diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/AutoLogon.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/AutoLogon.png new file mode 100644 index 0000000..1add2a2 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/AutoLogon.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Config.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Config.png new file mode 100644 index 0000000..f275005 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Config.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/EntryRagnar.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/EntryRagnar.png new file mode 100644 index 0000000..929a137 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/EntryRagnar.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ExecBAT.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ExecBAT.png new file mode 100644 index 0000000..23ddfe2 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ExecBAT.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Files.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Files.png new file mode 100644 index 0000000..74c34fc Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Files.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/GenerateListFiles.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/GenerateListFiles.png new file mode 100644 index 0000000..cc40d2c Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/GenerateListFiles.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InfoOS.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InfoOS.png new file mode 100644 index 0000000..5f1c786 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InfoOS.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InitExec.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InitExec.png new file mode 100644 index 0000000..b58deb3 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InitExec.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Injectshellcode.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Injectshellcode.png new file mode 100644 index 0000000..34b0f21 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Injectshellcode.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InstallTools.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InstallTools.png new file mode 100644 index 0000000..4e75fe2 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/InstallTools.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/NAT.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/NAT.png new file mode 100644 index 0000000..2155517 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/NAT.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Path.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Path.png new file mode 100644 index 0000000..4b1996c Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Path.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Payload.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Payload.png new file mode 100644 index 0000000..b4e3e29 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Payload.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ProcessEncrypt.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ProcessEncrypt.png new file mode 100644 index 0000000..c7198b7 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ProcessEncrypt.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Properties.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Properties.png new file mode 100644 index 0000000..f0a72ad Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Properties.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/QueryKey.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/QueryKey.png new file mode 100644 index 0000000..3ecd03e Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/QueryKey.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Ransomware.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Ransomware.png new file mode 100644 index 0000000..d85fa56 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Ransomware.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ReleaseMiniXP.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ReleaseMiniXP.png new file mode 100644 index 0000000..67495b3 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/ReleaseMiniXP.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/RunKey.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/RunKey.png new file mode 100644 index 0000000..e0e319e Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/RunKey.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Salsa.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Salsa.png new file mode 100644 index 0000000..3aa2b3f Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Salsa.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/TargetDir.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/TargetDir.png new file mode 100644 index 0000000..bd90b8b Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/TargetDir.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Untitled Diagram.drawio b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Untitled Diagram.drawio new file mode 100644 index 0000000..03ce41d --- /dev/null +++ b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Untitled Diagram.drawio @@ -0,0 +1 @@ +7Vjbkps4EP0aP2YLoasfMZdsKpWqVM3WTvZRA7KtrAxEyLG9X78iCHOdGidLdqaSPKFutRr1OQfUsILh4fxa83L/rsiEWvledl7BaOX7ACJkL7Xn0ngIgo1jp2XmgjrHnfxHOKfnvEeZiWoQaIpCGVkOnWmR5yI1Ax/XujgNw7aFGt615DsxcdylXE299zIz+8bLfNr5fxdyt2/vDMi6mTnwNthVUu15Vpx6LhivYKiLwjSjwzkUqgavxaVZlzwye92YFrm5ZcHbT/f3OH9L2Tn+g+yqj8A7JK9cls9cHV3B73Wx0/yQSGVh973EAia0q8BcWlh0ccwzUWcGK7g57aURdyVP69mTFYL17c1BuemtVCosVKG/rIUCZFhQ66+MLv4WvZk1oZATO+N2JbQR50fLBVcQrfpEcRBGX2yIW0Ac7E53oLVPHYugpWbfY7CN4044u2vmDls7cPB+BdT+BOo3eWW4UpG0+BJl7795qEe7evSn1ObIVVCWSvI8rblYkIKMC7ZN5yggKRMP22Uo8OFL4wBOOMikJtBDDOJojQBFFDIWYAwCkmAUYwBCNCWHl2UF/WUZwYJlaI4R5j9AstBDgfCIEW/KyBX9/4URPMcIJAghuvF8GkQQrVkQgMTzIgY3HkCI1UXMUULQD0DJ9bx4NkrIHCWA+vEm8hIS0w0KGWNRnITemsAEhHEUwykjmZYWmGXfW1uWinT2vfXAcI3kIpRQ+tKeEjpHibferHEEgOdHAGFoDRZHQbiJSEDjGAU/MiXP/5S0DWqPkwmuIs+Cuge1Vqp4Vcl0CKU4S/OhN/7Ljr3fsLOiunavNS6tkdvdf+gbvVW12S37YrXr0qP+fKW42anIJr3viA9bTXHUqXi6rTFc74R56uid8tvjD8/Q1/q0UNxY8Q77+xlO3R3eF9IW0jWDo04E4pEsmjLdqn4TPU7ERom8UaIGh0kiKwN+6YWVdUD1+IbhuH2Fg+beDpqMnX6vmP4HSU+/Bn5J+qne5Zekv1HSLRDfV9LTr64XLekFVQxvVDF5ThVTMBQFGp/Xt6qYjtSFwG0qXkxo00/Ln0Vo+Eah0ZcktPZA/XqhjT8Oxom+t9DQTyu09v/vU0Lzn1NocKQP7H+j0JA/eqPRpYRmze63cxPe/byH8b8= \ No newline at end of file diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Volumes.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Volumes.png new file mode 100644 index 0000000..5f0dc44 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/Volumes.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/batchedit.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/batchedit.png new file mode 100644 index 0000000..ba5da90 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/batchedit.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/entry0.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/entry0.png new file mode 100644 index 0000000..ac8f20d Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/entry0.png differ diff --git a/Additional Analysis/RagnarLocker/2020-08-08/Pictures/process_key.png b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/process_key.png new file mode 100644 index 0000000..3c5d6d8 Binary files /dev/null and b/Additional Analysis/RagnarLocker/2020-08-08/Pictures/process_key.png differ