Threat Database Ransomware Xorist.A Ransomware

Xorist.A Ransomware

By CagedTech in Ransomware

Threat Scorecard

Popularity Rank: 20,435
Threat Level: 100 % (High)
Infected Computers: 363
First Seen: August 3, 2018
Last Seen: February 26, 2026
OS(es) Affected: Windows

Analysis Report

General information

Family Name: Xorist.A Ransomware
Packers: UPX
Signature status: No Signature

Known Samples

MD5: 95c7b5d3a3ad2d49801f149344a8a334
SHA1: 7a78e133c8a04c98561e15254a96b1fa16a39262
SHA256: 6B0D4171FEFBDE4EFB177A3DDA4FB44D4521A664B9E781B8CCA04130FB00DE49
File Size: 242.69 KB, 242688 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File doesn't have exports table
  • File doesn't have relocations information
  • File doesn't have security information
  • File has been packed
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
Show More
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

File Icons

File Traits

  • No Version Info
  • packed
  • x86

Block Information

Total Blocks: 36
Potentially Malicious Blocks: 30
Whitelisted Blocks: 6
Unknown Blocks: 0

Visual Map

x x x x x 0 x x x x 0 x x x x x x x x x x 0 0 x x x x x x x 0 x 0 x x x
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Similar Families

  • Xorist.A
  • Xorist.E
  • Xorist.H
  • Xorist.I

Files Modified

File Attributes
Generic Write,Read Attributes
\\ Generic Read,Write Data,Write Attributes,Write extended,Append data
c:\users\user\appdata\local\temp\n9118066ootj11j.exe Generic Read,Write Data,Write Attributes,Write extended,Append data,Delete,LEFT 262144
c:\users\user\appdata\local\temp\n9118066ootj11j.exe Generic Write,Read Attributes

Registry Modifications

Key::Value Data API Name
HKLM\software\wow6432node\microsoft\windows\currentversion\run::alcmeter C:\Users\Cdmzbfln\AppData\Local\Temp\N9118066oOTJ11j.exe RegNtPreCreateKey
HKLM\software\classes\.bitanos:: OJCFIHGCSZUUAPE RegNtPreCreateKey
HKLM\software\classes\ojcfihgcszuuape:: CRYPTED! RegNtPreCreateKey
HKLM\software\classes\ojcfihgcszuuape\defaulticon:: C:\Users\Cdmzbfln\AppData\Local\Temp\N9118066oOTJ11j.exe,0 RegNtPreCreateKey
HKLM\software\classes\ojcfihgcszuuape\shell\open\command:: C:\Users\Cdmzbfln\AppData\Local\Temp\N9118066oOTJ11j.exe RegNtPreCreateKey

Trending

Most Viewed

Loading...