RIG EK at 5.200.52.238 Drops Ransom Locker
Common Information
Type Value
UUID 550b2a22-5c4e-4d01-a7d2-233eb38d56e4
Fingerprint 39900159edbb8aae
Analysis status DONE
Considered CTI value 2
Text language
Published March 27, 2017, 9:09 p.m.
Added to db Jan. 18, 2023, 9:59 p.m.
Last updated Nov. 18, 2024, 4:35 a.m.
Headline RIG EK at 5.200.52.238 Drops Ransom Locker
Title RIG EK at 5.200.52.238 Drops Ransom Locker
Detected Hints/Tags/Attributes 33/3/29
Attributes
Details Type #Events CTI Value
Details Domain 2
milliption.gdn
Details Domain 7
www.cyphort.com
Details Domain 2
fast.napadieselguide.com
Details Domain 1176
gmail.com
Details Email 1
malwarebreakdown@gmail.com
Details File 23
o32.tmp
Details File 1
pmpp20mo.exe
Details File 1
rocanebeda.exe
Details File 1
ffaebc00xx.tmp
Details File 1
wal.txt
Details File 3
upd.php
Details File 5
default.jpg
Details File 1
appdatalocaltemppmpp20mo.exe
Details File 1
appdatalocaltempo32.tmp
Details File 1
appdataroamingupd2explersysdrv32xzrocanebeda.exe
Details File 1
appdataroamingffaebc00xx.tmp
Details File 1
appdataroamingupd2explersysdrz.bmp
Details File 1
appdataroamingupd2explersysdrz.jpg
Details File 52
exploit.swf
Details sha256 1
cb36d55f538f5833fe0bd6e0d279624509b41b0228f60b3031a9d821a9a59cce
Details sha256 1
edf9f0c335175d47fa696b29b9cdeb78fd3477b7b59e965749ea203708647742
Details sha256 1
c39bf6674db6e6a8e16c08ef4ba400aa306c66e4e8c9e378423c5bb6c36f748c
Details IPv4 2
5.200.52.238
Details IPv4 2
62.75.195.128
Details IPv4 1
158.69.59.164
Details Url 1
https://www.cyphort.com/new-family-of-ransom-locker-found-uses-tor-hidden-service
Details Windows Registry Key 1
HKLMSoftwareMicrosoftWindowsCurrentVersionPoliciesExplorer
Details Windows Registry Key 15
HKCUSoftwareMicrosoftWindowsCurrentVersionRun
Details Windows Registry Key 1
HKCUSoftwareMicrosoftWindowsCurrentVersionRunOnce