s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-ps1.wannaren_loader

📛 Threat Title

Malware family: WannaRen Downloader

Category: WannaRen Downloader First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `ps1.wannaren_loader`. Printable name: WannaRen Downloader.

Indicators of Compromise (0)

No indicators of compromise on this threat.

References (1)

Remediations (10)

  • web:malpedia.caad.fkie.fraunhofer.de

    Details for the WannaRen Downloader malware family including references, samples and yara signatures.

  • web:threatfox.abuse.ch

    Indicators of Compromise (IOCs) on ThreatFox are associated with a certain malware fas. A malware sample can be associated with only one malware family . The page below gives you an overview on indicators of compromise associated with win. wannaren .

  • web:threats.kaspersky.com

    Class: Trojan- Downloader Programs classified as Trojan- Downloader download and install new versions of malicious programs, including Trojans and AdWare, on victim computers. Once downloaded from the Internet, the programs are launched or included on a list of programs which will run automatically when the operating system boots up.

  • web:www.broadcom.com

    WannaRen is an older ransomware variant discovered back in 2020. It has been reported that WannaRen has now made a comeback under a re-branded name of Life ransomware and that it targets users in India. The malware is spread in a form of a MSI package binary and it abuses legitimate system components for DLL sideloading.

  • web:www.cisa.gov

    It highlights technical approaches to uncovering malicious activity and includes mitigation steps according to best practices. The purpose of this report is to enhance incident response among partners and network administrators along with serving as a playbook for incident investigation.

  • web:www.glesec.com

    WannaRen ransomware appeared on the threat landscape in 2020 and reemerged in 2022 as Life ransomware. The new variant switched from using a PowerShell downloader to using a batch file to download and execute WINWORD.exe.

  • web:www.microsoft.com

    Understand how this virus or malware spreads and how its payloads affects your computer. Protect against this threat, identify symptoms, and clean up or remove infections.

  • web:www.ncsc.gov.uk

    This guidance helps private and public sector organisations deal with the effects of malware (which includes ransomware). It provides actions to help organisations prevent a malware infection, and also steps to take if you're already infected. Following this guidance will reduce: the likelihood of becoming infected the spread of malware throughout your organisation the impact of the infection

  • web:www.pcrisk.com

    What is WannaRen ? Discovered by Petrovic, WannaRen is a malicious ransomware-type program. This malware is designed to encrypt data and demand payment for decryption. During the encryption process, all affected files are appended with the ". WannaRen " extension. For example, a file originally named something like " 1.jpg " would appear as " 1.jpg. WannaRen " following encryption. After this ...

  • web:www.trendmicro.com

    This Ransomware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.It requires being executed with a specific argument/parameter, an additional component, or in a specific environment in order to proceed with its intended routine.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.