MBRlock
Aliases: DexLocker
- First seen
- 2017-01-01 00:00:00
- Malware type
- ransomware
- Family
- Malware family
- Profile updated
- 2026-07-07 15:11:32
Targeted industries: financial-services healthcare-and-pharmaceutical retail-and-hospitality
Context
This ransomware modifies the master boot record of the victim's computer so that it shows a ransom note before Windows starts.
Detection coverage
- 1 YARA rules
Detection rules
- MALPEDIA_Win_Mbrlock_Auto (yara-rule)
Reports & references
- malpedia.caad.fkie.fraunhofer.de — Win.Mbrlock (report)
- bleepingcomputer.com — Dexcrypt Mbrlocker Demands 30 Yuan To Gain Access To Computer (report)
- app.any.run — 0A7E643F 7562 4575 B8A5 747Bd6B5F02D (report)
- hybrid-analysis.com — Dfc56A704B5E031F3B0D2D0Ea1D06F9157758Ad950483B44Ac4B77D33293Cb38 (report)
- id-ransomware.blogspot.com.tr — Mbrlock Hax Ransomware (report)