Payload — Technical Analysis (Windows)
ID: 24ecd58d-837f-4654-b1ef-0d729498f618
STIX ID: report--24ecd58d-837f-4654-b1ef-0d729498f618
Threat Score
80/100
Uploaded: 2026-06-10
Published Date: 2026-06-10
Last Modified Date: 2026-08-06
Created by: dogesec
TLP:CLEAR
...
...
This report provides a reverse-engineered technical analysis of the Windows 'Payload' ransomware (SHA-256: 1ca67af9...), describing its build, IOCP-based multi-threaded encryption using Curve25519 key exchange and ChaCha20 (AVX2/SSE2/scalar), file targeting and footer format (.payload), recovery-inhibition (vssadmin deletion, recycle bin emptying), extensive process/service termination targeting backup and database software, ETW bypass, NT native API usage to evade user-mode hooks, self-deletion via NTFS ADS rename, and associated onion infrastructure and ransomware note details.
