Threat Database Ransomware Sage.DB Ransomware

Sage.DB Ransomware

Sage.DB Ransomware is a file-encrypting threat that belongs to the broader ransomware category, a class of malicious software designed to lock victims out of their own data and then demand payment for its release. Like most threats in this category, Sage.DB Ransomware is built to cause disruption and financial harm, targeting documents, images, databases and other personal or business files stored on an infected computer.

What Sage.DB Ransomware Does

Once active on a system, ransomware such as Sage.DB Ransomware typically scans local drives, and in many cases connected network shares or removable drives, searching for files that are valuable to the user. It then encrypts these files using a cryptographic algorithm, making them unreadable without a special decryption key. After the encryption process finishes, the ransomware usually leaves behind a ransom note, informing the victim that their files have been locked and that payment is required to restore access. These notes commonly appear as text or HTML files placed on the desktop or inside affected folders, and encrypted files often receive a new extension or modified file name to signal that they have been tampered with. It is important to understand that paying the demanded ransom does not guarantee that a working decryption tool will actually be provided.

How It Usually Gets Onto Computers

Ransomware infections of this type typically spread through deceptive means rather than exploiting a single specific method. Common infection vectors include malicious email attachments disguised as invoices, receipts or official documents, links embedded in phishing messages, pirated software or cracked program installers, fake software updates, and malicious advertisements or compromised websites. In some cases, attackers may also gain access to a system through weak or exposed remote access credentials, then manually deploy the ransomware. Because these delivery techniques rely heavily on tricking users, caution when handling unexpected files or links is one of the most effective defenses.

Risks for the User

The primary risk posed by Sage.DB Ransomware is the loss of access to important files, which can include personal photos, work documents, financial records or business databases. For individuals, this can mean losing irreplaceable memories or sensitive information. For businesses, an infection can halt operations, damage client trust and lead to significant financial losses. Beyond encryption, some ransomware families also exfiltrate data before locking files, adding the risk of stolen information being leaked or sold if the ransom is not paid. Attempting to remove the ransomware without addressing the encrypted files first will not restore data, and improperly handling infected files can sometimes make recovery even harder.

Signs of Infection

Typical warning signs include an inability to open previously accessible files, unusual file name changes or extensions, the sudden appearance of ransom note files, and a noticeable slowdown in system performance while encryption is taking place. Security software alerts, unexpected pop-up messages, or a desktop background that has been changed to display a ransom message can also indicate an active infection.

How to Stay Protected

Maintaining regular, offline backups of important files is one of the most reliable defenses against ransomware, since encrypted data can be restored without negotiating with attackers. Users should avoid opening email attachments or clicking links from unknown or unexpected senders, keep operating systems and software updated, and download programs only from official or trusted sources. Disabling unnecessary remote access features and using strong, unique passwords further reduces the risk of unauthorized access that could lead to a ransomware deployment.

Analysis Report

General information

Family Name: Sage.DB Ransomware
Signature status: No Signature

Known Samples

MD5: 3499ef398a88c7b9e25b72b77e374c7c
SHA1: d93a7b2d958523b6c39c4d041a34f85cefceb9e7
SHA256: 1811EC9FB6C7FF8D6E523E4B4AC820F72A9CE8FDDA97E36434B3A84C2259BA29
File Size: 485.38 KB, 485376 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name
  • Microsoft Corporation
File Description
  • Win32 Cabinet Self-Extractor
  • Самоизвлечение CAB-файлов Win32
File Version
  • 11.00.17763.1 (WinBuild.160101.0800)
Internal Name
  • Wextract
Legal Copyright
  • © Microsoft Corporation. All rights reserved.
  • © Корпорация Майкрософт. Все права защищены.
Original Filename
  • WEXTRACT.EXE .MUI
Product Name
  • Internet Explorer
Product Version
  • 11.00.17763.1

File Traits

  • HighEntropy
  • x86

Files Modified

File Attributes
\device\namedpipe\gmdasllogger Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\dsd04.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\dsd04.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\nsi73.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\nsi73.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp000.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete
c:\users\user\appdata\local\temp\ixp001.tmp\bwa65.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\bwa65.exe Synchronize,Write Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\cbo01fj.exe Generic Write,Read Attributes
c:\users\user\appdata\local\temp\ixp001.tmp\cbo01fj.exe Synchronize,Write Attributes
Show More
c:\users\user\appdata\local\temp\ixp001.tmp\tmp4351$.tmp Generic Write,Read Attributes,Delete

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup0 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Zgipvuvx\AppData\Local\Temp\IXP000.TMP\" RegNtPreCreateKey
HKLM\software\wow6432node\microsoft\windows\currentversion\runonce::wextract_cleanup1 rundll32.exe C:\WINDOWS\system32\advpack.dll,DelNodeRunDLL32 "C:\Users\Zgipvuvx\AppData\Local\Temp\IXP001.TMP\" RegNtPreCreateKey

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
User Data Access
  • GetUserDefaultLocaleName
  • GetUserObjectInformation
Encryption Used
  • BCryptOpenAlgorithmProvider
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\Users\Zgipvuvx\AppData\Local\Temp\IXP000.TMP\nSI73.exe
C:\Users\Zgipvuvx\AppData\Local\Temp\IXP001.TMP\bWA65.exe