logo

Maktub ransomware: possibly rebranded as Iron

ID: 7956497e-a464-59e1-9fa7-67bd94532d7e

STIX ID: report--7956497e-a464-59e1-9fa7-67bd94532d7e

Feed Name: Blaze's Security Blog

Threat Score
74/100

Date Published: 2018-04-10

Date Updated: 2026-04-19

Author: Bart

...
...

This report analyzes the Iron ransomware, likely a rebrand borrowing design and features from Maktub, DMA Locker, and Satan, that encrypts 374 file types, appends .encry, deletes originals (without removing shadow copies), and communicates with C2 at y5mogzal2w25p6bn.ml to register a GUID and obtain a unique Bitcoin address. It documents the ransom UI and notes, contact emails ([email protected], [email protected]), a hardcoded RSA public key, registry keys (HKCU\Software\CryptoA), mutex use, and an exclusion list mirroring Satan; IOCs include the C2 URLs, BTC address 1cimKyzS64PRNEiG89iFU3qzckVuEQuUj, and hashes (e.g., SHA256 19ee6d4a89d7f95145660ca68bd133edf985cc5b5c559e7062be824c0bb9e770), with decryption not possible without the private key though shadow copy recovery may help.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.