{"id":1423,"date":"2024-02-07T06:30:29","date_gmt":"2024-02-07T06:30:29","guid":{"rendered":"https:\/\/threats.amnpardaz.com\/en\/?p=1423"},"modified":"2024-04-22T12:49:22","modified_gmt":"2024-04-22T12:49:22","slug":"ransomware-linux-trigona","status":"publish","type":"post","link":"https:\/\/threats.amnpardaz.com\/en\/2024\/02\/07\/ransomware-linux-trigona\/","title":{"rendered":"Ransomware.Linux.Trigona"},"content":{"rendered":"<h2 style=\"text-align: justify\">Overview<\/h2>\n<p style=\"text-align: justify\"><strong>Type:<\/strong> Ransomware<br \/>\n<strong>Destruction Level:<\/strong> High<br \/>\n<strong>Prevalence:<\/strong> Moderate<\/p>\n<p>&nbsp;<\/p>\n<h3 style=\"text-align: justify\">Malware Name(s)<\/h3>\n<ul>\n<li style=\"text-align: justify\">Ransomware.Linux.Trigona (Padvish)<\/li>\n<li style=\"text-align: justify\">HEUR:Trojan-Ransom.Linux.Agent.gen (Kaspersky)<\/li>\n<li style=\"text-align: justify\">Trojan.Linux.Ransom.AD (Bitdefender)<\/li>\n<li style=\"text-align: justify\">LINUX\/Ransom.tzrgv (Avira)<\/li>\n<li style=\"text-align: justify\">Ransom.Linux.TRIGONA.THEAFBC (TrendMicro)<\/li>\n<\/ul>\n<h3><\/h3>\n<h3 style=\"text-align: justify\">What is ransomware?<\/h3>\n<p style=\"text-align: justify\">Ransomware is a form of malware that encrypts the user\u2019s vital data and demands ransom for decryption. Ransomware poses a grave threat, inflicting substantial financial harm. Typically, there is no feasible method to decrypt the encrypted data, and one prevalent means of paying the demanded ransom is through cryptocurrency due to its untraceable nature. With most ransomware, retrieving files becomes near-impossible, leaving the user with no choice but to transfer funds to the hacker\u2019s account.<\/p>\n<p>&nbsp;<\/p>\n<h3>What is TRIGONA ransomware?<\/h3>\n<p>TRIGONA, a relatively new family of ransomware, emerged in 2022. Deploying the AES encryption method, Trigona encrypts files. Furthermore, it alters the filenames, appending a randomized string, and affixes the extension &#8220;(locked_)&#8221; at the end. The sample that will be described in this report is a variant tailored to target ESXi server and its purpose is to encrypt files related to virtual machines created on these servers.<\/p>\n<h2><\/h2>\n<h2>Technical Review<\/h2>\n<h3>Indicators of Compromise (IoC)<\/h3>\n<p style=\"text-align: justify\">&#8211; Presence of &#8216;how_to_decrypt.txt&#8217; file in all directories<br \/>\n&#8211; Encryption of files associated with virtual machines created on ESXi servers<br \/>\n&#8211; Encryption of all log files<\/p>\n<p>&nbsp;<\/p>\n<h3>Performance Description<\/h3>\n<p>The overall functionality of this malware varies based on parameters provided during execution. This ransomware is applied on vm and log files and does not make any changes on other types of files. To execute the ransomware specifying the desired path for file encryption is imperative done by assigning the path value to the &#8216;p\/&#8217; or &#8216;path\/&#8217; parameter. In the image below, you can observe the outcome of executing the file with the \/&#8221; path as an example. Once executed, the ransomware file displays information about its execution progress on the server, including the number of encrypted files:<img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3874\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/\u0646\u0645\u0648\u0646\u0647-\u0627\u062c\u0631\u0627\u06cc-\u0641\u0627\u06cc\u0644-\u0628\u0631\u0627\u06cc-\u0645\u0633\u06cc\u0631-1.png\" alt=\"\u0646\u0645\u0648\u0646\u0647 \u0627\u062c\u0631\u0627\u06cc \u0641\u0627\u06cc\u0644 \u0628\u0631\u0627\u06cc \u0645\u0633\u06cc\u0631 \u201c\/\u201d \" width=\"517\" height=\"571\" \/><\/p>\n<p style=\"text-align: justify\">? If we consider the selected path to be the \u201c\/\u201d path of the ESXi system, the files in the following directories will be subject to encryption:<\/p>\n<table style=\"border-collapse: collapse;width: 29.4959%;height: 114px\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 100%;height: 24px;border-color: #000000\">Infected paths<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 100%;height: 24px\"><span style=\"color: #3366ff\">\/vmfs\/volumes\/&lt;UUID&gt;\/<\/span><\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 100%;height: 24px\"><span style=\"color: #3366ff\">\/scratch\/log\/<\/span><\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 100%;height: 24px\"><span style=\"color: #3366ff\">\/var\/lib\/vmware\/osdata\/log\/<\/span><\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 100%;height: 24px\"><span style=\"color: #3366ff\">\/var\/log\/<\/span><\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 100%;height: 24px\"><span style=\"color: #3366ff\">\/var\/run\/log\/<\/span><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p style=\"text-align: justify\">Based on the code snippet depicted in the image below, the script identifies the file types associated with ESXi server machines targeted for encryption.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3875 size-full\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/2-\u0645\u0634\u062e\u0635-\u0634\u062f\u0646-\u0627\u0646\u0648\u0627\u0639-\u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc-\u0645\u0631\u0628\u0648\u0637-\u0628\u0647-\u0645\u0627\u0634\u06cc\u0646\u200c\u0647\u0627\u06cc-\u0645\u0648\u062c\u0648\u062f-\u0628\u0631-\u0631\u0648\u06cc-\u0633\u0631\u0648\u0631-ESXi.png\" alt=\" \u0645\u0634\u062e\u0635 \u0634\u062f\u0646 \u0627\u0646\u0648\u0627\u0639 \u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u0645\u0627\u0634\u06cc\u0646\u200c\u0647\u0627\u06cc \u0645\u0648\u062c\u0648\u062f \u0628\u0631 \u0631\u0648\u06cc \u0633\u0631\u0648\u0631 ESXi\" width=\"713\" height=\"681\" \/><\/p>\n<p style=\"text-align: justify\">In the image provided, two system commands are evident within the ransomware code. The initial command is responsible for retrieving information regarding virtual machines (VMs), while the subsequent command shuts down the available VMs. Following this, then the file encryption steps begin.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3876\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/3-\u062f\u0633\u062a\u0648\u0631-\u0633\u06cc\u0633\u062a\u0645\u06cc-\u062f\u0631-\u0628\u062f\u0646\u0647-\u06a9\u062f-\u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631-\u0648-\u0627\u0637\u0644\u0627\u0639\u0627\u062a-vm-\u0647\u0627-\u0627\u0633\u062a\u062e\u0631\u0627\u062c.png\" alt=\" \u062f\u0633\u062a\u0648\u0631 \u0633\u06cc\u0633\u062a\u0645\u06cc \u062f\u0631 \u0628\u062f\u0646\u0647 \u06a9\u062f \u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631 \u0648 \u0627\u0637\u0644\u0627\u0639\u0627\u062a vm \u0647\u0627 \u0627\u0633\u062a\u062e\u0631\u0627\u062c\" width=\"889\" height=\"102\" \/><\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3877 \" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/4-\u062f\u0633\u062a\u0648\u0631-\u0633\u06cc\u0633\u062a\u0645\u06cc-\u062f\u0631-\u0628\u062f\u0646\u0647-\u06a9\u062f-\u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631-\u0648-\u062e\u0627\u0645\u0648\u0634-\u06a9\u0631\u062f\u0646-vm\u0647\u0627\u06cc-\u06a9\u0647-\u062f\u0631-\u062f\u0633\u062a\u0631\u0633-.png\" alt=\"\u062f\u0633\u062a\u0648\u0631 \u0633\u06cc\u0633\u062a\u0645\u06cc \u062f\u0631 \u0628\u062f\u0646\u0647 \u06a9\u062f \u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631 \u0648\u00a0\u00a0\u062e\u0627\u0645\u0648\u0634 \u06a9\u0631\u062f\u0646 vm\u0647\u0627\u06cc \u06a9\u0647 \u062f\u0631 \u062f\u0633\u062a\u0631\u0633\u00a0\" width=\"891\" height=\"163\" \/><\/p>\n<p style=\"text-align: justify\">After encryption files are stored with random name and extension locked_. :<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3878 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/5-\u0630\u062e\u06cc\u0631\u0647\u200c\u0633\u0627\u0632\u06cc-\u0641\u0627\u06cc\u0644\u200c\u0647\u0627-\u067e\u0633-\u0627\u0632-\u0631\u0645\u0632-\u0634\u062f\u0646-\u0628\u0627-\u0646\u0627\u0645-\u062a\u0635\u0627\u062f\u0641\u06cc-\u0648-\u067e\u0633\u0648\u0646\u062f-locked..png\" alt=\"\u0630\u062e\u06cc\u0631\u0647\u200c\u0633\u0627\u0632\u06cc \u0641\u0627\u06cc\u0644\u200c\u0647\u0627 \u067e\u0633 \u0627\u0632 \u0631\u0645\u0632 \u0634\u062f\u0646 \u0628\u0627 \u0646\u0627\u0645 \u062a\u0635\u0627\u062f\u0641\u06cc \u0648 \u067e\u0633\u0648\u0646\u062f\u00a0locked.\" width=\"916\" height=\"310\" \/><\/p>\n<p>The ransomware also places its payload file, named &#8220;how_to_decrypt.txt,&#8221; in all directories along the target path.<\/p>\n<p>In the provided image, the overall process of file encryption is illustrated, assuming the ransomware is executed with only its essential parameter, which is a specific path. Next, each step will be described separately:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3879 \" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/6-\u0631\u0648\u0646\u062f-\u06a9\u0644\u06cc-\u0631\u0645\u0632-\u0634\u062f\u0646-\u0641\u0627\u06cc\u0644\u200c\u0647\u0627-\u062f\u0631-\u062d\u0627\u0644\u062a-\u0627\u062c\u0631\u0627\u06cc-\u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631-\u062a\u0646\u0647\u0627-\u0628\u0627-\u067e\u0627\u0631\u0627\u0645\u062a\u0631-\u0636\u0631\u0648\u0631\u06cc-\u0622\u0646-\u062f\u0631-\u0645\u0633\u06cc\u0631\u06cc-\u062e\u0627\u0635.png\" alt=\"\u0631\u0648\u0646\u062f \u06a9\u0644\u06cc \u0631\u0645\u0632 \u0634\u062f\u0646 \u0641\u0627\u06cc\u0644\u200c\u0647\u0627 \u062f\u0631 \u062d\u0627\u0644\u062a \u0627\u062c\u0631\u0627\u06cc \u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631 \u062a\u0646\u0647\u0627 \u0628\u0627 \u067e\u0627\u0631\u0627\u0645\u062a\u0631 \u0636\u0631\u0648\u0631\u06cc \u0622\u0646 \u062f\u0631 \u0645\u0633\u06cc\u0631\u06cc \u062e\u0627\u0635\" width=\"955\" height=\"453\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>1.\u00a0 The file targeted for encryption is initially opened with write access, and its contents are loaded into memory.<br \/>\n2. Subsequently, a range of 815 to 840 bytes from the end of the file is filled with the value &#8220;0&#8221;<br \/>\n3. Following this step, the initial 512 KB of the file content is replaced with encrypted values.<br \/>\n4. The previously inserted &#8220;0&#8221; values at the end of the file are then substituted with the specified value shown in the image above.<br \/>\n5. In this stage, the altered file is read.<br \/>\n6. Subsequently, the original file name is substituted with a new name. Verification is conducted to ensure the accuracy of the name change.<\/p>\n<p>&nbsp;<\/p>\n<p>As an example, in the following images, the clean and then encrypted state of one of the log files is given:<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3880 \" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/7-\u062d\u0627\u0644\u062a-\u0633\u0627\u0644\u0645-\u0648-\u0633\u067e\u0633-\u0631\u0645\u0632-\u0634\u062f\u0647-\u06cc\u06a9\u06cc-\u0627\u0632-\u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc-log.png\" alt=\"\u062d\u0627\u0644\u062a \u0633\u0627\u0644\u0645 \u0648 \u0633\u067e\u0633 \u0631\u0645\u0632 \u0634\u062f\u0647 \u06cc\u06a9\u06cc \u0627\u0632 \u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc log\" width=\"996\" height=\"558\" \/><\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-3881\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/8-\u062d\u0627\u0644\u062a-\u0631\u0645\u0632-\u0634\u062f\u0647-\u06cc\u06a9\u06cc-\u0627\u0632-\u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc-log.png\" alt=\"\u062d\u0627\u0644\u062a \u0631\u0645\u0632 \u0634\u062f\u0647 \u06cc\u06a9\u06cc \u0627\u0632 \u0641\u0627\u06cc\u0644\u200c\u0647\u0627\u06cc log\" width=\"968\" height=\"840\" \/><\/p>\n<p style=\"text-align: justify\">?The ransomware file&#8217;s input parameters:<\/p>\n<table style=\"border-collapse: collapse;width: 93.8299%;height: 217px\" border=\"1\">\n<tbody>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;border-color: #000000;text-align: center\">Command line arguments<\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: center\">Function<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>path\/<\/em>\u00a0or\u00a0<em>p\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">This parameter is used to determine the desired path for encrypting files on the ESXi server.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>full\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">The ransomware encrypts the entire content of the file. If omitted, only the first 512 KB of the file will undergo encryption.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>erase\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">Deletes files within the specified path.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>do_not_poweroff\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">When activated, this parameter prevents the malware from shutting down the virtual machines (VMs). Consequently, the portion of the code executing the command &#8220;vim-cmd vmsvc\/power.off&#8221; will not be triggered.Encryption will start only when the VMs are operational. Once the user shuts down the VMs, the files become encrypted and the VMs become inaccessible.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>stealth\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">This parameter initiates encryption of files while preserving their original name and extensionAlso, the Payment file is not created in the paths where the files are encrypted.<br \/>\nThese Changes can only be detected by examining the contents of the files.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>fast\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">This parameter accelerates the file encryption process. Combining it with the &#8220;full\/&#8221; parameter noticeably enhances the speed of file encryption.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>sleep\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">The program pauses execution for a specified duration of n seconds before proceeding<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>shdwn\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">Once files are encrypted, the ESXi server shuts down.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>delete\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">\u00a0Following the completion of the file encryption operation, the ransomware deletes its own file.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>detach\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">In this case, the malware operates in the background without displaying any logs regarding file encryption or Payment file creation in the terminal. Instead, a file named &#8220;nohup.out&#8221; is created in the directory of the ransomware file execution, documenting the names of the disregarded VMs.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>detached\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">In this case, the malware operates in the background without displaying any logs regarding file encryption or Payment file creation in the terminal. Only the list of ignored vms is displayed in the terminal, and no separate file is created.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>short_log\/<\/em><\/span><br \/>\n<span style=\"color: #0000ff\">\u0648<\/span><br \/>\n<span style=\"color: #0000ff\"><em>log\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">These commands print the output of every function called in the ransomware code in the terminal.<\/td>\n<\/tr>\n<tr style=\"height: 24px\">\n<td style=\"width: 20.6496%;height: 24px;text-align: center\"><span style=\"color: #0000ff\"><em>allow_system\/<\/em><\/span><\/td>\n<td style=\"width: 81.8364%;height: 24px;text-align: left\">In this case, the ransomware also encrypts files with its desired extension in the extension in the system directory path of the ESXi server.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<p>?<strong>Ransomware Execution with the &#8216;full\/&#8217; Parameter:<\/strong><\/p>\n<p style=\"text-align: justify\">As depicted in the image below, the volume of encrypted content in this mode significantly exceeds that of the normal mode.<\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3882 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/9-\u062d\u062c\u0645-\u0628\u0633\u06cc\u0627\u0631-\u0628\u0627\u0644\u0627\u06cc-\u0645\u062d\u062a\u0648\u0627\u06cc-\u0631\u0645\u0632-\u0634\u062f\u0647-\u062f\u0631-\u0627\u062c\u0631\u0627\u06cc-\u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631-\u0628\u0627-\u067e\u0627\u0631\u0627\u0645\u062a\u0631-full-.png\" alt=\"\u062d\u062c\u0645 \u0628\u0633\u06cc\u0627\u0631 \u0628\u0627\u0644\u0627\u06cc \u0645\u062d\u062a\u0648\u0627\u06cc \u0631\u0645\u0632 \u0634\u062f\u0647 \u062f\u0631 \u0627\u062c\u0631\u0627\u06cc \u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631 \u0628\u0627 \u067e\u0627\u0631\u0627\u0645\u062a\u0631 full\u00a0\" width=\"646\" height=\"762\" \/><\/p>\n<h4><\/h4>\n<p style=\"text-align: justify\">?<strong> Ransomware Execution with the &#8216;do_not_poweroff\/&#8217; Parameter:<\/strong><\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3883 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/10-\u0627\u062c\u0631\u0627\u06cc-\u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631-\u0628\u0627-\u067e\u0627\u0631\u0627\u0645\u062a\u0631-do_not_poweroff.png\" alt=\"\u0627\u062c\u0631\u0627\u06cc \u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631 \u0628\u0627 \u067e\u0627\u0631\u0627\u0645\u062a\u0631 do_not_poweroff\" width=\"651\" height=\"597\" \/><\/p>\n<h4><\/h4>\n<p style=\"text-align: justify\">? <strong>Ransomware execution with the &#8216;short_log\/&#8217; parameter:<\/strong><\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3884 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/11-\u0627\u062c\u0631\u0627\u06cc-\u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631-\u0628\u0627-\u067e\u0627\u0631\u0627\u0645\u062a\u0631-short_log.png\" alt=\" \u0627\u062c\u0631\u0627\u06cc \u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631 \u0628\u0627 \u067e\u0627\u0631\u0627\u0645\u062a\u0631 short_log\" width=\"642\" height=\"439\" \/><\/p>\n<p>&nbsp;<\/p>\n<p>As illustrated in the image below, when deploying this parameter, details of every activity conducted by the ransomware are printed.<\/p>\n<p style=\"text-align: justify\"><img loading=\"lazy\" decoding=\"async\" class=\" wp-image-3885 aligncenter\" src=\"http:\/\/threats.amnpardaz.com\/wp-content\/uploads\/sites\/2\/2024\/02\/12-\u0686\u0627\u067e-\u0627\u0637\u0644\u0627\u0639\u0627\u062a-\u0645\u0631\u0628\u0648\u0637-\u0628\u0647-\u0641\u0639\u0627\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc-\u0627\u0646\u062c\u0627\u0645-\u0634\u062f\u0647-\u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631-\u0647\u0646\u06af\u0627\u0645-\u0627\u0633\u062a\u0641\u0627\u062f\u0647-\u0627\u0632-\u067e\u0627\u0631\u0627\u0645\u062a\u0631-short_log.png\" alt=\" \u0686\u0627\u067e \u0627\u0637\u0644\u0627\u0639\u0627\u062a \u0645\u0631\u0628\u0648\u0637 \u0628\u0647 \u0641\u0639\u0627\u0644\u06cc\u062a\u200c\u0647\u0627\u06cc \u0627\u0646\u062c\u0627\u0645 \u0634\u062f\u0647 \u0628\u0627\u062c\u200c\u0627\u0641\u0632\u0627\u0631\u00a0\u00a0\u0647\u0646\u06af\u0627\u0645 \u0627\u0633\u062a\u0641\u0627\u062f\u0647 \u0627\u0632 \u067e\u0627\u0631\u0627\u0645\u062a\u0631\u00a0short_log\" width=\"692\" height=\"728\" \/><\/p>\n<h2><\/h2>\n<h2><strong>How to deal with and clean the system?<\/strong><\/h2>\n<p>\u2714\ufe0f Padvish antivirus identifies Trigona ransomware and removes it from the system.<\/p>\n<p>\u2714\ufe0f To prevent potential infection with this ransomware, it is advisable to refrain from downloading files from untrustworthy sources that could compromise the system&#8217;s security.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Overview Type: Ransomware Destruction Level: High Prevalence: Moderate &nbsp; Malware Name(s) Ransomware.Linux.Trigona (Padvish) HEUR:Trojan-Ransom.Linux.Agent.gen (Kaspersky) Trojan.Linux.Ransom.AD (Bitdefender) LINUX\/Ransom.tzrgv (Avira) Ransom.Linux.TRIGONA.THEAFBC (TrendMicro) What is ransomware? Ransomware is a form of malware that encrypts the user\u2019s vital data and demands ransom for decryption. Ransomware poses a grave threat, inflicting substantial financial harm. Typically, there is no feasible&hellip;<\/p>\n","protected":false},"author":27,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,47],"tags":[39,44,51],"class_list":["post-1423","post","type-post","status-publish","format-standard","hentry","category-ransomware","category-malware","tag-ransomware","tag-malware","tag-trigona"],"_links":{"self":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1423","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/users\/27"}],"replies":[{"embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/comments?post=1423"}],"version-history":[{"count":11,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1423\/revisions"}],"predecessor-version":[{"id":1544,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/posts\/1423\/revisions\/1544"}],"wp:attachment":[{"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/media?parent=1423"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/categories?post=1423"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/threats.amnpardaz.com\/en\/wp-json\/wp\/v2\/tags?post=1423"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}