C:\Windows\SQL<br />
</li>
<li>C:\Windows\SQL\taskhost.exe<br />
</li>
<li>C:\Windows\SQL\rem.bat<br />
</li>
<li>C:\Windows\svchost<br />
</li>
<li>C:\Windows\svchost\conhost.exe<br />
<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Payment Instruction File :</span> Read Me.TXT<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Characteristics :</span><br />
 <ul class="mycode_list"><li>Offline Encryption<br />
</li>
<li>Disable system restore (vssadmin delete shadows /All /Quiet)<br />
</li>
<li>Deletes event log (wevtutil clear-log Application, wevtutil clear-log Security, wevtutil clear-log Setup, wevtutil clear-log System)<br />
</li>
</ul>
<br />
<br />
<span style="font-weight: bold;" class="mycode_b"><a href="https://www.checkmal.com/video/read/6794/?p=1" target="_blank" rel="noopener" class="mycode_url">More Info HERE</a></span><br />
<br />
<span style="font-style: italic;" class="mycode_i"><span style="font-size: small;" class="mycode_size">Content lifted from CheckMAL site with permission</span></span>]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align">
<span style="font-weight: bold;" class="mycode_b">Redeemer Ransomware (.redeem) (2025. 01. 17. 456)</span></div>
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">AppCheck Anti-Ransomware : Redeemer Ransomware (.redeem) Block Video</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/ixB8rUgMICE" frameborder="0" allowfullscreen="true"></iframe></div>
<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Distribution Method :</span> Unknown<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">MD5 :</span> e37a0ece30267233f1dddf3c2300393f<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Detection Name :</span> Ransom:Win32/Redeemer.MK!MTB (Microsoft), Ransom.Win32.REDEEM.YXBLV (Trend Micro)<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Encrypted File Pattern :</span> .redeem<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Malicious File Creation Location :</span><br />
 <ul class="mycode_list"><li>C:\Windows\ProgramData<br />
</li>
<li>C:\Windows\ProgramData\calc.exe<br />
</li>
<li>C:\Windows\SQL<br />
</li>
<li>C:\Windows\SQL\taskhost.exe<br />
</li>
<li>C:\Windows\SQL\rem.bat<br />
</li>
<li>C:\Windows\svchost<br />
</li>
<li>C:\Windows\svchost\conhost.exe<br />
<br />
</li>
</ul>
<br />
<span style="font-weight: bold;" class="mycode_b">Payment Instruction File :</span> Read Me.TXT<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Characteristics :</span><br />
 <ul class="mycode_list"><li>Offline Encryption<br />
</li>
<li>Disable system restore (vssadmin delete shadows /All /Quiet)<br />
</li>
<li>Deletes event log (wevtutil clear-log Application, wevtutil clear-log Security, wevtutil clear-log Setup, wevtutil clear-log System)<br />
</li>
</ul>
<br />
<br />
<span style="font-weight: bold;" class="mycode_b"><a href="https://www.checkmal.com/video/read/6794/?p=1" target="_blank" rel="noopener" class="mycode_url">More Info HERE</a></span><br />
<br />
<span style="font-style: italic;" class="mycode_i"><span style="font-size: small;" class="mycode_size">Content lifted from CheckMAL site with permission</span></span>]]></content:encoded>
		</item>
		<item>
			<title><![CDATA[AstraLocker v2.0 Ransomware (.AstraLocker)]]></title>
			<link>https://www.geeks.fyi/showthread.php?tid=20529</link>
			<pubDate>Mon, 27 Jan 2025 09:19:48 +0000</pubDate>
			<dc:creator><![CDATA[<a href="https://www.geeks.fyi/member.php?action=profile&uid=1295">jasonX</a>]]></dc:creator>
			<guid isPermaLink="false">https://www.geeks.fyi/showthread.php?tid=20529</guid>
			<description><![CDATA[<div style="text-align: center;" class="mycode_align">
<span style="font-weight: bold;" class="mycode_b">AstraLocker v2.0 Ransomware (.AstraLocker) (2025. 01. 18. 434)</span></div>
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">AppCheck Anti-Ransomware : AstraLocker v2.0 Ransomware (.AstraLocker) Block Video</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/qC5tRsfwXRQ" frameborder="0" allowfullscreen="true"></iframe></div>
<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Distribution Method :</span> Unknown<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">MD5 :</span> 8db7d5fb5cbdfc0731978261639f01a6<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Detection Name :</span> Ransom:Win32/Babuk.MAK!MTB (Microsoft), Ransom.Win32.BABUK.SMRD1 (Trend Micro)<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Encrypted File Pattern :</span> .AstraLocker<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Payment Instruction File :</span> Recover_Your_Files.html<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Characteristics :</span><br />
 <ul class="mycode_list"><li>Offline Encryption<br />
</li>
<li>Babuk Locker / ChiChi Locker / DARKY LOCK / Delta Plus / Pandora / RA Group / Rook Ransomware series<br />
</li>
<li>Recovery Partition (M:\) + EFI System Partition (N:\) drives are activate.<br />
</li>
<li>Block processes execution (excel.exe, firefox.exe, oracle.exe, sql.exe, synctime.exe, thebat.exe etc.)<br />
</li>
<li>Stop multi services (backup, DefWatch, GxFWD, QBFCService, sophos, veeam etc.)<br />
</li>
<li>Disable system restore (vssadmin.exe delete shadows /all /quiet)<br />
</li>
</ul>
<br />
<br />
<br />
<br />
<span style="font-weight: bold;" class="mycode_b"><a href="https://www.checkmal.com/video/read/6795/?p=1" target="_blank" rel="noopener" class="mycode_url">More Info HERE</a></span><br />
<br />
<span style="font-style: italic;" class="mycode_i"><span style="font-size: small;" class="mycode_size">Content lifted from CheckMAL site with permission</span></span>]]></description>
			<content:encoded><![CDATA[<div style="text-align: center;" class="mycode_align">
<span style="font-weight: bold;" class="mycode_b">AstraLocker v2.0 Ransomware (.AstraLocker) (2025. 01. 18. 434)</span></div>
 <br />
<div style="text-align: center;" class="mycode_align"><span style="font-weight: bold;" class="mycode_b">AppCheck Anti-Ransomware : AstraLocker v2.0 Ransomware (.AstraLocker) Block Video</span></div>
<div style="text-align: center;" class="mycode_align"><iframe width="560" height="315" src="//www.youtube-nocookie.com/embed/qC5tRsfwXRQ" frameborder="0" allowfullscreen="true"></iframe></div>
<br />
<br />
<span style="font-weight: bold;" class="mycode_b">Distribution Method :</span> Unknown<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">MD5 :</span> 8db7d5fb5cbdfc0731978261639f01a6<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Detection Name :</span> Ransom:Win32/Babuk.MAK!MTB (Microsoft), Ransom.Win32.BABUK.SMRD1 (Trend Micro)<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Encrypted File Pattern :</span> .AstraLocker<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Payment Instruction File :</span> Recover_Your_Files.html<br />
 <br />
<span style="font-weight: bold;" class="mycode_b">Major Characteristics :</span><br />
 <ul class="mycode_list"><li>Offline Encryption<br />
</li>
<li>Babuk Locker / ChiChi Locker / DARKY LOCK / Delta Plus / Pandora / RA Group / Rook Ransomware series<br />
</li>
<li>Recovery Partition (M:\) + EFI System Partition (N:\) drives are activate.<br />
</li>
<li>Block processes execution (excel.exe, firefox.exe, oracle.exe, sql.exe, synctime.exe, thebat.exe etc.)<br />
</li>
<li>Stop multi services (backup, DefWatch, GxFWD, QBFCService, sophos, veeam etc.)<br />
</li>
<li>Disable system restore (vssadmin.exe delete shadows /all /quiet)<br />
</li>
</ul>
<br />
<br />
<br />
<br />
<span style="font-weight: bold;" class="mycode_b"><a href="https://www.checkmal.com/video/read/6795/?p=1" target="_blank" rel="noopener" class="mycode_url">More Info HERE</a></span><br />
<br />
<span style="font-style: italic;" class="mycode_i"><span style="font-size: small;" class="mycode_size">Content lifted from CheckMAL site with permission</span></span>]]></content:encoded>
		</item>
	</channel>
</rss>