Flyper Ransomware - IOC


1) Ransomware Name - Flyper

2) Encrypted Extensions - .locked

3) Ransom Note File -
instruction.txt
 instruction.html

4) Encrypted Algorithm - AES

5) Decryptor Link - NA

6) Screenshots -

7) Indicators of Compromise - flyper01@sigaint.org



8) File Details -
MD5 e7fe0668a6544b659294337a9eaf3f5a
SHA1 cc6a21b828d66a1e65410689939f841a7d17ddfb
SHA256 9bc81280113473de9ebfe54f689b4440287c37fff562e070d3a28f5269cadcf0
Ssdeep3072: 3M + lmsolAIrRuw + mqv9j1MWLQthQz6LyZMhM + lmsolAIrRuw + mqv9j1MWLQlD: c + lDAA0hg6Ly9 + lDAAmD
Authentihash  8c89b15d82565d836c37dc14632a5fa31a9859d2bdaf66905673280fab42fba3
Imphash  F34d5f2d4577ed6d9ceec516c1f5a744
The size of the file is 214.0 KB (219136 bytes)
Win32 EXE file type
DescriptionPE32 executable for MS Windows (console) Intel 80386 32-bit Mono / .Net assembly

Comments