Posts

Showing posts with the label #d0glun

The ransom group d0glun, is it hidden threat or just for fun?

Image
  Summary The below ransomware d0glun was first submitted on 2025-01-16; it is worth paying more attention to because his motivation is low confidence.   Analysis   The details of the D0glun ransomware are as follows: it displays the private information “QQ424714982 TG@CXL13131,” the product name is 8180VPN, and the product version is 1.0.0.0. Figure1-Details of file   A text file for warning displays on the desktop, which tells the victim what date and time they were infected by ransomware. Figure2-a warn text on the desktop   On the screen, a text ransom note tells the victim what types of files will be encrypted; this is different from the other ransom group and how to recover and contact the attacker and leave the address of the dark site but without requiring any bitcoin. Figure3-ransom notes   Different types of files use different suffixes, which are not very common. Figure4-different suffix The other windows are used for decryp...