Threat Database Ransomware Filecoder.DAI Ransomware

Filecoder.DAI Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 10,633
Threat Level: 100 % (High)
Infected Computers: 110
First Seen: March 27, 2022
Last Seen: February 19, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Filecoder.DAI Ransomware
Signature status: No Signature

Known Samples

MD5: ea9a058bd735213295690659213957b2
SHA1: 45933238017a15b0d84c5b70b64575e18190f12a
File Size: 1.18 MB, 1182720 bytes
MD5: 3f8cc8ab6ac9b61725986cab19bbb196
SHA1: 5edbc38d14974ba449e8c604d2644123a06de1bc
SHA256: A6D10A82A82BDE7461C7C343CFB4AB47C7EF39D35367422468D74507CD85FB37
File Size: 1.18 MB, 1182208 bytes
MD5: 0589b8ddc375ba7ecf19c0865c6be79f
SHA1: 7886385104c333d7aff025d03e9e4865165d619a
SHA256: D128657D0183E755B539558A07B69EC440533896C9E6BED7CAFC0EC322989F62
File Size: 1.18 MB, 1182208 bytes
MD5: 6172f26c00f859da868105cecec2afb0
SHA1: e91220790a93311ec925943a540781caac4cc976
SHA256: 8C0778ACBCADC6350CDE4A5E96B784C7EA959416E25DAE29A5C67905F7F8487A
File Size: 1.18 MB, 1182208 bytes
MD5: 4fe30d637e55a20eb07ec5bcb8732586
SHA1: 5f38c786dd44308d386c25f8ca3af704576798d7
SHA256: 436FF14B53640BE788B9E61AEAFED16B22236975F4C8829C068DE2BAF846D530
File Size: 1.18 MB, 1182208 bytes
Show More
MD5: 140269880e7763f7b348cc2e96c389aa
SHA1: 57c2fe07ec8b07f61fe42188f782087c0cfc87b4
SHA256: 1A7FDE6E459066CA8730F2BA1969F50179B9E89D3F780FCD69BB2C2B3315F440
File Size: 1.18 MB, 1184768 bytes
MD5: 9d820d26394e580e2cb99af2cb77aa1e
SHA1: d59829cb48f2fd971ed43f517dda244a1dc4e4c1
SHA256: AD9C0409F622AD56FBAFFF5FC851975DA6501DDE9B768BF7C5C263407B55B058
File Size: 1.18 MB, 1182208 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have resources
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Traits

  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 1,135
Potentially Malicious Blocks: 133
Whitelisted Blocks: 975
Unknown Blocks: 27

Visual Map

x x x 0 x x x x x ? x 0 ? x x x x x x x x x x x x x x x x x x x x x ? x x x 0 x x x 0 x ? x x x x x x x x ? 0 x x x x 0 0 x ? ? x x x 0 x x ? 0 x ? x x 0 0 0 x x ? ? ? x x x x 0 ? ? x x x ? ? ? x x x x x 0 x x 0 x x ? x 0 x x ? x ? x ? ? x ? x ? ? 0 x x x x x x ? ? x 0 x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x x 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 3 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 1 0 0 0 0 0 1 0 0 1 0 2 0 0 0 0 0 0 0 1 0 0 0 0 1 0 0 0 0 2 2 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 2 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 0 1 1 1 0 0 2 2 0 1 1 1 0 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Filecoder.DAI

Files Modified

File Attributes
c:\programdata\{0224d08f-c952-6d0d-7dcb-72284abd03aa}\cdqoowgr.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\{0bee537a-aa75-c07a-a143-d490b6e97535}\qicvbujx.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\{49d631fa-a5e0-6a31-22cd-1a0600f84ecc}\ypzbzczc.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\{9ef0189a-c35c-db8d-6223-40d1232cab51}\txhvpbhe.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\{d2143aba-5baa-8c85-a143-d490b6e97535}\vqmizlgq.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\programdata\{dc28b2de-6a40-86b9-6223-40d1232cab51}\razyycgm.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\default.tmp Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKCU\software\microsoft\windows\currentversion\run::{d2143aba-5baa-8c85-a143-d490b6e97535} "C:\ProgramData\{D2143ABA-5BAA-8C85-A143-D490B6E97535}\vqmizlgq.exe" /V- RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::{0bee537a-aa75-c07a-a143-d490b6e97535} "C:\ProgramData\{0BEE537A-AA75-C07A-A143-D490B6E97535}\qicvbujx.exe" /V- RegNtPreCreateKey
HKCU\software\microsoft\windows\currentversion\run::{0224d08f-c952-6d0d-7dcb-72284abd03aa} "C:\ProgramData\{0224D08F-C952-6D0D-7DCB-72284ABD03AA}\cdqoowgr.exe" /V- RegNtPreCreateKey

Windows API Usage

Category API
Encryption Used
  • CryptAcquireContext
Other Suspicious
  • AdjustTokenPrivileges
User Data Access
  • GetComputerName
  • GetUserName
Network Winsock2
  • WSAStartup
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

C:\ProgramData\{49D631FA-A5E0-6A31-22CD-1A0600F84ECC}\ypzbzczc.exe (NULL)
C:\ProgramData\{D2143ABA-5BAA-8C85-A143-D490B6E97535}\vqmizlgq.exe (NULL)
C:\ProgramData\{DC28B2DE-6A40-86B9-6223-40D1232CAB51}\razyycgm.exe (NULL)
C:\ProgramData\{9EF0189A-C35C-DB8D-6223-40D1232CAB51}\txhvpbhe.exe (NULL)
C:\ProgramData\{0BEE537A-AA75-C07A-A143-D490B6E97535}\qicvbujx.exe (NULL)
Show More
C:\ProgramData\{0224D08F-C952-6D0D-7DCB-72284ABD03AA}\cdqoowgr.exe (NULL)

Trending

Most Viewed

Loading...