logo

Dissecting Ransomless AntiWar Malware: No Ransom Demand

ID: e3a0e40e-472a-5076-a345-c9d307e488d8

STIX ID: report--e3a0e40e-472a-5076-a345-c9d307e488d8

Feed Name: Cyble Blog

Threat Score
65/100

Date Published: 2025-05-20

Date Updated: 2026-07-16

...
...

This report analyzes an x64 Windows ransomware sample (SHA-256 9f3c1668ee44bfcd1afd599215f5bd73c76609776b78cb04bb6ef1121cc80d37) that encrypts files (appending a ".putinwillburninhell" extension), kills backup and database services, empties the Recycle Bin, excludes system folders and certain extensions, and drops an anti-war HTML message instead of demanding ransom; the report includes technical behavior, MITRE ATT&CK mappings, IoCs, and remediation recommendations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.