General
-
Target
https://github.com/Da2dalus/The-MALWARE-Repo
-
Sample
250508-pez4tsek6x
Static task
static1
URLScan task
urlscan1
Behavioral task
behavioral1
Sample
https://github.com/Da2dalus/The-MALWARE-Repo
Resource
win10ltsc2021-20250425-en
16 signatures
900 seconds
Malware Config
Extracted
Path
C:\Users\README_HOW_TO_UNLOCK.TXT
Ransom Note
YOUR FILE HAS BEEN LOCKED
In order to unlock your files, follow the instructions bellow:
1. Download and install Tor Browser
2. After a successful installation, run Tor Browser and wait for its initialization.
3. Type in the address bar: http://zvnvp2rhe3ljwf2m.onion
4. Follow the instructions on the site.
URLs
http://zvnvp2rhe3ljwf2m.onion
Targets
-
-
Target
https://github.com/Da2dalus/The-MALWARE-Repo
-
Deletes shadow copies
Ransomware often targets backup files to inhibit system recovery.
-
Downloads MZ/PE file
-
Legitimate hosting services abused for malware hosting/C2
-