These are very dangerous ransomware:
125bb27c33959755a839f04959863481268d742ccbf4f3c430bc7b0070c0228b
2130a3195fc093d2eb138d7e9a795461936f6f358fc98a67dea3ae5effd6a2d7
09ad7647ea9b4afca94b33efc9341cacdb248773778620c38f76565e59f383ad
5fd5a9dfa514609a2bd6764d04a119a245eaf4b991b0a8db437fd75c80efaf9a
2d52b482a6813b628d8db7cf3b712fbe2f6b189d9634d63fc83cd014b014f888
Hello,
Thank you for sharing these, we’ll check them.
Best regards,
FlorinG
1 Like
I got these from a friend, it could only the first one is the ransomware, the 4 others are clean. you decide though
i just scanned with Comodo firewall Found those two suspicious certificates
Did a scan with the usual tools nothing to be found
HMP ,Kaspersky , Mbam
but i don’t think that those tool look for suspicious cert
is this a false positive ??
VirusTotal - File - 1f0847ceaa0149a4adc6aa31f5571c024ef82d4e5154e9233e99823216ee6baf Rogue antivirus
phsoftware-corp/RogueDB: Rogue software database (mostly rogue AVs)
Hello,
Thank you for your submissions, we’ll check them.
Best regards,
FlorinG
Ok it’s not rogue antivirus it’s PUA.

