Threat Database Ransomware Shade.B Ransomware

Shade.B Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 18,924
Threat Level: 100 % (High)
Infected Computers: 97
First Seen: February 18, 2019
Last Seen: November 20, 2025
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Shade.B Ransomware
Signature status: No Signature

Known Samples

MD5: a0dfd84daf9e3bdd6e1570b308e160e9
SHA1: eeea9eb710f198863add4b136ec64f02b35e245e
SHA256: 57D453D038BDF8B254124D76FBF183E12B4C95D9C14046CD8D749B106995F640
File Size: 2.29 MB, 2293890 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Comments Reset_AnyDesk_ID_Address
Company Name Skills dG Guo
File Description Reset AnyDesk ID Address Skills dG Guo
File Version 3.3.14.5
Legal Copyright ©1999-2018 Jonathan Bennett & AutoIt Team
Product Name Reset_AnyDesk_ID_Address
Product Version 3.3.14.5

File Traits

  • big overlay
  • HighEntropy
  • WriteProcessMemory
  • x86

Block Information

Total Blocks: 11
Potentially Malicious Blocks: 8
Whitelisted Blocks: 3
Unknown Blocks: 0

Visual Map

x x x x x x x x 0 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Decap.A

Windows API Usage

Category API
Process Shell Execute
  • CreateProcess
Process Manipulation Evasion
  • NtUnmapViewOfSection
  • ReadProcessMemory

Shell Command Execution

C:\Users\Rxjovgrr\AppData\Local\Temp (NULL)
explorer.exe

Trending

Most Viewed

Loading...