SYMBOLCOMMON_NAMEaka. SYNONYMS
win.thunderx (Back to overview)

ThunderX

aka: Ranzy Locker
VTCollection    

Ransomware.

References
2022-01-19 ⋅ Mandiant ⋅ Adrian Sanchez Hernandez, Ervin James Ocampo, Paul Tarter
One Source to Rule Them All: Chasing AVADDON Ransomware
BlackMatter Avaddon BlackMatter MedusaLocker SystemBC ThunderX
2021-10-28 ⋅ PICUS Security ⋅ Süleyman Özarslan
A Detailed Walkthrough of Ranzy Locker Ransomware TTPs
ThunderX
2021-10-25 ⋅ FBI ⋅ FBI
CU-000153-MW: Indicators of Compromise Associated with Ranzy Locker Ransomware
ThunderX
2021-05-10 ⋅ DarkTracer ⋅ DarkTracer
Intelligence Report on Ransomware Gangs on the DarkWeb: List of victim organizations attacked by ransomware gangs released on the DarkWeb
RansomEXX Avaddon Babuk Clop Conti Cuba DarkSide DoppelPaymer Egregor Hades LockBit Mailto Maze MedusaLocker Mespinoza Mount Locker Nefilim Nemty Pay2Key PwndLocker RagnarLocker Ragnarok RansomEXX REvil Sekhmet SunCrypt ThunderX
2021-05-06 ⋅ Cyborg Security ⋅ Brandon Denker
Ransomware: Hunting for Inhibiting System Backup or Recovery
Avaddon Conti DarkSide LockBit Mailto Maze Mespinoza Nemty PwndLocker RagnarLocker RansomEXX REvil Ryuk Snatch ThunderX
2020-11-18 ⋅ SentinelOne ⋅ Jim Walter
Ranzy Ransomware | Better Encryption Among New Features of ThunderX Derivative
ThunderX
2020-11-16 ⋅ Intel 471 ⋅ Intel 471
Ransomware-as-a-service: The pandemic within a pandemic
Avaddon Clop Conti DoppelPaymer Egregor Hakbit Mailto Maze Mespinoza RagnarLocker REvil Ryuk SunCrypt ThunderX
2020-10-16 ⋅ Bleeping Computer ⋅ Lawrence Abrams
ThunderX Ransomware rebrands as Ranzy Locker, adds data leak site
ThunderX
2020-08-18 ⋅ ID Ransomware ⋅ Andrew Ivanov
ThunderX Ransomware
ThunderX
Yara Rules
[TLP:WHITE] win_thunderx_auto (20260917 | Detects win.thunderx.)
rule win_thunderx_auto {

    meta:
        author = "Felix Bilstein - yara-signator at cocacoding dot com"
        date = "2026-09-17"
        version = "1"
        description = "Detects win.thunderx."
        info = "autogenerated rule brought to you by yara-signator"
        tool = "yara-signator v0.6.0"
        signator_config = "callsandjumps;datarefs;binvalue"
        malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thunderx"
        malpedia_rule_date = "20260916"
        malpedia_hash = "53a643781c18e08f4a50949af60172d837a0b6f6"
        malpedia_version = "20260917"
        malpedia_license = "CC BY-SA 4.0"
        malpedia_sharing = "TLP:WHITE"

    /* DISCLAIMER
     * The strings used in this rule have been automatically selected from the
     * disassembly of memory dumps and unpacked files, using YARA-Signator.
     * The code and documentation is published here:
     * https://github.com/fxb-cocacoding/yara-signator
     * As Malpedia is used as data source, please note that for a given
     * number of families, only single samples are documented.
     * This likely impacts the degree of generalization these rules will offer.
     * Take the described generation method also into consideration when you
     * apply the rules in your use cases and assign them confidence levels.
     */


    strings:
        $sequence_0 = { 0f84ba000000 68???????? 8d4da8 e8???????? 6a0b 58 c645fc01 }
            // n = 7, score = 200
            //   0f84ba000000         | je                  0xc0
            //   68????????           |                     
            //   8d4da8               | lea                 ecx, [ebp - 0x58]
            //   e8????????           |                     
            //   6a0b                 | push                0xb
            //   58                   | pop                 eax
            //   c645fc01             | mov                 byte ptr [ebp - 4], 1

        $sequence_1 = { 8945fc e8???????? 8bf0 8d4e01 51 e8???????? 897314 }
            // n = 7, score = 200
            //   8945fc               | mov                 dword ptr [ebp - 4], eax
            //   e8????????           |                     
            //   8bf0                 | mov                 esi, eax
            //   8d4e01               | lea                 ecx, [esi + 1]
            //   51                   | push                ecx
            //   e8????????           |                     
            //   897314               | mov                 dword ptr [ebx + 0x14], esi

        $sequence_2 = { c7459c02000000 eb15 51 56 8bcf e8???????? }
            // n = 6, score = 200
            //   c7459c02000000       | mov                 dword ptr [ebp - 0x64], 2
            //   eb15                 | jmp                 0x17
            //   51                   | push                ecx
            //   56                   | push                esi
            //   8bcf                 | mov                 ecx, edi
            //   e8????????           |                     

        $sequence_3 = { 50 8d45e4 50 ff15???????? 8d4dcc e8???????? 8d45cc }
            // n = 7, score = 200
            //   50                   | push                eax
            //   8d45e4               | lea                 eax, [ebp - 0x1c]
            //   50                   | push                eax
            //   ff15????????         |                     
            //   8d4dcc               | lea                 ecx, [ebp - 0x34]
            //   e8????????           |                     
            //   8d45cc               | lea                 eax, [ebp - 0x34]

        $sequence_4 = { 51 51 ff7610 50 6a08 51 }
            // n = 6, score = 200
            //   51                   | push                ecx
            //   51                   | push                ecx
            //   ff7610               | push                dword ptr [esi + 0x10]
            //   50                   | push                eax
            //   6a08                 | push                8
            //   51                   | push                ecx

        $sequence_5 = { e8???????? ba???????? 8d8d58feffff e8???????? 8d8d30ffffff c645fc0c 51 }
            // n = 7, score = 200
            //   e8????????           |                     
            //   ba????????           |                     
            //   8d8d58feffff         | lea                 ecx, [ebp - 0x1a8]
            //   e8????????           |                     
            //   8d8d30ffffff         | lea                 ecx, [ebp - 0xd0]
            //   c645fc0c             | mov                 byte ptr [ebp - 4], 0xc
            //   51                   | push                ecx

        $sequence_6 = { 50 e8???????? 834dfcff 8d4dd4 e8???????? a1???????? 8d48e4 }
            // n = 7, score = 200
            //   50                   | push                eax
            //   e8????????           |                     
            //   834dfcff             | or                  dword ptr [ebp - 4], 0xffffffff
            //   8d4dd4               | lea                 ecx, [ebp - 0x2c]
            //   e8????????           |                     
            //   a1????????           |                     
            //   8d48e4               | lea                 ecx, [eax - 0x1c]

        $sequence_7 = { ba???????? e8???????? 8bf0 33db 395e10 7434 }
            // n = 6, score = 200
            //   ba????????           |                     
            //   e8????????           |                     
            //   8bf0                 | mov                 esi, eax
            //   33db                 | xor                 ebx, ebx
            //   395e10               | cmp                 dword ptr [esi + 0x10], ebx
            //   7434                 | je                  0x36

        $sequence_8 = { 8a040e 8801 3bfa 72f1 8b4584 8bbd78ffffff 8d75bc }
            // n = 7, score = 200
            //   8a040e               | mov                 al, byte ptr [esi + ecx]
            //   8801                 | mov                 byte ptr [ecx], al
            //   3bfa                 | cmp                 edi, edx
            //   72f1                 | jb                  0xfffffff3
            //   8b4584               | mov                 eax, dword ptr [ebp - 0x7c]
            //   8bbd78ffffff         | mov                 edi, dword ptr [ebp - 0x88]
            //   8d75bc               | lea                 esi, [ebp - 0x44]

        $sequence_9 = { 895dc8 8975bc 8975c0 8975c4 8975fc 8d45d4 52 }
            // n = 7, score = 200
            //   895dc8               | mov                 dword ptr [ebp - 0x38], ebx
            //   8975bc               | mov                 dword ptr [ebp - 0x44], esi
            //   8975c0               | mov                 dword ptr [ebp - 0x40], esi
            //   8975c4               | mov                 dword ptr [ebp - 0x3c], esi
            //   8975fc               | mov                 dword ptr [ebp - 4], esi
            //   8d45d4               | lea                 eax, [ebp - 0x2c]
            //   52                   | push                edx

    condition:
        7 of them and filesize < 319488
}
[TLP:WHITE] win_thunderx_w0   (20200915 | Rule to dettect tthe ThunderX ransomware family)
import "pe"

rule win_thunderx_w0 {
   meta:
      description = "Rule to dettect tthe ThunderX ransomware family"
      author = "Christiaan Beek @ McAfee ATR team"
      date = "2020-09-14"
      rule_version = "v1"
      malware_type = "ransomware"
      malware_family = "Ransomware:W32/ThunderX"
      actor_type = "Cybercrime"
      actor_group = "Unknown"
      hash1 = "7bab5dedef124803668580a59b6bf3c53cc31150d19591567397bbc131b9ccb6"
      hash2 = "0fbfdb8340108fafaca4c5ff4d3c9f9a2296efeb9ae89fcd9210e3d4c7239666"
      hash3 = "7527459500109b3bb48665236c5c5cb2ec71ba789867ad2b6417b38b9a46615e"
      source = "https://github.com/advanced-threat-research/Yara-Rules/blob/master/ransomware/Ransom_ThunderX.yar"
      malpedia_reference = "https://malpedia.caad.fkie.fraunhofer.de/details/win.thunderx"
      malpedia_rule_date = "20200915"
      malpedia_hash = ""
      malpedia_version = "20200915"
      malpedia_license = "CC BY-SA 4.0"
      malpedia_sharing = "TLP:WHITE"

   strings:
   
      $pattern1 = "626364656469742E657865202F736574207B64656661756C747D20626F6F74737461747573706F6C6963792069676E6F7265616C6C6661696C75726573" 
     
      $s3 = "776261646D696E2044454C4554452053595354454D53544154454241434B5550202D64656C6574654F6C64657374" ascii
      $s4 = "626364656469742E657865202F736574207B64656661756C747D207265636F76657279656E61626C6564204E6F" ascii 
      $s5 = "776261646D696E2044454C4554452053595354454D53544154454241434B5550" ascii 
      $s6 = "433A5C50726F6772616D2046696C65732028783836295C4D6963726F736F66742053514C20536572766572" ascii 
      $s7 = "476C6F62616C5C33353335354641352D303745392D343238422D423541352D314338384341423242343838" ascii 
      $s8 = "433A5C50726F6772616D2046696C65735C4D6963726F736F66742053514C20536572766572" ascii 
      $s9 = "76737361646D696E2E6578652044656C65746520536861646F7773202F416C6C202F5175696574" ascii 
      $s10 = "776D69632E65786520534841444F57434F5059202F6E6F696E746572616374697665" ascii 
      $s11 = "534F4654574152455C4D6963726F736F66745C45524944" ascii 
      $s12 = "AppPolicyGetProcessTerminationMethod" fullword ascii
      $s13 = "7B5041545445524E5F49447D" ascii 
      $s14 = "726561646D652E747874" ascii 
      $s15 = "226E6574776F726B223A22" ascii 
      $s16 = "227375626964223A22" ascii 
      $s17 = "226C616E67223A22" ascii 
      $s18 = "22657874223A22" ascii 
      $s19 = "69642E6B6579" ascii 
      $s20 = "7B5549447D" ascii 

      $seq0 = { eb 34 66 0f 12 0d 10 c4 41 00 f2 0f 59 c1 ba cc }
      $seq1 = { 6a 07 50 e8 51 ff ff ff 8d 86 d0 }
      $seq2 = { ff 15 34 81 41 00 eb 15 83 f8 fc 75 10 8b 45 f4 }
   condition:
      ( uint16(0) == 0x5a4d and filesize < 400KB and pe.imphash() == "ea7e408cd2a264fd13492973e97d8d70" and $pattern1 and 4 of them ) and all of ($seq*) or ( all of them )
}
Download all Yara Rules