SYMBOLCOMMON_NAMEaka. SYNONYMS
win.ragnarlocker (Back to overview)

RagnarLocker

VTCollection    

There is no description at this point.

References
2023-12-22PRODAFTPRODAFT
Smoke and Mirrors: Understanding The Workings of Wazawaka
Conti Monti Babuk Hive LockBit RagnarLocker Trigona
2023-10-20TechCrunchCarly Page
Authorities confirm RagnarLocker ransomware taken down during international sting
RagnarLocker RagnarLocker
2023-03-30United States District Court (Eastern District of New York)Fortra, HEALTH-ISAC, Microsoft
Cracked Cobalt Strike (1:23-cv-02447)
Black Basta BlackCat LockBit RagnarLocker LockBit Black Basta BlackCat Cobalt Strike Cuba Emotet LockBit Mount Locker PLAY QakBot RagnarLocker Royal Ransom Zloader
2022-06-23KasperskyDanila Nasonov, Natalya Shornikova, Nikita Nazarov, Vasily Davydov, Vladislav Burtsev
The hateful eight: Kaspersky’s guide to modern ransomware groups’ TTPs (Download Form)
BlackByte BlackCat Clop Conti Hive LockBit Mespinoza RagnarLocker
2022-05-05Intel 471Intel 471
Cybercrime loves company: Conti cooperated with other ransomware gangs
LockBit Maze RagnarLocker Ryuk
2022-05-01BushidoTokenBushidoToken
Gamer Cheater Hacker Spy
Egregor HelloKitty NetfilterRootkit RagnarLocker Winnti
2022-03-17SophosTilly Travers
The Ransomware Threat Intelligence Center
ATOMSILO Avaddon AvosLocker BlackKingdom Ransomware BlackMatter Conti Cring DarkSide dearcry Dharma Egregor Entropy Epsilon Red Gandcrab Karma LockBit LockFile Mailto Maze Nefilim RagnarLocker Ragnarok REvil RobinHood Ryuk SamSam Snatch WannaCryptor WastedLocker
2022-03-09The RegisterJessica Lyons Hardcastle
Ragnar ransomware gang hit 52 critical US orgs, says FBI
RagnarLocker
2022-03-09CywareCyware
Ragnar Locker Breached 52 Organizations and Counting, FBI Warns
RagnarLocker
2022-03-07FBIFBI
FBI Flash CU-000163-MW: RagnarLocker Ransomware Indicators of Compromise
RagnarLocker
2022-03-07Bleeping ComputerSergiu Gatlan
FBI: Ransomware gang breached 52 US critical infrastructure orgs
RagnarLocker
2022-02-28TrellixTaylor Mullins
Trellix Global Defenders: Analysis and Protections for RagnarLocker Ransomware
RagnarLocker RagnarLocker
2022-01-20CybleincCyble
Deep Dive Into Ragnar_locker Ransomware Gang
RagnarLocker
2021-10-11AccentureAccenture Cyber Threat Intelligence
Moving Left of the Ransomware Boom
REvil Cobalt Strike MimiKatz RagnarLocker REvil
2021-08-19Seguranca InformaticaPedro Tavares
Ragnar Locker – Malware analysis
RagnarLocker
2021-08-15SymantecThreat Hunter Team
The Ransomware Threat
Babuk BlackMatter DarkSide Avaddon Babuk BADHATCH BazarBackdoor BlackMatter Clop Cobalt Strike Conti DarkSide DoppelPaymer Egregor Emotet FiveHands FriedEx Hades IcedID LockBit Maze MegaCortex MimiKatz QakBot RagnarLocker REvil Ryuk TrickBot WastedLocker
2021-06-12Twitter (@AltShiftPrtScn)Peter Mackenzie
A thread on RagnarLocker ransomware group's TTP seen in an Incident Response
Cobalt Strike RagnarLocker
2021-05-10DarkTracerDarkTracer
Intelligence Report on Ransomware Gangs on the DarkWeb: List of victim organizations attacked by ransomware gangs released on the DarkWeb
RansomEXX Avaddon Babuk Clop Conti Cuba DarkSide DoppelPaymer Egregor Hades LockBit Mailto Maze MedusaLocker Mespinoza Mount Locker Nefilim Nemty Pay2Key PwndLocker RagnarLocker Ragnarok RansomEXX REvil Sekhmet SunCrypt ThunderX
2021-05-06Cyborg SecurityBrandon Denker
Ransomware: Hunting for Inhibiting System Backup or Recovery
Avaddon Conti DarkSide LockBit Mailto Maze Mespinoza Nemty PwndLocker RagnarLocker RansomEXX REvil Ryuk Snatch ThunderX
2021-04-13CAPCOMCAPCOM
4th Update Regarding Data Security Incident Due to Unauthorized Access:Investigation Results
RagnarLocker
2021-04-12ilbaroni
Unpacking RAGNARLOCKER via emulation
RagnarLocker
2021-04-07ANALYST1Jon DiMaggio
Ransom Mafia Analysis of the World's First Ransomware Cartel
Conti Egregor LockBit Maze RagnarLocker Ryuk SunCrypt TA2101 VIKING SPIDER
2021-04-07ANALYST1Jon DiMaggio
Ransom Mafia - Analysis of the World's First Ransomware Cartel
Conti Egregor LockBit Maze RagnarLocker SunCrypt VIKING SPIDER
2021-02-23CrowdStrikeCrowdStrike
2021 Global Threat Report
RansomEXX Amadey Anchor Avaddon BazarBackdoor Clop Cobalt Strike Conti Cutwail DanaBot DarkSide DoppelPaymer Dridex Egregor Emotet Hakbit IcedID JSOutProx KerrDown LockBit Mailto Maze MedusaLocker Mespinoza Mount Locker NedDnLoader Nemty Pay2Key PlugX Pushdo PwndLocker PyXie QakBot Quasar RAT RagnarLocker Ragnarok RansomEXX REvil Ryuk Sekhmet ShadowPad SmokeLoader Snake SUNBURST SunCrypt TEARDROP TrickBot WastedLocker Winnti Zloader Evilnum OUTLAW SPIDER RIDDLE SPIDER SOLAR SPIDER VIKING SPIDER
2021-02-03Sophos Managed Threat Response (MTR)Greg Iddon
MTR casebook: Uncovering a backdoor implant in a SolarWinds Orion server
RagnarLocker
2021-01-01AcronisAcronis Security
Analysis of Ragnar Locker Ransomware
RagnarLocker
2020-12-16AccenturePaul Mansfield
Tracking and combatting an evolving danger: Ransomware extortion
DarkSide Egregor Maze Nefilim RagnarLocker REvil Ryuk SunCrypt
2020-11-19FBIFBI
MU-000140-MW: Indicators of Compromise Associated with Ragnar Locker Ransomware
RagnarLocker
2020-11-16Intel 471Intel 471
Ransomware-as-a-service: The pandemic within a pandemic
Avaddon Clop Conti DoppelPaymer Egregor Hakbit Mailto Maze Mespinoza RagnarLocker REvil Ryuk SunCrypt ThunderX
2020-11-11Kaspersky LabsDmitry Bestuzhev, Fedor Sinitsyn
Targeted ransomware: it’s not just about encrypting your data! Part 1 - “Old and New Friends”
Egregor Maze RagnarLocker
2020-11-10KrebsOnSecurityBrian Krebs
Ransomware Group Turns to Facebook Ads
RagnarLocker
2020-11-05Bleeping ComputerLawrence Abrams
Capcom hit by Ragnar Locker ransomware, 1TB allegedly stolen
RagnarLocker
2020-11-05ZDNetCharlie Osborne
Capcom quietly discloses cyberattack impacting email, file servers
RagnarLocker
2020-11-05Bleeping ComputerLawrence Abrams
Japanese game dev Capcom hit by cyberattack, business impacted
RagnarLocker
2020-10-23HornetsecurityHornetsecurity Security Lab
Leakware-Ransomware-Hybrid Attacks
Avaddon Clop Conti DarkSide DoppelPaymer Mailto Maze Mespinoza Nefilim RagnarLocker REvil Sekhmet SunCrypt
2020-09-25CrowdStrikeThe Crowdstrike Intel Team
Double Trouble: Ransomware with Data Leak Extortion, Part 1
DoppelPaymer FriedEx LockBit Maze MedusaLocker RagnarLocker REvil RobinHood SamSam WastedLocker MIMIC SPIDER PIZZO SPIDER TA2101 VIKING SPIDER
2020-09-24CrowdStrikeCrowdStrike Intelligence Team
Double Trouble: Ransomware with Data Leak Extortion, Part 1
DoppelPaymer Gandcrab LockBit Maze MedusaLocker RagnarLocker SamSam OUTLAW SPIDER OVERLORD SPIDER
2020-09-24Kaspersky LabsKaspersky Lab ICS CERT
Threat landscape for industrial automation systems - H1 2020
Poet RAT Mailto Milum RagnarLocker REvil Ryuk Snake
2020-08-25KELAVictoria Kivilevich
How Ransomware Gangs Find New Monetization Schemes and Evolve in Marketing
Avaddon Clop DarkSide DoppelPaymer Mailto Maze MedusaLocker Mespinoza Nefilim RagnarLocker REvil Sekhmet
2020-07-30WILDIRE LABSWILDFIRE LABS
Dissecting Ragnar Locker: The Case Of EDP
RagnarLocker
2020-06-09McAfeeAlexandre Mundo
RagnarLocker Ransomware Threatens to Release Confidential Information
RagnarLocker
2020-05-21SophosSophosLabs Uncut
Ragnar Locker ransomware deploys virtual machine to dodge security
RagnarLocker
2020-04-28MicrosoftMicrosoft Threat Protection Intelligence Team
Ransomware groups continue to target healthcare, critical services; here’s how to reduce risk
LockBit Mailto Maze MedusaLocker Paradise RagnarLocker REvil RobinHood
2020-04-14Bleeping ComputerSergiu Gatlan
RagnarLocker ransomware hits EDP energy giant, asks for €10M
RagnarLocker
2020-02-04ID RansomwareAndrew Ivanov
RagnarLocker Ransomware
RagnarLocker
Yara Rules
[TLP:WHITE] win_ragnarlocker_auto (20260504 | Detects win.ragnarlocker.)
rule win_ragnarlocker_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-05-04"
        version = "1"
        description = "Detects win.ragnarlocker."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.ragnarlocker"
        malpedia_rule_date = "20260422"
        malpedia_hash = "a182e35da64e6d71cb55f125c4d4225196523f14"
        malpedia_version = "20260504"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 8b7d90 13d6 014de8 8bf7 8bcf 13d3 33db }
            // n = 7, score = 300
            //   8b7d90               | mov                 edi, dword ptr [ebp - 0x70]
            //   13d6                 | adc                 edx, esi
            //   014de8               | add                 dword ptr [ebp - 0x18], ecx
            //   8bf7                 | mov                 esi, edi
            //   8bcf                 | mov                 ecx, edi
            //   13d3                 | adc                 edx, ebx
            //   33db                 | xor                 ebx, ebx

        $sequence_1 = { b82c000000 668945f4 8d45f4 50 56 e8???????? 83c408 }
            // n = 7, score = 300
            //   b82c000000           | mov                 eax, 0x2c
            //   668945f4             | mov                 word ptr [ebp - 0xc], ax
            //   8d45f4               | lea                 eax, [ebp - 0xc]
            //   50                   | push                eax
            //   56                   | push                esi
            //   e8????????           |                     
            //   83c408               | add                 esp, 8

        $sequence_2 = { 3175fc 8b4db4 8bf1 3375f8 234df8 8b55f0 }
            // n = 6, score = 300
            //   3175fc               | xor                 dword ptr [ebp - 4], esi
            //   8b4db4               | mov                 ecx, dword ptr [ebp - 0x4c]
            //   8bf1                 | mov                 esi, ecx
            //   3375f8               | xor                 esi, dword ptr [ebp - 8]
            //   234df8               | and                 ecx, dword ptr [ebp - 8]
            //   8b55f0               | mov                 edx, dword ptr [ebp - 0x10]

        $sequence_3 = { c1ea08 0bd9 8b8d50ffffff c1e618 0bf2 8b956cffffff }
            // n = 6, score = 300
            //   c1ea08               | shr                 edx, 8
            //   0bd9                 | or                  ebx, ecx
            //   8b8d50ffffff         | mov                 ecx, dword ptr [ebp - 0xb0]
            //   c1e618               | shl                 esi, 0x18
            //   0bf2                 | or                  esi, edx
            //   8b956cffffff         | mov                 edx, dword ptr [ebp - 0x94]

        $sequence_4 = { 8d8560f9ffff 50 ffd6 6a01 8d8560f9ffff 57 50 }
            // n = 7, score = 300
            //   8d8560f9ffff         | lea                 eax, [ebp - 0x6a0]
            //   50                   | push                eax
            //   ffd6                 | call                esi
            //   6a01                 | push                1
            //   8d8560f9ffff         | lea                 eax, [ebp - 0x6a0]
            //   57                   | push                edi
            //   50                   | push                eax

        $sequence_5 = { 3375f4 2375b8 8b4dd4 234df4 8b55c0 }
            // n = 5, score = 300
            //   3375f4               | xor                 esi, dword ptr [ebp - 0xc]
            //   2375b8               | and                 esi, dword ptr [ebp - 0x48]
            //   8b4dd4               | mov                 ecx, dword ptr [ebp - 0x2c]
            //   234df4               | and                 ecx, dword ptr [ebp - 0xc]
            //   8b55c0               | mov                 edx, dword ptr [ebp - 0x40]

        $sequence_6 = { 13fa 039d44ffffff 13bd38ffffff 039d18ffffff 13bd14ffffff 81c32f3b4dec 81d7cffbc0b5 }
            // n = 7, score = 300
            //   13fa                 | adc                 edi, edx
            //   039d44ffffff         | add                 ebx, dword ptr [ebp - 0xbc]
            //   13bd38ffffff         | adc                 edi, dword ptr [ebp - 0xc8]
            //   039d18ffffff         | add                 ebx, dword ptr [ebp - 0xe8]
            //   13bd14ffffff         | adc                 edi, dword ptr [ebp - 0xec]
            //   81c32f3b4dec         | add                 ebx, 0xec4d3b2f
            //   81d7cffbc0b5         | adc                 edi, 0xb5c0fbcf

        $sequence_7 = { 660f1f840000000000 8b7508 8a840d20ffffff ff4508 3206 8b75cc 8807 }
            // n = 7, score = 300
            //   660f1f840000000000     | nop    word ptr [eax + eax]
            //   8b7508               | mov                 esi, dword ptr [ebp + 8]
            //   8a840d20ffffff       | mov                 al, byte ptr [ebp + ecx - 0xe0]
            //   ff4508               | inc                 dword ptr [ebp + 8]
            //   3206                 | xor                 al, byte ptr [esi]
            //   8b75cc               | mov                 esi, dword ptr [ebp - 0x34]
            //   8807                 | mov                 byte ptr [edi], al

        $sequence_8 = { 8b7d08 8bd9 85ff 0f84a1010000 56 8b750c }
            // n = 6, score = 300
            //   8b7d08               | mov                 edi, dword ptr [ebp + 8]
            //   8bd9                 | mov                 ebx, ecx
            //   85ff                 | test                edi, edi
            //   0f84a1010000         | je                  0x1a7
            //   56                   | push                esi
            //   8b750c               | mov                 esi, dword ptr [ebp + 0xc]

        $sequence_9 = { 50 ff32 8b45fc 6a00 6a01 6a00 ff7004 }
            // n = 7, score = 300
            //   50                   | push                eax
            //   ff32                 | push                dword ptr [edx]
            //   8b45fc               | mov                 eax, dword ptr [ebp - 4]
            //   6a00                 | push                0
            //   6a01                 | push                1
            //   6a00                 | push                0
            //   ff7004               | push                dword ptr [eax + 4]

    condition:
        7 of them and filesize < 147456
}
Download all Yara Rules