TF-MAL-elf.ragnarlocker
📛 Threat Title
Malware family: RagnarLocker
Description
ThreatFox malware family `elf.ragnarlocker`. Printable name: RagnarLocker.
Indicators of Compromise (1)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
domain
elf.ragnarlocker
VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ragnarlocker
IOC database
- Type
- domain
- Value
elf.ragnarlocker- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
- Description
- Extracted from Threat TF-MAL-elf.ragnarlocker
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ragnarlocker
References (1)
- ThreatFox: IOCs for this family ThreatFox Malwares
Remediations (10)
-
web:fieldeffect.com
Analysis Beyond generating revenue, Ragnar Locker may loan or rent out its malware toolkit to help obfuscate attribution, making it harder for security researchers to link specific attacks to the group. If multiple actors use the same tool, it creates plausible deniability, complicating efforts to track down the original developers.
-
web:github.com
RagnarLocker is a Ransomware normally associated with the APT Viking Spider whose InitialAccess is varied, but as usual, they perform direct attacks trying to exploit systems or after the abuse of legitimate applications or by implanting malware inside these, after these movements, the most common is to gain maximum access and control within the attacked company to encrypt as many computers as ...
-
web:www.aha.org
RagnarLocker ransomware actors work as part of a ransomware family1, frequently changing obfuscation techniques to avoid detection and prevention. 1 Ransomware family is a group of binaries associated to several ransomware variants or actor groups.
-
web:www.ic3.gov
Lastly, RagnarLocker encrypts all available files of interest. Instead of choosing which files to encrypt, RagnarLocker chooses which folders it will not encrypt. Taking this approach allows the computer to continue to operate "normally" while the malware encrypts files with known and unknown extensions containing data of value to the victim. For example, if the logical drive being ...
-
web:www.malwarebytes.com
All component/technology detections are passed to the remediation engine for complete removal from infected systems. This industry leading technology uses patented techniques in identifying all cohorts or associated files for a single threat and removes them all together to prevent malware from resuscitating itself.
-
web:www.oha.com
You are receiving this advisory to make you aware of some new intelligence on the Ragnar locker ransomware group. Recipients of this information are advised to act and take precautionary measures to protect your organization's information assets, systems, and networks.
-
web:www.pcrisk.com
What kind of malware is Ragnar Locker? Ragnar Locker is ransomware-type software designed not only to encrypt data but also to terminate installed programs (such as ConnectWise and Kaseya), which are commonly used by managed service providers and various Windows services.
-
web:www.salvagedata.com
Ragnar Locker is a family of ransomware that has been in action since at least December 2019. It is known for targeting large organizations and attempting to extort large amounts of cryptocurrency from its victims. Some key features of Ragnar Locker ransomware include:The Ragnar Locker group is known to employ a double extortion tactic, where the ransom payment is not only for recovering ...
-
web:www.securityweek.com
" RagnarLocker ransomware actors work as part of a ransomware family , frequently changing obfuscation techniques to avoid detection and prevention," the FBI says in its alert. The malware relies on VMProtect, UPX, and custom packing algorithms and is typically deployed on compromised systems within a custom virtual machine.
-
web:www.sentinelone.com
Ragnar Locker is a dangerous threat group that does not tolerate the use of "negotiation" or "recovery" companies during ransom negotiations. Furthermore, they often use different ransomware payloads from other malicious developers, keeping their malware up-to-date.
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.