
sorry-ransomware-analysis
Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

Sorry ransomware (.sorry) IOCs, YARA rules and forensic analysis - CVE-2026-41940 cPanel campaign

A Simple Ransomware Vaccine

Gets updates from various clearnet domains and ransomware threat actor domains

Curated YARA rules and detection programs for identifying ransomware families, providing signature-based indicators for malware triage, threat…

Yet another Ransomware gang tracker

Tools developed by the Zscaler ThreatLabz Threat Intelligence team

This repository contains indicators of compromise (IOCs) of our various investigations.

ESXi semi-automated ransomware attacks bitcoin wallets

A collection of malware samples caught by several honeypots i manage

A resource containing all the tools each ransomware gangs uses

Map tracking ransomware, by OCD World Watch team

HexaLocker ransomware analysis

Zeek script that monitors SMB traffic and alerts on known ransomware filenames using the Anti-Ransomware File System Resource Manager list.

Curated repository of threat intelligence feeds, IoC lists, YARA rules, and DFIR tool references for SOC/CERT/CTI detection and incident response.

Threat intelligence and incident response case study on LockBit ransomware exploiting CVE-2023-4966 (Citrix Bleed).

🔒 Consolidating and extending hosts files from several well-curated sources. Optionally pick extensions for porn, social media, and other categories.

Read-only cPanel CVE-2026-41940 IOC detector for .sorry ransomware, Mr_Rot13 Filemanager backdoors, C2 callbacks, cron, SSH, and logs.

Conducted a full SOC investigation into a Conti ransomware compromise of an Exchange server using Splunk 8.2.2. Analysed 28,145 events across Windows…