Globe targets Windows OS and its method of distribution is currently unknown. Once installed, Globe employs its anti-forensic capabilities as it determines whether or not it is running within a sandbox or a virtual machine (VM) such as Anubis, VirtualBox, VMware, or Virtual PC. If any of these are present, Globe will terminate itself. If none are detected, Globe begins the encryption process using the Blowfish encryption algorithm, targeting 995 file extensions and appending .globe or .purge to the name of every file it encrypts. It then creates an autorun.inf file which displays a ransom note using an HTML Application file named How to restore files.hta which opens when the victim logs into Windows. Globe deletes Shadow Volume Copies to prevent file restoration and disables Windows Startup Repair. Lastly, Globe will change the victim’s desktop wallpaper to display an image featuring characters from the movie, The Purge: Election Year.
Extensions appended to encrypted file names by Globe:
.blt, [random].encrypted, .[random].raid10, .[firstname.lastname@example.org], .[random].globe, .zendr2, .blackblock, .email@example.com, .GSupport3, .firstname.lastname@example.org, .zendrz, .zendr4, .MK, .x3m, .UCRYPT, .ACRYPT, .SGood, .email@example.com, .firstname.lastname@example.org, .trust, .nazarbayev, decryptallfiles[@]india.com, .lovewindows, bahij2[@]india.com, ink, .ziptox1, .restorefiles[@]protonmail.ch.FROZEN, .sorry, .email@example.com
Extensions appended to encrypted file names by Globe v2:
.decryptional, .firstname.lastname@example.org, .email@example.com
Extensions appended to encrypted file names by Globe v3:
.wuciwug, .happydayzz, .1, .x3mpro, .firstname.lastname@example.org, .[File-Help@India.Com].mails, .WormKiller@india.com.xtbl, .[email@example.com], .firstname.lastname@example.org, .[Gofmen17@Ya.Ru],Crp
Ransom note file names:
- Bleeping Computer provides more information about Globe here.
- Emsisoft provides a decryption tool for Globe, available here.
- Emsisoft provides a decryption tool for Globe2, available here.
- Emsisoft provides a decryption tool for Globe version 3 here. This tool will decrypt files appended with .decrypt2017 and hnumkhotep.