Sage 2.0 analysis
ID: 24bd74c1-ed7a-554c-9e9d-0d4e70db4451
STIX ID: report--24bd74c1-ed7a-554c-9e9d-0d4e70db4451
Feed Name: CERT Polska
Threat Score
*Sage 2.0 is a CryLocker-derived ransomware distributed via malspam (ZIP attachments containing macro-enabled Word documents) that performs locale and location fingerprinting, requires UAC approval, persists in %APPDATA% and re-encrypts files after reboot; it uses Curve25519 ECDH with ChaCha for per-file encryption, appends encrypted key material to files, provides a Tor-based ransom panel, and the report includes YARA rules and multiple SHA-256 sample hashes.*
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
