Dissecting Ransomless AntiWar Malware: No Ransom Demand
ID: e3a0e40e-472a-5076-a345-c9d307e488d8
STIX ID: report--e3a0e40e-472a-5076-a345-c9d307e488d8
Feed Name: Cyble Blog
Threat Score
This report analyzes an x64 Windows ransomware sample (SHA-256 9f3c1668ee44bfcd1afd599215f5bd73c76609776b78cb04bb6ef1121cc80d37) that encrypts files (appending a ".putinwillburninhell" extension), kills backup and database services, empties the Recycle Bin, excludes system folders and certain extensions, and drops an anti-war HTML message instead of demanding ransom; the report includes technical behavior, MITRE ATT&CK mappings, IoCs, and remediation recommendations.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
