PULSE NAME
Old Miner, New Tricks.
WHITE PetrP.73 2025-07-18 Modified: 2025-08-17
91
IOCs
HIGH VOLUME
The investigation into the Lcryx ransomware by the FortiCNAPP team reveals notable overlaps with the H2Miner crypto mining botnet, suggesting a collaborative effort or adaptation by threat actors to enhance financial gain. The Lcryx ransomware, particularly its new variant Lcrypt0rx, is identified as a VBScript-based ransomware first seen in November 2024, exhibiting anomalies indicating potential AI generation. Evidence includes function duplication, erroneous persistence mechanisms, flawed encryption logic, and malformed syntax. These indicators point to poorly optimized code generation and illogical behaviors within its execution.
Indicators of Compromise (23 / 91 total)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 CVE domain hostname
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a729410de4dc397d1fb2ab8f7ae560d3 2025-07-18
FileHash-MD5 006700e5a2ab05704bbb0c589b88924d 2025-07-18
FileHash-MD5 01e5b2530d4cba34f91c8090d19c92db 2025-07-18
FileHash-MD5 0680df49e1866c86697028ea73d28d28 2025-07-18
FileHash-MD5 06a482a6096e8ff4499ae69a9c150e92 2025-07-18
FileHash-MD5 0dc2c71ce9c6c34668e9636abf61b1ae 2025-07-18
FileHash-MD5 1aee8a425ea53c571a16b8efde05ba01 2025-07-18
FileHash-MD5 1bf1efeadedf52c0ed50941b10a2f468 2025-07-18
FileHash-MD5 2726145d4ef3b34d3c3a566177805c39 2025-07-18
FileHash-MD5 44143827116c96f5dcace4f95dff8697 2025-07-18
FileHash-MD5 57f0fdec4d919db0bd4576dc84aec752 2025-07-18
FileHash-MD5 6868c280c61c0b1e2ab8bf6792f1eef2 2025-07-18
FileHash-MD5 9e4f149dae1891f1d22a2cea4f68432e 2025-07-18
FileHash-MD5 9f764ec91535eaf03983b930d9f3bacd 2025-07-18
FileHash-MD5 a7bee104bb486ad0f10331233cc9a9f1 2025-07-18
FileHash-MD5 b3039abf2ad5202f4a9363b418002351 2025-07-18
FileHash-MD5 b6cd214bb814362694cc48299ebaf0e5 2025-07-18
FileHash-MD5 ccef46c7edf9131ccffc47bd69eb743b 2025-07-18
FileHash-MD5 d3884cc519c6855ae20d64264d5f6e93 2025-07-18
FileHash-MD5 da753ebcfe793614129fc11890acedbc 2025-07-18
FileHash-MD5 dbc9125192bd1994cbb764f577ba5dda 2025-07-18
FileHash-MD5 f5f2b61b39105a2b1e6e1a5f4a3863ae 2025-07-18
FileHash-MD5 ff1706b37fea16d75b739a5396d9ffba 2025-07-18