Mobef, Yakes
Tags
country: India
attack-pattern: Software - T1592.002
Common Information
Type Value
UUID 81b7e7ed-dfaa-472f-9168-cddc0ecd3f16
Fingerprint e27d387f5465fa2a
Analysis status DONE
Considered CTI value 0
Text language
Published April 20, 2016, 10:39 p.m.
Added to db Sept. 26, 2022, 9:32 a.m.
Last updated Nov. 17, 2024, 11:40 p.m.
Headline Шифровальщики-вымогатели The Digest "Crypto-Ransomware"
Title Mobef, Yakes
Detected Hints/Tags/Attributes 19/2/36
Attributes
Details Type #Events CTI Value
Details Domain 396
protonmail.com
Details Domain 99
india.com
Details Domain 4128
github.com
Details Domain 2
1nformat1onfor.you
Details Domain 1
kentamplin.net
Details Domain 1
pgndeltapsi.com
Details Domain 1
pleaseread.me
Details Domain 155
yandex.com
Details Domain 2
moscowmail.com
Details Email 2
momsbestfriend@protonmail.com
Details Email 3
torrenttracker@india.com
Details Email 2
the.dodger@protonmail.com
Details Email 2
logical.disk@yandex.com
Details Email 2
windows.update@moscowmail.com
Details File 17
8.exe
Details File 2
-infection.txt
Details File 1
4-15-2016-infection.txt
Details File 1
4152016000.key
Details File 1
2886098.txt
Details File 31
tmp.exe
Details File 59
2.exe
Details File 2
-infectione.txt
Details File 1
date-infectione.txt
Details File 2
000.key
Details File 1
date000.key
Details File 2
encrypt1on.key
Details File 2
hitlerslittlecrypter.key
Details File 2
hitlersnastylittlecrypter.key
Details File 2
hitlerhasyourfiles.key
Details File 1
thisisa.key
Details File 1
443826.log
Details Github username 1
mailchuck
Details IPv4 1
192.185.16.132
Details Windows Registry Key 4
HKEY_CLASSES_ROOT\interface
Details Windows Registry Key 2
HKLM\Software\Microsoft\Cryptography\DESHashSessionKeyBackward
Details Windows Registry Key 2
HKLM\Software\Microsoft\Cryptography\Defaults\Provider\Microsoft