Lorenz

Compare
Parsing: enabled

View crypto

Description

Tesorion describes Lorenz as a ransomware with design and implementation flaws, leading to impossible decryption with tools provided by the attackers. A free decryptor for 2021 versions was made available via the NoMoreRansom initiative. A new version of the malware was discovered in March 2022, for which again was provided a free decryptor, while the ransomware operators are not able to provide tools to decrypt affected files.

External Analysis9
External Analysis
https://www.zdnet.com/article/lorenz-ransomware-attack-victims-can-now-retrieve-their-files-for-free-with-this-decryption-tool
https://www.cybertalk.org/the-worst-outcomes-lorenz-ransomware-a-new-double-extortion-strategy
https://arcticwolf.com/resources/blog/lorenz-ransomware-chiseling-in/
https://therecord.media/free-decrypter-available-for-lorenz-ransomware/
https://twitter.com/AltShiftPrtScn/status/1423190900516302860?s=20
https://www.bleepingcomputer.com/news/security/meet-lorenz-a-new-ransomware-gang-targeting-the-enterprise/
https://www.cybereason.com/blog/cybereason-vs.-lorenz-ransomware
https://www.tesorion.nl/en/posts/lorenz-ransomware-analysis-and-a-free-decryptor/
https://www.tesorion.nl/en/posts/lorenz-ransomware-rebound-corruption-and-irrecoverable-files/
Ransom notes2
Urls2
Url
Status
Screen
Uptime 30d
Health
http://lorenzmlwpzgxq736jzseuterytjueszsvznuibanxomlpkyxk6ksoyd.onion/ Down Screen
0%
http://woe2suafeg6ehxivgvvn4nh6ectbdhdqgc4vzph27mmyn7rjf2c52jid.onion Down
0%
Chat servers2
Url
Status
Screen
Uptime 30d
Health
http://lorenzedzyzyjhzxvlcv347n5piltxamo755pzqpozh5l47kj7mxueid.onion/ Down
0%
http://lorenzezzwvtk3y24wfph4jpho27grrctqvf6yvld7256rnoz7yg2eid.onion/ Down
0%
Activity (interactive) 98
Activity charts
Posts98
Date Title Description Screen
Bayer Heritage Federal Credit Union
EOS
Koh Brothers
Cogdell Memorial Hospital
Truck Bodies & Equipment International
Broad River Retail/Ashley Store
AllCare Pharmacy
BF&S Civil Engineers
Dee Sign
Felling Trailers, Inc.
Tarolli, Sundheim, Covell & Tummino LLP
Joy Cone Co, Joy Baking group, BoDeans Baking, Altesa
NGS Super
Intrasect Technologies
Moore Engineering
Manning Building Supplies
Tarolli
Hopsteiner
AmerisourceBergen/Censora - MWI Animal Health
Chestertons Inc.
Thor Specialties, Inc.
Shelco
Albina Asphalt
Holler-Classic
Nissan of Las Cruces
Salud Family Health
Main & Main Capital Group
Miracapo pizza company
Wes-tec inc.
Turner Enterprises, Inc.
Ward Hadaway
Northern Contours Inc.
Laddawn Inc.
Engine Power
Northern Contours
Airtech
Tygavac
Wolfe Eye Clinic
Challenge-mfg
Turner Enterprises
Hensoldt
VadaTech
Wardhadaway
DeeZee
Musco
Tosoh
Brunk
Fuji
Bonneville
Wis-Pak
Biothane
Fandeli
Van Ausdall & Farrar, inc
Biothane usa
Gresco
Uppco
Wis-Pak, Inc
Bonneville Collections
Westwood
Fuji America Corporation
Mebulbs
Magtek
Brunk Industries Inc.
AmCham Shanghai
Tosoh Corporation
Tosoh Bioscience
Morrie's Auto Group
Musco Sports Lighting
Simply Placed
DeeZee
Advizrs
Keicorp(ICPM)
Biz Retek
Fuji America Corporation
VadaTech
Ward Hadaway
Hensoldt
Buchanan Hauling & Rigging
Turner Enterprises, Inc.
Kenall/Legrand
Component Assembly Systems
SCREEN Holdings
Sebastian
Miller-Valentine Group
MPS Credit Union
Buchanan Hauling & Rigging
Langs Building Supplies Pty Ltd
Challenge Manufacturing Company
Airtech Advanced Materials Group
DNS Toptech
Joy Cone
Wolfe Eye Clinic
Bases Conversion and Development Authority (BCDA)
Tygavac ltd.
The managementtrust
Multifeeder
Commport Communications
Windemuller
Note