Ragnarlocker

Compare
Parsing: enabled

View crypto

Description

External Analysis49
External Analysis
https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security
https://www.bleepingcomputer.com/news/security/ransomware-gang-threatens-to-leak-data-if-victim-contacts-fbi-police
https://twitter.com/malwrhunterteam/status/1475568201673105409
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/analysis-and-protections-for-ragnarlocker-ransomware.html
http://reversing.fun/posts/2021/04/15/unpacking_ragnarlocker_via_emulation.html
http://reversing.fun/reversing/2021/04/15/unpacking_ragnarlocker_via_emulation.html
https://analyst1.com/blog/ransom-mafia-analysis-of-the-worlds-first-ransomware-cartel
https://analyst1.com/file-assets/RANSOM-MAFIA-ANALYSIS-OF-THE-WORLD%E2%80%99S-FIRST-RANSOMWARE-CARTEL.pdf
https://blog.blazeinfosec.com/dissecting-ragnar-locker-the-case-of-edp/
https://blog.bushidotoken.net/2022/05/gamer-cheater-hacker-spy.html
https://blog.cyble.com/2022/01/20/deep-dive-into-ragnar-locker-ransomware-gang/
https://blog.reversing.xyz/docs/posts/unpacking_ragnarlocker_via_emulation/
https://blog.reversing.xyz/reversing/2021/04/15/unpacking_ragnarlocker_via_emulation.html
https://cyware.com/news/ragnar-locker-breached-52-organizations-and-counting-fbi-warns-0588d220/
https://docs.google.com/spreadsheets/d/1MI8Z2tBhmqQ5X8Wf_ozv3dVjz5sJOs-3
https://go.crowdstrike.com/rs/281-OBQ-266/images/Report2021GTR.pdf
https://ics-cert.kaspersky.com/media/KASPERSKY_H1_2020_ICS_REPORT_EN.pdf
https://id-ransomware.blogspot.com/2020/02/ragnarlocker-ransomware.html
https://intel471.com/blog/conti-ransomware-cooperation-maze-lockbit-ragnar-locker
https://ke-la.com/how-ransomware-gangs-find-new-monetization-schemes-and-evolve-in-marketing/
https://krebsonsecurity.com/2020/11/ransomware-group-turns-to-facebook-ads/
https://news.sophos.com/en-us/2020/05/21/ragnar-locker-ransomware-deploys-virtual-machine-to-dodge-security/
https://news.sophos.com/en-us/2021/02/03/mtr-casebook-uncovering-a-backdoor-implant-in-a-solarwinds-orion-server/
https://news.sophos.com/en-us/2022/03/17/the-ransomware-threat-intelligence-center/
https://public.intel471.com/blog/ransomware-as-a-service-2020-ryuk-maze-revil-egregor-doppelpaymer/
https://securelist.com/modern-ransomware-groups-ttps/106824/
https://securelist.com/targeted-ransomware-encrypting-data/99255/
https://seguranca-informatica.pt/ragnar-locker-malware-analysis/
https://symantec.broadcom.com/hubfs/The_Ransomware_Threat_September_2021.pdf
https://twitter.com/AltShiftPrtScn/status/1403707430765273095
https://www.accenture.com/us-en/blogs/cyber-defense/evolving-danger-ransomware-extortion
https://www.accenture.com/us-en/blogs/cyber-defense/moving-left-ransomware-boom
https://www.acronis.com/en-sg/articles/ragnar-locker/
https://www.bleepingcomputer.com/news/security/capcom-hit-by-ragnar-locker-ransomware-1tb-allegedly-stolen/
https://www.bleepingcomputer.com/news/security/fbi-ransomware-gang-breached-52-us-critical-infrastructure-orgs/
https://www.bleepingcomputer.com/news/security/japanese-game-dev-capcom-hit-by-cyberattack-business-impacted/
https://www.bleepingcomputer.com/news/security/ragnarlocker-ransomware-hits-edp-energy-giant-asks-for-10m/
https://www.capcom.co.jp/ir/english/news/pdf/e210413.pdf
https://www.crowdstrike.com/blog/double-trouble-ransomware-data-leak-extortion-part-1
https://www.crowdstrike.com/blog/double-trouble-ransomware-data-leak-extortion-part-1/
https://www.cyborgsecurity.com/cyborg_labs/hunting-ransomware-inhibiting-system-backup-or-recovery/
https://www.hornetsecurity.com/en/security-informationen-en/leakware-ransomware-hybrid-attacks/
https://www.ic3.gov/Media/News/2022/220307.pdf
https://www.mcafee.com/blogs/other-blogs/mcafee-labs/ragnarlocker-ransomware-threatens-to-release-confidential-information
https://www.microsoft.com/security/blog/2020/04/28/ransomware-groups-continue-to-target-healthcare-critical-services-heres-how-to-reduce-risk/
https://www.theregister.com/2022/03/09/fbi_says_ragnar_locker_ransomware/
https://www.trellix.com/en-us/about/newsroom/stories/threat-labs/analysis-and-protections-for-ragnarlocker-ransomware.html
https://www.waterisac.org/system/files/articles/FLASH-MU-000140-MW.pdf
https://www.zdnet.com/article/capcom-quietly-discloses-cyberattack-impacting-email-file-servers/
Ransom notes2
Urls2
Url
Status
Screen
Uptime 30d
Health
http://rgleak7op734elep.onion Down
http://rgleaktxuey67yrgspmhvtnrqtgogur35lwdrup4d3igtbm3pupc4lyd.onion/ Up Screen
67%
File servers7
Url
Status
Screen
Uptime 30d
Health
http://p6o7m73ujalhgkiv.onion Down
http://2dxxyil6kur3qpht2tkklupdgacrcbfun6qf5jmk3hafmt6n6ockbzid.onion Down
http://goh2zbohdiblk23scvtae7delci5cioy73la2lnrduxutxksl7xiscqd.onion Down
http://t2w5byhtkqkaw6m543i6ax3mamfdy7jkkqsduzzfwhfcep4shqqsd5id.onion Down
http://wxbpssv4hiwlcgt4cxam3cznu4feqgf5pqfibbku3x6dwvtcakdkyeid.onion Down
http://xxbsnxdqmthgpydddmuvg7yzy6pdfnlnlepxa5my4mjiqjsee6yidhyd.onion Down
http://7twfgaqyik3xfuu4.onion Down
Chat servers1
Url
Status
Screen
Uptime 30d
Health
http://ragnarmj3hlykxstyanwtgf33eyacccleg45ctygkuw7dkgysict6xyd.onion/ Down Screen
33%
Activity (interactive) 123
Activity charts
Posts123
Date Title Description Screen
Scotbeef Ltd. - Leaks Post screen
Eicon Controle Inteligentes Post screen
International Presence Ltd - Leaked Post screen
Learning Partnership West - Leaked Post screen
Groupe Fructa Partner - Leaked Post screen
Network Pacific Real Estate - Leak Post screen
Astre - Leaked Post screen
Stratesys Full data leak Post screen
Announcement: COMECA Group going to be Leaked Post screen
Announcement: Skatax Accounting company going to be leaked Post screen
Retail House - Full Leak Post screen
Announcement: Stratesys solutions going to be leaked Post screen
Announcement: Stratesys solutions going to b Post screen
Announcement: Groupe Fructa Partner will be leaked soon Post screen
CITIZEN company LEAKED Post screen
Announcement: Retail House going to be LEAKED Post screen
Updates: Israel "MYMC" Post screen
Israel Medical Center - leaked Post screen
DOIT - Canadian IT company allowed leak of its own clients. Post screen
Batesville didn't react on appeal and allows Full Leak Post screen
Announcement: Batesville Tool & Die, Inc will be leaked in 3 Days Post screen
Belize Electricity Limited - Leaked Post screen
Portugal Scotturb Data Leaked Post screen
Australian Universal Crane Leak Post screen
Autlan Metallorum, Mexican Miner Leak Post screen
CANTALK, Canadian translation services - Leak Post screen
Public Appeal to the CANTALK management Post screen
Temporary Leak Page #0013995NTa
New Leak in lawyers company AASP. Post screen
New Leak in lawyers company.
AASP claim there was no data leakage! Post screen
Hundred thousands of personal data, leak preview Post screen
Wrapex Industrial - Leaked Post screen
Serena Hotels - Leaked Post screen
ITONCLOUD - LEAKED Post screen
Essent company - Leaked Post screen
Leak Announcement - IT company ITonCLOUD Post screen
Belgium company Zwijndrecht - Leaked Post screen
DURAVIT A.G. - Announcement before publishing data
DIPF-INTERN - Leaked Post screen
Dollmar SpA - Leaked Post screen
Fashion company ZIGI NY - Leaked Post screen
DMCI Holding Leaked Post screen
TANG CAPITAL LEAKED Post screen
Avalon luxury transport company - Leaked Post screen
AudioQuest Data Leaked Post screen
Malayan Flour Mills Bhd. Data Leak Post screen
TAP Air Leak of more than 1.5 million of customers and many other. Post screen
DDoS instead of the Discuss - Nice try TAP Air Post screen
TAP AIR PORTUGAL - 115k personal data leak Post screen
TAP Air - First Facts Post screen
USA Insurance company - Smith brothers File tree and some proofs
Huge drama for Tap Air Portugal Post screen
DESFA - Pipeline company LEAK Post screen
Announcement. Action Lab File-tree
Greece pipeline company breached - DESFA Post screen
File-tree of Tang Capital Post screen
Puma Biotechnology - decided to allow Leaks Post screen
GENSCO Inc. - allows Leak Post screen
Epec.PL - Lied about the absence of Leak Post screen
New Leak: Northern Data Systems Post screen
New Leak: Prudential LTG. Post screen
Sierra Packaging Leaked Post screen
Jonathan Adler Leaks Post screen
Germany Corporation "VMT-GmbH" Leaked Post screen
Simonson-Lumber decided to be Leaked Post screen
Simonson-Lumber Inc. First batch of Data.
International Centre Leaked Post screen
Smith Transport Full Leak Post screen
GHI Hornos Industriales Fully Leaked Post screen
GHI Hornos Industriales first batch of Data (0,1%) Post screen
Airspan Networks got Leaked Post screen
IT-companies Subex & Sectrio Leaked Post screen
Company Group LDLC Post screen
Leak of IT company Saksoft Post screen
Full Data Leak Linical Post screen
Update: Linicals Data Post screen
Groupe LDLC is going to be Leaked Post screen
Team Computers Ltd. - Leak Post screen
LINICAL doesn't care about digital hygiene Post screen
Atlas Financial Holdings, Inc. - Leaked Post screen
FULL DATA LEAK of Primary Residential Mortgage, Inc. // Post screen
Primary Residential Mortgage inc. - Leaked Post screen
Who is the real Bad Guys here? Or what recovery experts prefer to keep silent. Post screen
Announcement: FTP Post screen
GATEWAY Property Management Post screen
Software company Xoriant Post screen
New Leak GatewayPM Post screen
NEW Links for ADATA Post screen
ADATA LEAKED Post screen
Webhelp's company - XtraSource Post screen
Ludwig Pfeiffer Leaked Post screen
Grupo SADA Leak Post screen
New Data Leak post from Chemical company Post screen
Kaye/Bassman International - New "Wall of Shamer" Post screen
Cornerstone-BB Group Leaked Post screen
Attention, Dassault Falcon Jet updated Post screen
Advertising Material: Forest Construction Leaked Post screen
LEAK Post Campari Group Post screen
Updates with files in EastCoastSeafood Inc. Post screen
New "WallofShamer" - East Coast Seafood Inc. Post screen
Shasun Chemicals & Drugs Ltd. LEAK Post screen
JMA Energy LEAK Post screen
New Files For Leak Campari Post Post screen
Ragnar_Team Announce of Potential "WallofShamer" Post screen
LEAK Post CAPCOM Post screen
LEAK post FINSA Post screen
Official appeal to DASSAULT FALCON JET Post screen
DASSAULT FALCON JET Post screen
Security breach of CAPCOM network Post screen
Security breach of Campari Group network Post screen
BIOLOGICAL E. Ltd. (BE) LEAK POST Post screen
Insignia Environmental company. Post screen
Astro Industries, Inc. Post screen
Bailey&Galyen Attorney at Law Post screen
New leaks from SOLTEK PACIFIC Post screen
GST Autoleather Company ! Post screen
ST Engineering Post screen
Leaks from company EDP Group Post screen
Leaks from company Omniga GmbH & Co. Post screen
Leakage from company Catania, Mahon & Rider, PLLC Post screen
Brunner Announce – Hello World ! Post screen
Leaks Company Birch Communications inc. Post screen
Note