Ransomware Group intelligence
Prolock
InactiveTrack Prolock with 2 published victims and 1 known leak locations in a single intelligence view.
Overview
Prolock is tracked by Breach House as a ransomware group with 2 published victims.
United States is currently the most targeted country in this dataset.
1 known leak locations are currently associated with this group.
Top Countries
Interactive distribution based on the currently visible victims list.
Known Leak Locations (1)
| Label | Type | Availability | Links |
|---|---|---|---|
| Leak location 1 | Onion service | Down checked 25m ago | msaoyrayohnp32tcgwcanhjouetb5k54aekgnwg7dcvtgtecpumrxpqd.onion |
Top Activity Sectors (2)
Typical Attacks (7)
▼How Prolock typically operates, as attributed by MITRE ATT&CK v19.2. Attributed via ProLock.
-
T1047 Windows Management Instrumentation Execution
What they do: ProLock can use WMIC to execute scripts on targeted hosts.
What that means: Adversaries may abuse Windows Management Instrumentation (WMI) to execute malicious commands and payloads.
-
What they do: ProLock can use BITS jobs to download its malicious payload.
What that means: Adversaries may abuse BITS jobs to persistently execute code and perform various background tasks.
-
T1068 Exploitation for Privilege Escalation Privilege Escalation
What they do: ProLock can use CVE-2019-0859 to escalate privileges on a compromised host.
What that means: Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
-
T1027.003 Steganography Stealth
What they do: ProLock can use .jpg and .bmp files to store its payload.
What that means: Adversaries may use steganography techniques in order to prevent the detection of hidden information.
-
T1070.004 File Deletion Stealth
What they do: ProLock can remove files containing its payload after they are executed.
What that means: Adversaries may delete files left behind by the actions of their intrusion activity.
-
T1486 Data Encrypted for Impact Impact
What they do: ProLock can encrypt files on a compromised host with RC6, and encrypts the key with RSA-1024.
What that means: Adversaries may encrypt data on target systems or on large numbers of systems in a network to interrupt availability to system and network resources.
-
T1490 Inhibit System Recovery Impact
What they do: ProLock can use vssadmin.exe to remove volume shadow copies.
What that means: Adversaries may delete or remove built-in data and turn off services designed to aid in the recovery of a corrupted system to prevent recovery.
Ransom Notes (1)
▼The note this group leaves on a compromised machine. Click a filename to read it.
[HOW TO RECOVER FILES].TXT
Your files have been encrypted by ProLock Ransomware using RSA-2048 algorithm. [.:Nothing personal just business:.] No one can help you to restore files without our special decryption tool. To get your files back you have to pay the decryption fee in BTC. The final price depends on how fast you write to us. 1. Download TOR browser: https://www.torproject.org/ 2. Install the TOR Browser. 3. Open the TOR Browser. 4. Open our website in the TOR browser: msaoyrayohnp32tcgwcanhjouetb5k54aekgnwg7dcvtgtecpumrxpqd.onion 5. Login using your ID [snip] ***If you have any problems connecting or using TOR network: contact our support by email [email protected]. [You'll receive instructions and price inside] The decryption keys will be stored for 1 month. We also have gathered your sensitive data. We would share it in case you refuse to pay. Decryption using third party software is impossible. Attempts to self-decrypting files will result in the loss of your data.
Ransom-note text from RansomLook, licensed CC BY 4.0.
Victims (2)
Search, filter and paginate the victim timeline for Prolock. Showing 1–2 of 2.
| Type | Target | Discovered | Country | Business Category | Intel Link |
|---|---|---|---|---|---|
| Ransomware | Diebold Nixdorf (ATM provider) id356 View details | United States | Communication / Marketing | — | |
|
No additional victim description available. |
|||||
| Ransomware | LaSalle County Government id331 View details | United States | Public Sector | — | |
|
No additional victim description available. |
|||||