Threat Database Trojans Trojan.Ransomlock.W

Trojan.Ransomlock.W

By GoldSparrow in Trojans

Threat Scorecard

Popularity Rank: 16,508
Threat Level: 90 % (High)
Infected Computers: 429
First Seen: October 4, 2012
Last Seen: January 27, 2026
OS(es) Affected: Windows

Trojan.Ransomlock.W is a Trojan that corrupts the vulnerable computers by the Politie Federal Computer Crime Unit Ransomware. Trojan.Ransomlock.W locks the desktop of the compromised PC and does not allow victims to use the computer. Trojan.Ransomlock.W demands a ransom from the victim to be paid via a Ukash or MoneyPak to unlock the PC. While being executed, Trojan.Ransomlock.W creates several infected files and registry entries including one particular entry that enales it to load automatically whenever you turn your computer on. When the PC is locked by the Trojan.Ransomlock.W, it illustrates a a tricky warning message on the screen, which blames computer users for performing illegal actions and asks them to pay a supposed ransom of of $200 via a Ukash or MoneyPak to restore the locked PC.

File System Details

Trojan.Ransomlock.W may create the following file(s):
# File Name Detections
1. %UserProfile%\Application Data\KB[EIGHT RANDOM DIGITS].exe

Registry Details

Trojan.Ransomlock.W may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"KB[EIGHT RANDOM DIGITS].exe" = "%UserProfile%\Application Data\KB[EIGHT RANDOM DIGITS].exe"

Analysis Report

General information

Family Name: HEUR.Shellcode.Obfus.Generic
Signature status: Self Signed

Known Samples

MD5: 3168a7d23eae4254f591bff0575338c5
SHA1: b1f4af9f9ee929fbf7387bb97af99230cedebc6b
SHA256: 0C1F8DF73B24D902E94652BFCA2C401FA426904412F610851BFE034AF94C05E8
File Size: 5.44 MB, 5435976 bytes
MD5: cca4f35a47f410342f3a80dedf76d0a0
SHA1: 7d51faf54c37384511afd0c262b2e69cd7624a1c
SHA256: 7C7273DC61E3F52E307088AAB0240C1171400114E671659458AF4EB120A77EC0
File Size: 8.40 MB, 8403136 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have exports table
  • File doesn't have relocations information
  • File has TLS information
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
Show More
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

Windows PE Version Information

Name Value
Company Name NoahSystem
File Description Knight Online Client
File Version 4, 23, 13, 3000
Internal Name Warfare
Legal Copyright Copyright ? 2001. NoahSystem.co.ltd
Original Filename KnightOnline.exe
Product Name Knight Online Client
Product Version 4, 23, 13, 3000

Digital Signatures

Signer Root Status
Mgame Corp GlobalSign GCC R45 CodeSigning CA 2020 Self Signed
Game Cafe Services Inc SSL.com Code Signing Intermediate CA ECC R2 Self Signed

File Traits

  • 00 section
  • 2+ executable sections
  • fptable
  • HighEntropy
  • No Version Info
  • x86

Block Information

Total Blocks: 677
Potentially Malicious Blocks: 52
Whitelisted Blocks: 115
Unknown Blocks: 510

Visual Map

? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? ? 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? x 0 x x ? x x ? ? ? ? ? 0 x x x x x x x x x x x 0 x 0 0 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 x x x x x x x 0 0 0 0 0 0 0 0 x 0 0 0 0 0 0 0 x 0 x 0 x x 0 x x 0 x x 0 x x x x 0 x x ? x ? ? ? ? ? ? ? 0 x x x x x x x ? ? ? 0 0 0 1 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Trending

Most Viewed

Loading...