IoCs/Ransomware-ProLock.csv at master · sophoslabs/IoCs
Common Information
Type Value
UUID dff562cb-c0e3-4c08-b51a-39e5b6474bdf
Fingerprint 3616fc3b7c76320b
Analysis status DONE
Considered CTI value 2
Text language
Published Jan. 1, 2022, midnight
Added to db Sept. 11, 2022, 12:35 p.m.
Last updated Nov. 17, 2024, 6:50 p.m.
Headline UNKNOWN
Title IoCs/Ransomware-ProLock.csv at master · sophoslabs/IoCs
Detected Hints/Tags/Attributes 21/2/24
Attributes
Details Type #Events CTI Value
Details File 1
ransomware-prolock.csv
Details File 3
c:\programdata\winmgr.bmp
Details File 1
c:\programdaa\winmgr.xml
Details File 4
c:\programdata\run.bat
Details File 3
c:\programdata\clean.bat
Details File 15
clean.bat
Details File 26
run.bat
Details File 4
winmgr.xml
Details File 5
winmgr.bmp
Details sha1 1
9cae5fcefc8bc9b748b4b16549e789e27ae816df
Details sha1 1
a037439ad7e79dbf4a20664cf10126c93429e350
Details sha1 1
0ce3614560e7c1ddbc3b8f56f3e45278de47d3bb
Details sha1 1
4f125d890a8f98c9c7069b0bb2b5625c7754fad6
Details sha1 1
e2a961c9a78d4c8bf118a0387dc15c564efc8fe9
Details sha1 1
81d5888bb8d43d88315c040be1f51db6bb5cf64c
Details sha256 1
18661f8c245d26be1ec4df48a9e186569a77237f424f322f00ef94652b9d5f35
Details sha256 1
b262b1b82e5db337d367ea1d4119cadb928963896f1aff940be763a00d45f305
Details sha256 1
2f0e4b178311a260601e054b0b405999715084227e49ff18a19e1a59f7b2f309
Details sha256 1
a6ded68af5a6e5cc8c1adee029347ec72da3b10a439d98f79f4b15801abd7af0
Details sha256 1
dfbd62a3d1b239601e17a5533e5cef53036647901f3fb72be76d92063e279178
Details IPv4 1
185.212.128.8
Details Url 1
http://185.212.128.8/b
Details Windows Registry Key 2
HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet
Details Windows Registry Key 164
HKLM\SOFTWARE\Microsoft\Windows