Threat Database Ransomware St0rm.A Ransomware

St0rm.A Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 22,909
Threat Level: 100 % (High)
Infected Computers: 43
First Seen: May 15, 2022
Last Seen: May 26, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: St0rm.A Ransomware
Signature status: No Signature

Known Samples

MD5: b482cbc4aec39f8c76aa1cac3cf16ff5
SHA1: 271059260878109cd3352abc8d9b583a7c304cfd
SHA256: CDA02EDD87DB8B655A2F9165EA9DBF94D11C1F88ED3F557A4FBC642474BCEB71
File Size: 190.46 KB, 190464 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File is 32-bit executable
  • File is console application (IMAGE_SUBSYSTEM_WINDOWS_CUI)
  • File is either console or GUI application
  • File is Native application (NOT .NET application)
  • File is not packed
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name PERSONA78
File Description FIX BALONG ISSUE IN PHONE PROPERTY
File Version 1,0,0,0
Internal Name BALONG_FIX
Legal Copyright PERSONA78
Product Name PERSONA78
Product Version 1.0.0.0

File Traits

  • 2+ executable sections
  • x86

Block Information

Total Blocks: 178
Potentially Malicious Blocks: 4
Whitelisted Blocks: 174
Unknown Blocks: 0

Visual Map

x 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 x 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • HackKMS.TC
  • Lamer.CA
  • Lamer.CB
  • Lamer.E
  • St0rm.A
Show More
  • Wpakill.A

Files Modified

File Attributes
c:\224e.tmp\fix_balong.cmd Generic Read,Write Data,Write Attributes,Write extended,Append data

Windows API Usage

Category API
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess

Shell Command Execution

"\224E.tmp\fix_balong.cmd" c:\users\user\downloads\271059260878109cd3352abc8d9b583a7c304cfd_0000190464

Trending

Most Viewed

Loading...