sasas.bin
Classification: Malicious
sasas.bin is a malicious file sample. Linked to Ragnar Locker malware. Reported by 4 threat sources, last seen 2026-04-17. Detected by 62 antivirus engines.
Detection summary
- 62 antivirus detections (58% detection ratio)
- 0 IDS alerts
- 0 processes observed
- 0 contacted hosts
- 0 DNS requests
MITRE ATT&CK associations
Malware families: RAGNAR LOCKER (S0481)
Blacklist sightings
| Description | Source | First seen | Last seen | Labels | MITRE ATT&CK |
|---|---|---|---|---|---|
| Generic Malware | Cyber Threat Alliance | 2026-04-17 13:17:23 | 2026-04-17 13:17:23 | ||
| RagnarLocker | ThreatFox Abuse.ch | 2021-12-08 15:54:52 | 2021-12-09 00:08:05 | S0481 Ragnar Locker | |
| Generic.Malware | Abuse.ch | 2020-11-26 13:59:37 | 2020-11-26 13:59:37 | malicious-activity | |
| Ransom.RAGNARLOCKER | Hybrid-Analysis | 2020-11-09 17:00:07 | 2020-11-09 17:00:07 |
Tags
ransomware win.ragnarlockerSample information
- Filenames
- sasas.bin, file
- File type
- PE32 executable (GUI) Intel 80386, for MS Windows
- Size
- 6026592 bytes
- MD5
14e0a802b64a6ce08f1ee408655257e4- SHA-1
5c7b10241c27005b804119be34b18d9ae38c2d39- SHA-256
afab912c41c920c867f1b2ada34114b22dcc9c5f3666edbfc4e9936c29a17a68- First indexed
- 2020-11-09 17:00:07
- Last updated
- 2025-10-30 16:29:03
Antivirus detections
| Engine | Detection |
|---|---|
| ALYac | Trojan.Ransom.RagnarLocker |
| APEX | Malicious |
| AVG | Win32:DangerousSig [Trj] |
| AhnLab-V3 | Trojan/Win32.RagnarLocker.R355456 |
| Alibaba | Ransom:Win32/RagnarLocker.294714c4 |
| Antiy-AVL | Trojan[Ransom]/Win32.RagnarLocker |
| Arcabit | Trojan.Generic.D2A4AAB3 |
| Avast | Win32:DangerousSig [Trj] |
| Avira | TR/Ransom.RagnarLocker.mquxw |
| BitDefender | Trojan.GenericKD.44346035 |
| Bkav | W32.Common.237BF184 |
| CAT-QuickHeal | Trojan.Ghanarava.17311145515257e4 |
| CTX | exe.trojan.ragnarlocker |
| CrowdStrike | win/malicious_confidence_100% (W) |
| Cylance | Unsafe |
| Cynet | Malicious (score: 99) |
| DeepInstinct | MALICIOUS |
| DrWeb | Trojan.Encoder.32986 |
| ESET-NOD32 | Win32/Filecoder.RagnarLocker.A |
| Elastic | malicious (high confidence) |
| Emsisoft | MalCert-S.DF (A) |
| F-Secure | Trojan.TR/Ransom.RagnarLocker.mquxw |
| Fortinet | W32/RagnarLocker.A!tr.ransom |
| GData | Trojan.GenericKD.44346035 |
| Detected | |
| Gridinsoft | Ransom.Win32.Generic.oa!s4 |
| Ikarus | Trojan-Ransom.Ragnarlocker |
| Jiangmin | Trojan.Cryptor.tk |
| K7AntiVirus | Trojan ( 0056475b1 ) |
| K7GW | Trojan ( 0056475b1 ) |
| Kaspersky | Trojan-Ransom.Win32.RagnarLocker.e |
| Lionic | Trojan.Win32.RagnarLocker.j!c |
| Malwarebytes | Malware.AI.2798067359 |
| MaxSecure | Trojan.Malware.73879543.susgen |
| McAfeeD | ti!AFAB912C41C9 |
| MicroWorld-eScan | Trojan.GenericKD.44346035 |
| Microsoft | Ransom:Win32/RagnarLocker!MSR |
| NANO-Antivirus | Trojan.Win32.Cryptor.ibhytm |
| Paloalto | generic.ml |
| Panda | Trj/CI.A |
| Rising | Trojan.DelShad!8.107D7 (TFE:5:01lhpoOXV0R) |
| Skyhigh | RANSOM/Ragnar.a |
| Sophos | Mal/Generic-S |
| Symantec | Trojan.Maltrec.TS |
| TACHYON | Ransom/W32.RagnarLocker.6026592 |
| Tencent | Win32.Trojan.Filecoder.Wimw |
| TrellixENS | RANSOM/Ragnar.a |
| TrendMicro | Ransom.Win32.RAGNARLOCKER.B |
| TrendMicro-HouseCall | Ransom.Win32.RAGNARLOCKER.B |
| VBA32 | BScope.TrojanRansom.RagnarLocker |
| VIPRE | Trojan.GenericKD.44346035 |
| Varist | W32/ABRansom.SOCZ-2623 |
| ViRobot | Trojan.Win32.Z.Ransom.6026592 |
| Xcitium | Malware@#3fm3usftktxoh |
| Zillya | Trojan.Filecoder.Win32.16821 |
| ZoneAlarm | Troj/Ransom-GCU |
| alibabacloud | Ransomware:Win/RagnarLocker.A |
| huorong | Trojan/Generic!7DFAB0CBB8BE1454 |
| ESET-NOD32 | Win32/Filecoder.RagnarLocker.A trojan |
| K7AntiVirus | Ransomware ( 00613b221 ) |
| K7GW | Ransomware ( 00613b221 ) |
| Tencent | Malware.Win32.Gencirc.10be470a |