Contact us Buy Me a Coffee

Sponsored by Hudson Rock Use Hudson Rock's free cybercrime intelligence tools to learn how Infostealer infections are leading to ransomware attacks

Yanluowang

According to PCrisk, Yanluowang is ransomware that encrypts (and renames) files, ends all running processes, stops services, and creates the README.txt file containing a ransom note. It appends the .yanluowang extension to filenames. Cybercriminals behind Yanluowang are targeting enterprise entities and organizations in the financial sector.Files encrypted by Yanluowang can be decrypted with this tool (it is possible to decrypt all files if the original file is larger than 3GB. If the original file is smaller than 3GB, then only smaller files can be decrypted).
External information

Victims
6
 
First Discovered
2022-07-02
victim
Last Discovered
2022-08-10
victim
Inactive Since
3yrs
more than
Avg Delay
N/A
attack→claim
Infostealer
N/A
victims with domain
Countries
0
hit
View Victims on World Map View Group Statistics

Known Locations (1)
Favicon Title Type Available Last Visit Server Info FQDN
favicon Yanluowang No 2026-04-28T07:23:40 jukswsxbh3jsxuddvidrjdvwuohtsy4kxg2axbppiyclomt2qciyfoad.onion

Target
Top 5 Activity Sectors
  • Technology 1
  • Consumer Services 1
  • Telecommunication 1
Top 5 Countries

Heatmap

Ransom Notes (1)

Tools Used
This information is provided by Ransomware-Tool-Matrix
Discovery RMM Tools Defense Evasion Credential Theft OffSec Networking LOLBAS Exfiltration
AdFind

Cent Browser

S3 Browser

SoftPerfect NetScan

LogMeIn

ScreenConnect

TeamViewer






GrabChrome

GrabFF

KeeThief

Mimikatz

NirSoft WebBrowserPassView
Cobalt Strike

Impacket



Chisel




NTDS Utility (ntdsutil)

PsExec

Windows Event Utility (wevtutil)







YARA Rules (1)

Victims (6)
Logo
Discovered: 2022-08-10 (3y ago)
No description available
Logo
Discovered: 2022-07-02 (3y ago)
No description available
Logo
Discovered: 2022-07-02 (3y ago)
No description available
Logo
Discovered: 2022-07-02 (3y ago)
No description available
Logo
Discovered: 2022-07-02 (3y ago)
No description available
Logo
Discovered: 2022-07-02 (3y ago)
No description available