PULSE NAME
Helldown-Donex-Darktrace-Ransomware.
WHITE PetrP.73 2025-03-18 Modified: 2025-03-18
23
IOCs
MEDIUM VOLUME
The Helldown Ransomware group has been identified as a new strain of the malware and I’ve identified a number of unique detection opportunities for the group.
Indicators of Compromise (7 / 23 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 0bfe25de8c46834e9a7c216f99057d855e272eafafdfef98a6012cecbbdcfabf 2025-03-18
FileHash-SHA256 0ec61a80e61f56f460fc42e5d4f0accec2b04c8db98c28ed4534946214076f2a 2025-03-18
FileHash-SHA256 3e3fad9888856ce195c9c239ad014074f687ba288c78ef26660be93ddd97289e 2025-03-18
FileHash-SHA256 6d6134adfdf16c8ed9513aba40845b15bd314e085ef1d6bd20040afd42e36e40 2025-03-18
FileHash-SHA256 7cd7c04c62d2a8b4697ceebbe7dd95c910d687e4a6989c1d839117e55c1cafd7 2025-03-18
FileHash-SHA256 a02ef4063430d0607e0e7b23ea7c5bf19fad9a09a12565c6745b350b00362be6 2025-03-18
FileHash-SHA256 cb48e4298b216ae532cfd3c89c8f2cbd1e32bb402866d2c81682c6671aa4f8ea 2025-03-18