s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

TF-MAL-elf.ragnarlocker

📛 Threat Title

Malware family: RagnarLocker

Category: RagnarLocker First seen: Last updated: Source: ThreatFox Malwares

Description

ThreatFox malware family `elf.ragnarlocker`. Printable name: RagnarLocker.

Indicators of Compromise (1)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

domain elf.ragnarlocker VT: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ragnarlocker

IOC database

Type
domain
Value
elf.ragnarlocker
First seen
Last seen
Attached to this threat
Appears in
1 threat
Description
Extracted from Threat TF-MAL-elf.ragnarlocker

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Client Error: Too Many Requests for url: https://www.virustotal.com/api/v3/domains/elf.ragnarlocker

References (1)

Remediations (10)

  • web:fieldeffect.com

    Analysis Beyond generating revenue, Ragnar Locker may loan or rent out its malware toolkit to help obfuscate attribution, making it harder for security researchers to link specific attacks to the group. If multiple actors use the same tool, it creates plausible deniability, complicating efforts to track down the original developers.

  • web:github.com

    RagnarLocker is a Ransomware normally associated with the APT Viking Spider whose InitialAccess is varied, but as usual, they perform direct attacks trying to exploit systems or after the abuse of legitimate applications or by implanting malware inside these, after these movements, the most common is to gain maximum access and control within the attacked company to encrypt as many computers as ...

  • web:www.aha.org

    RagnarLocker ransomware actors work as part of a ransomware family1, frequently changing obfuscation techniques to avoid detection and prevention. 1 Ransomware family is a group of binaries associated to several ransomware variants or actor groups.

  • web:www.ic3.gov

    Lastly, RagnarLocker encrypts all available files of interest. Instead of choosing which files to encrypt, RagnarLocker chooses which folders it will not encrypt. Taking this approach allows the computer to continue to operate "normally" while the malware encrypts files with known and unknown extensions containing data of value to the victim. For example, if the logical drive being ...

  • web:www.malwarebytes.com

    All component/technology detections are passed to the remediation engine for complete removal from infected systems. This industry leading technology uses patented techniques in identifying all cohorts or associated files for a single threat and removes them all together to prevent malware from resuscitating itself.

  • web:www.oha.com

    You are receiving this advisory to make you aware of some new intelligence on the Ragnar locker ransomware group. Recipients of this information are advised to act and take precautionary measures to protect your organization's information assets, systems, and networks.

  • web:www.pcrisk.com

    What kind of malware is Ragnar Locker? Ragnar Locker is ransomware-type software designed not only to encrypt data but also to terminate installed programs (such as ConnectWise and Kaseya), which are commonly used by managed service providers and various Windows services.

  • web:www.salvagedata.com

    Ragnar Locker is a family of ransomware that has been in action since at least December 2019. It is known for targeting large organizations and attempting to extort large amounts of cryptocurrency from its victims. Some key features of Ragnar Locker ransomware include:The Ragnar Locker group is known to employ a double extortion tactic, where the ransom payment is not only for recovering ...

  • web:www.securityweek.com

    " RagnarLocker ransomware actors work as part of a ransomware family , frequently changing obfuscation techniques to avoid detection and prevention," the FBI says in its alert. The malware relies on VMProtect, UPX, and custom packing algorithms and is typically deployed on compromised systems within a custom virtual machine.

  • web:www.sentinelone.com

    Ragnar Locker is a dangerous threat group that does not tolerate the use of "negotiation" or "recovery" companies during ransom negotiations. Furthermore, they often use different ransomware payloads from other malicious developers, keeping their malware up-to-date.

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.