Zeropadypt, Ouroboros
Tags
attack-pattern: | Data Malware - T1587.001 Malware - T1588.001 Server - T1583.004 Server - T1584.004 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | d31f0334-099f-42b1-854f-6d398e8852b5 |
Fingerprint | 129dd05f4db41a69 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | April 27, 2019, 1 p.m. |
Added to db | Jan. 18, 2023, 7:55 p.m. |
Last updated | Nov. 17, 2024, 5:57 p.m. |
Headline | Шифровальщики-вымогатели The Digest "Crypto-Ransomware" |
Title | Zeropadypt, Ouroboros |
Detected Hints/Tags/Attributes | 43/1/173 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | http://id-ransomware.blogspot.com/2019/04/zeropadypt-ransomware.html |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 2 | asmodeus.us |
|
Details | Domain | 3 | www.sfml-dev.org |
|
Details | Domain | 911 | any.run |
|
Details | Domain | 1174 | gmail.com |
|
Details | Domain | 396 | protonmail.com |
|
Details | Domain | 89 | protonmail.ch |
|
Details | Domain | 167 | tutanota.com |
|
Details | Domain | 144 | cock.li |
|
Details | Domain | 17 | foxmail.com |
|
Details | Domain | 162 | localbitcoins.com |
|
Details | Domain | 68 | www.coindesk.com |
|
Details | Domain | 83 | tuta.io |
|
Details | Domain | 24 | rape.lol |
|
Details | Domain | 1 | image.jpg.email |
|
Details | Domain | 10 | horsefucker.org |
|
Details | Domain | 158 | aol.com |
|
Details | Domain | 37 | xmpp.jp |
|
Details | Domain | 84 | airmail.cc |
|
Details | Domain | 1 | image001.png.email |
|
Details | Domain | 1 | ouroboros.pa |
|
Details | Domain | 15 | elude.in |
|
Details | Domain | 768 | www.youtube.com |
|
Details | Domain | 24 | ctemplar.com |
|
Details | Domain | 46 | firemail.cc |
|
Details | Domain | 68 | keemail.me |
|
Details | 1 | id=xxxxxxxxxx][email=asmo49@asmodeus.us |
||
Details | 1 | email=asmo49@asmodeus.us |
||
Details | 2 | asmo49@asmodeus.us |
||
Details | 1 | id=lz4ac3t***][mail=legion.developers72@gmail.com |
||
Details | 2 | legion.developers72@gmail.com |
||
Details | 1 | picture.jpg.[id=crzj7w6lig][mail=backfilehelp@protonmail.com |
||
Details | 1 | id=xxxxxxxxxx][mail=backfilehelp@protonmail.com |
||
Details | 2 | backfilehelp@protonmail.com |
||
Details | 2 | dcyptfils@protonmail.ch |
||
Details | 2 | letitbedecryptedzi@gmail.com |
||
Details | 1 | picture.jpg.[id=sbpoa46znc][mail=recoverunknown@protonmail.com |
||
Details | 2 | recoverunknown@protonmail.com |
||
Details | 1 | picture.jpg.[id=m5jfptuz0i][mail=helpcrypt1@tutanota.com |
||
Details | 2 | helpcrypt1@tutanota.com |
||
Details | 1 | picture.jpg.[id=pdlzmtcs4u][mail=letitbedecryptedzi@gmail.com |
||
Details | 1 | filename.[id=xxxxxxxxxx][mail=decryptersupport@protonmail.com |
||
Details | 2 | decryptersupport@protonmail.com |
||
Details | 1 | id=xxxxxxxxxx][mail=unlockme123@protonmail.com |
||
Details | 1 | unlockme123@protonmail.com.exe |
||
Details | 1 | id=6ucenb3ezh][mail=letitbedecryptedzi@gmail.com |
||
Details | 1 | id=xxxxxxxxxx][mail=mr.teslabrain@gmail.com |
||
Details | 2 | mr.teslabrain@gmail.com |
||
Details | 1 | id=xxxxxxxxxx][mail=dataadecrypt@cock.li |
||
Details | 2 | dataadecrypt@cock.li |
||
Details | 1 | id=xxxxxxxxxx][mail=decryp7@foxmail.com |
||
Details | 2 | decryp7@foxmail.com |
||
Details | 1 | id=xxxxxxxxxx][mail=decryptions@protonmail.com |
||
Details | 1 | restsharp.xml.[id=20jfkhklzu][mail=decryptions@protonmail.com |
||
Details | 2 | decryptions@protonmail.com |
||
Details | 1 | id=xxxxxxxxxx][mail=scorpionencryption@protonmail.com |
||
Details | 3 | scorpionencryption@protonmail.com |
||
Details | 1 | id=eo1qqcm2lm][mail=fileshelp@tutanota.com |
||
Details | 2 | fileshelp@tutanota.com |
||
Details | 1 | image.jpg.[id=au2wegh***][email=jacdecr@tuta.io |
||
Details | 2 | jacdecr@tuta.io |
||
Details | 1 | image.jpg.[id=flkr3nghuw][mail=steven77xx@protonmail.com |
||
Details | 3 | steven77xx@protonmail.com |
||
Details | 1 | image.jpg.[id=u2wegah***][email=rezcrypt@cock.li |
||
Details | 2 | rezcrypt@cock.li |
||
Details | 1 | suckbabe@rape.lol |
||
Details | 1 | image.jpg.[id=mdp6rrqefx][mail=mr.teslabrain@gmail.com |
||
Details | 1 | email=[jacdecr@tuta.io |
||
Details | 1 | image.jpg.email=[jacdecr@tuta.io |
||
Details | 1 | email=[mr.teslabrain@gmail.com |
||
Details | 1 | image.jpg.email=[mr.teslabrain@gmail.com |
||
Details | 1 | email=[rezcrypt@cock.li |
||
Details | 1 | image.jpg.email=[rezcrypt@cock.li |
||
Details | 1 | email=[legion.developers72@gmail.com |
||
Details | 1 | image.jpg.email=[legion.developers72@gmail.com |
||
Details | 1 | email=[decryptfiles@horsefucker.org |
||
Details | 1 | image.jpg.email=[decryptfiles@horsefucker.org |
||
Details | 2 | decryptfiles@horsefucker.org |
||
Details | 1 | email=[datarest0re@aol.com |
||
Details | 1 | image.jpg.email=[datarest0re@aol.com |
||
Details | 3 | datarest0re@aol.com |
||
Details | 2 | datarest0re@protonmail.com |
||
Details | 2 | datarest0re@xmpp.jp |
||
Details | 1 | email=[hiddenhelp@cock.li |
||
Details | 1 | image.jpg.email=[hiddenhelp@cock.li |
||
Details | 2 | hiddenhelp@cock.li |
||
Details | 2 | decodehelp@cock.li |
||
Details | 1 | email=[restoredata@airmail.cc |
||
Details | 2 | restoredata@airmail.cc |
||
Details | 1 | email=[fixallfiles@tuta.io |
||
Details | 1 | image.jpg.email=[fixallfiles@tuta.io |
||
Details | 2 | fixallfiles@tuta.io |
||
Details | 1 | email=[recoveryhelp2019@protonmail.com |
||
Details | 2 | recoveryhelp2019@protonmail.com |
||
Details | 1 | image.jpg.[id=xxxxxxxxxx][mail=leltitbedecrypteddzi@gmail.com |
||
Details | 2 | leltitbedecrypteddzi@gmail.com |
||
Details | 2 | blackroot54@protonmail.com |
||
Details | 2 | recovery94@cock.li |
||
Details | 1 | email=[mr.teslabrain@protonmail.com |
||
Details | 2 | mr.teslabrain@protonmail.com |
||
Details | 2 | teslabrain@cock.li |
||
Details | 1 | image001.png.email=[filedownload2020@protonmail.com |
||
Details | 2 | filedownload2020@protonmail.com |
||
Details | 2 | rx99@cock.li |
||
Details | 1 | email=[bitdefender2020@cock.li |
||
Details | 2 | bitdefender2020@cock.li |
||
Details | 1 | email=[honeylock@protonmail.com |
||
Details | 2 | honeylock@protonmail.com |
||
Details | 2 | advancedbackup@protonmail.com |
||
Details | 2 | recover85@protonmail.com |
||
Details | 2 | unlock0101@protonmail.com |
||
Details | 8 | rdpmanager@airmail.cc |
||
Details | 1 | email_[supportodveta@protonmail.com |
||
Details | 2 | supportodveta@protonmail.com |
||
Details | 2 | supportodveta@elude.in |
||
Details | 1 | email=[js3010@rape.lol |
||
Details | 1 | js3010@rape.lol |
||
Details | 1 | email=[softs98@protonmail.com |
||
Details | 2 | softs98@protonmail.com |
||
Details | 1 | email=[josefrendal797@gmail.com |
||
Details | 2 | josefrendal797@gmail.com |
||
Details | 1 | email=[tools1990m@gmail.com |
||
Details | 2 | tools1990m@gmail.com |
||
Details | 2 | toolsl990m@gmail.com |
||
Details | 1 | email=[vashmail@protonmail.com |
||
Details | 2 | vashmail@protonmail.com |
||
Details | 2 | vashmail@ctemplar.com |
||
Details | 2 | vashmail@firemail.cc |
||
Details | 1 | vashmail@keemail.me |
||
Details | 1 | email=[filedecryptor@protonmail.com |
||
Details | 2 | filedecryptor@protonmail.com |
||
Details | 1 | email=[darkencryptor@tutanota.com |
||
Details | 2 | darkencryptor@tutanota.com |
||
Details | 1 | email=[smartrecav@tutanota.com |
||
Details | 2 | smartrecav@tutanota.com |
||
Details | 2 | decodeodveta@protonmail.com |
||
Details | 2 | decrypt0077@gmail.com |
||
Details | 1 | email=[decfile431@tutanota.com |
||
Details | 2 | deccoder431@protonmail.com |
||
Details | 2 | decfile431@tutanota.com |
||
Details | 1 | email=[decryptfiles5@gmail.com |
||
Details | 2 | decryptfiles5@gmail.com |
||
Details | File | 3 | read-me-now.txt |
|
Details | File | 2 | activator_office.exe |
|
Details | File | 2 | ip-provider.php |
|
Details | File | 51 | picture.jpg |
|
Details | File | 1 | ouroboros_en.exe |
|
Details | File | 1 | letitbedecryptedzi.exe |
|
Details | File | 23 | com.exe |
|
Details | File | 1 | restsharp.xml |
|
Details | File | 1 | decryption_guidance.txt |
|
Details | File | 32 | image.jpg |
|
Details | File | 1 | howtodecrypt.txt |
|
Details | File | 1 | li_kronos.exe |
|
Details | File | 1 | uiapp.exe |
|
Details | File | 8 | out.exe |
|
Details | File | 1 | unlock-files.txt |
|
Details | File | 4 | image001.png |
|
Details | File | 1 | how_to_unlock-files.txt |
|
Details | File | 4 | ids.txt |
|
Details | File | 2 | pkey.txt |
|
Details | File | 2 | zx.exe |
|
Details | File | 1 | how_to_unlock_files.txt |
|
Details | File | 1 | unlock_files.txt |
|
Details | File | 1 | ours.exe |
|
Details | Pdb | 1 | ouroboros_en.pdb |
|
Details | Pdb | 1 | motherfucker.pdb |
|
Details | Pdb | 1 | d:\kronos+\motherfucker\release\motherfucker.pdb |
|
Details | Pdb | 1 | d:\ouroboros v7\ouroborosv7\release\ouroborosv7.pdb |
|
Details | Pdb | 1 | d:\ouroboros v8\ouroborosv7\release\ouroborosv7.pdb |
|
Details | Url | 52 | https://localbitcoins.com/buy_bitcoins |
|
Details | Url | 2 | https://www.coindesk.com/information/how-can-i-buy-bitcoins |
|
Details | Url | 1 | https://www.youtube.com/watch?v=_tz6ytab2pg |
|
Details | Url | 1 | https://www.youtube.com/watch?v=2q9c6chiqs4 |