- First seen: December 2019
- Aliases:
- Samples:
- 32beefe2c5e28e87357813c0ef91f47b631a3dff4a6235256aa123fc77564346 | windows | ransom | pe
Property | Value |
---|---|
Size | 487392 bytes |
CRC32 | 0x22f640ec |
MD5 | f503991495275a4d5a88b691498cbf09 |
SHA1 | 4b41a1508f0f519396b7c14df161954f1c819e86 |
SHA256 | 32beefe2c5e28e87357813c0ef91f47b631a3dff4a6235256aa123fc77564346 |
SHA512 | a00b7684e0174dae85089004be2557e2407b146468c33a014d25ba48ed93d212163bc247fbad781eb169cad4aa9e4924d42613f74725f0123d584fcebb4f75f4 |
Ssdeep | 6144:0qejsgRNGKhy9zzMOss2XWrccaaXCunmifiTbRF7WKHBQAk6Fjt0laAOzrJroCFQ:0m0ymOjZRaMhuF7LhQF6Mla7bu |
Magic | PE32 executable (GUI) Intel 80386, for MS Windows |
Packer | PE: compiler: Microsoft Visual C/C++(2017 v.15.9)[-] PE: linker: Microsoft Linker(14.16, Visual Studio 2017 15.9*)[EXE32] |
TrID | 32.2% (.EXE) Win64 Executable (generic) (10523/12/4) 20.1% (.DLL) Win32 Dynamic Link Library (generic) (6578/25/2) 15.4% (.EXE) Win16 NE executable (generic) (5038/12/1) 13.7% (.EXE) Win32 Executable (generic) (4505/5/1) 6.2% (.EXE) OS/2 Executable (generic) (2029/13) |
+ Avast: clean
- Avira: TR/Redcap.wnzao
- Bitdefender: Generic.Ransom.Cuba.11D2667D
+ Clamav: clean
+ Comodo: clean
- Drweb: Trojan.Encoder.31426
- Eset: Win32/Filecoder.OAE
- Fsecure: Trojan.TR/Redcap.wnzao
- Kaspersky: HEUR:Trojan-Ransom.Win32.Generic
+ Mcafee: clean
+ Sophos: clean
+ Symantec: clean
+ Trendmicro: clean
- Windefender: Ransom:Win32/Zudochka.B!MTB
- https://www.trendmicro.com/en_us/research/22/f/cuba-ransomware-group-s-new-variant-found-using-optimized-infect.html
- https://www.cisa.gov/sites/default/files/publications/aa22-335a-stopransomware-cuba-ransomware.pdf
- https://www.avertium.com/resources/threat-reports/an-in-depth-look-at-cuba-ransomware?hs_amp=true
- https://www.elastic.co/security-labs/cuba-ransomware-campaign-analysis
- https://www.elastic.co/security-labs/cuba-ransomware-malware-analysis
- https://unit42.paloaltonetworks.com/cuba-ransomware-tropical-scorpius/
- https://lab52.io/blog/cuba-ransomware-analysis/