• CommunityEnterprisePlans
  • Intel Exchange
    Intel ExchangeDetections
  • Resources
  • About
  • Leaderboard
Join CommunitySign In
    All Detections

    CRPx0 Pre-Encryption Shadow Copy and Backup Destruction

    avatar
    GlassDiceBearhttps://www.dicebear.comhttps://creativecommons.org/publicdomain/zero/1.0/„Glass” (https://www.dicebear.com) by „DiceBear”, licensed under „CC0 1.0” (https://creativecommons.org/publicdomain/zero/1.0/)
    Ibrahim Saud@tektrix
    •updated 25 days ago•0•0•0

    Detects pre-encryption activity typical of the CRPx0 ransomware, involving the destruction of Windows Volume Shadow Copies, Windows Backup Catalogs, or macOS Time Machine snapshots using system utilities such as vssadmin, wbadmin, wmic, or tmutil. This behavior is indicative of an imminent encryption phase.

    YARA-L

    Tags

    T1490 - Inhibit System RecoveryT1047 - Windows Management InstrumentationTA0040 - ImpactTA0002 - ExecutionProcess CreationCommand ExecutionWindowsmacOSWindows SysmonWindows Eventlog Security

    Found in

    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026
    • CRPx0 ClickFix Ransomware Technical AnalysisLast updated Sep 9, 2026

    Community Inspired.
    AI Enhanced.
    Better Detections.

    Follow Us

    Company

    • About
    • Leaderboard

    Product

    • Community
    • Enterprise
    • Plans

    © 2026 Copyright. All Rights Reserved.

    Privacy PolicyTerms of Service

    Sign up to view this detection

    or

    Already have an account?