Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
101
Global rank
98 infographic chevron month
Month rank
85 infographic chevron week
Week rank
0
IOCs

Dharma is advanced ransomware that has been observed in the wild since 2016. It is considered to be the second most profitable RaaS operation by the FBI. The malware targets hospitals and state organizations, encrypts files, and demands a payment to restore access to lost information.

Ransomware
Type
Unknown
Origin
24 August, 2017
First seen
28 August, 2026
Last seen

How to analyze Dharma with ANY.RUN

Type
Unknown
Origin
24 August, 2017
First seen
28 August, 2026
Last seen

IOCs

IP addresses
200.43.178.237
222.25.196.3
117.72.242.9
210.243.136.114
210.40.225.135
210.183.225.16
159.254.4.233
129.28.245.228
165.57.191.50
134.131.43.0
82.163.137.66
33.59.140.89
35.234.67.204
169.20.110.100
27.37.3.185
96.85.140.112
210.127.39.250
192.95.200.170
196.190.220.153
33.59.187.160
Hashes
92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
a17fcf0a2f50e2d495e4f90ce263410edc183add6c62699a2facbccf60410f74
69b61b2c00323cea3686315617d0f452e205dae10c47e02cbe1ea96fea38f582
ba25fefad8a545281ae6f99515926717ebe8c1146805795bedd32041192a0688
61450bd6bc6590236b1df56e1594b12ae174496357a49b5963c41d0d1465d66f
84b900dbd7fa978d6e0caee26fc54f2f61d92c9c75d10b35f00e3e82cd1d67b4
5bdd60c20bf45fbb96d6df9a27040a12b2a131bbf81445bb291a3d4c237c3638
0bda727d28b1303c50ca05c71522af79a0dc714338ef57634682171327fc772f
4055d1b9e553b78c244143ab6b48151604003b39a9bf54879dee9175455c1281
f5d002bfe80b48386a6c99c41528931b7f5df736cd34094463c3f85dde0180bf
326bcb85652c67780d0193d78d5bab30e3668e6bcbcffcff304751b2f4518f54
28afa9302c5708c74af235d477cb13c0dd1358f2ea17f3d08a4c02b6fe4a0939
408ad45577c7d5d163c0019fa9f900fcbf132a1183dbc58cf14cb83e195c6bfa
99e6eb0215c652fe9e9b2f91db5759286cd04f837ce09b331f88f804b0be5195
c9d5bb7022889629ac75a5f7b56779c5ed3d4facea41effd1616039d95bbbc5d
2c8a0014e2b00ecece9639af449fee4c8b8af95a2b9e1589715168fdc9f14600
21ff1de20ee321daf3b67e5d4b8cbfa34cce3af19276abd7f8ae3dcf21e9e971
e01730fda4af0b4efcd46b2ed11ec9a6f46335f0da943ec574de0c0c81e87e62
8db6544480798c1f7e62868ab5f60722bba009cd2b7ca656dd72f40a51b4ebdd
63bcd09c106915cebed1ab7ed14f59b568ebb338e25c876b98580e4578be0cc2
Domains
ip-api.com
pastebin.com
slscr.update.microsoft.com
edge-consumer-static.azureedge.net
urlhaus.abuse.ch
www.google.com
0022a601.pphost.net
matthewsigmondv5.pages.dev
github.com
safeuploadz.com
fonts.googleapis.com
resolver.disbalancer.com
qiniuyunxz.yxflzs.com
mogimall.com
edge-mobile-static.azureedge.net
c.pki.goog
settings-win.data.microsoft.com
cnr.microsoft-telemetry.at
open.spotify.com
gitlab.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://login.live.com/ppsecure/deviceaddcredential.srf
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://urlhaus.abuse.ch/downloads/text_online/
http://144.172.71.105:1338/nova_flow/patcher.exe
https://www.blackhattoolz.com/licensing/updates/addmefast%20bot.exe
https://raw.githubusercontent.com/leetcipher/malware.development/main/process-injection/process-injection.exe
https://raw.githubusercontent.com/haa15/driver-shitty/main/kdmapper_release.exe
https://github.com/hkakkkaa/gdsssdggsg/releases/download/fsdfsd/lol11.exe
https://release-assets.githubusercontent.com/github-production-release-asset/1055902550/c1473cf5-ad3b-426a-8984-5bc61976d274?sp=r&sv=2018-11-09&sr=b&spr=https&se=2026-08-28t12%3a24%3a38z&rscd=attachment%3b+filename%3dlol11.exe&rsct=application%2foctet-stream&skoid=96c2d410-5711-43a1-aedd-ab1947aa7ab0&sktid=398a6654-997b-47e9-b12b-9515b896b4de&skt=2026-08-28t11%3a23%3a43z&ske=2026-08-28t12%3a24%3a38z&sks=b&skv=2018-11-09&sig=c55xqnra0h1y9qkw2iqmtw5pab2x6spaimkomqi6niy%3d&jwt=eyj0exaioijkv1qilcjhbgcioijiuzi1nij9.eyjpc3mioijnaxrodwiuy29tiiwiyxvkijoicmvszwfzzs1hc3nldhmuz2l0ahvidxnlcmnvbnrlbnquy29tiiwia2v5ijoia2v5msisimv4cci6mtc4nzkxnzizmiwibmjmijoxnzg3ote2otmylcjwyxroijoicmvszwfzzwfzc2v0chjvzhvjdglvbi5ibg9ilmnvcmuud2luzg93cy5uzxqifq.xx_s-1rm4wy4vlc8piwgob44k-01m9e-y4y99trt0by&response-content-disposition=attachment%3b%20filename%3dlol11.exe&response-content-type=application%2foctet-stream
http://crl.microsoft.com/pki/crl/products/microoceraut2011_2011_03_22.crl
http://www.microsoft.com/pkiops/crl/micsecserca2011_2011-10-18.crl
http://144.172.71.105:1338/nova_flow/patcher.exe?hash
https://settings-win.data.microsoft.com/settings/v3.0/wsd/waasassessment?os=windows&osver=10.0.19041.1.amd64fre.vb_release.191206-&ring=retail&sku=48&deviceclass=windows.desktop&locale=en-us&deviceid=bad99146-31d3-4ec6-a1a4-be76f32ba5d4&flightring=retail&telemetrylevel=1&hidovergattreg=c%3a%5cwindows%5csystem32%5cdriverstore%5cfilerepository%5chidbthle.inf_amd64_9610b4821fdf82a5%5cmicrosoft.bluetooth.profiles.hidovergatt.dll&appver=10.0&processoridentifier=amd64%20family%2023%20model%201%20stepping%202&oemmodel=dell&updateoffereddays=4294967295&processormanufacturer=authenticamd&installdate=1661339444&oemmodelbaseboard=&branchreadinesslevel=cb&oemsubmodel=j5cr&isclouddomainjoined=0&deferfeatureupdateperiodindays=30&isdeviceretaildemo=0&flightingbranchname=&osuilocale=en-us&devicefamily=windows.desktop&wuclientver=10.0.19041.3996&uninstallactive=1&isflightingenabled=0&osskuid=48&processorclockspeed=3094&totalphysicalram=6144&securebootcapable=0&app=waasassessment&processorcores=6&currentbranch=vb_release&installlanguage=en-us&deferqualityupdateperiodindays=0&servicingbranch=cb&oemname_uncleaned=dell&tpmversion=0&primarydisktotalcapacity=262144&installationtype=client&attrdataver=186&processormodel=amd%20ryzen%205%203500%206-core%20processor&isedgewithchromiuminstalled=1&osversion=10.0.19045.4046&ismdmenrolled=0&activationchannel=retail&honorwufbdeferrals=0&firmwareversion=a.40&trendinstalledkey=1&osarchitecture=amd64&defaultuserregion=244&updatemanagementgroup=2
https://45.138.16.51/bin/screenconnect.clientsetup.exe
http://192.162.199.149/uploads/d6a0dbb9ae834113a8401012b1f9aa18.exe
http://0022a601.pphost.net/threatsim/exe/640.exe
http://0022a601.pphost.net/threatsim/exe/xerox01_pdf.exe
http://119.193.158.215/center.exe
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbtrjrydryt%2bapf3gspypfhbxr5xtqqus9tippmhxdiunkhmewnpyim8s8yceajtxtab8my1oj8mfwpz%2f7y%3d
Last Seen at
Last Seen at

Recent blog posts

post image
US Finance Under Phishing Pressure: What the...
watchers 2536
comments 0
post image
A Single Canadian Tax Lure Spread into a 46-C...
watchers 7351
comments 0
post image
North Korean IT Workers Scheme: Detection IOC...
watchers 10494
comments 0

What is Dharma ransomware?

Dharma is a ransomware-type malware. A malicious program that encrypted files and demands a ransom to restore information. Dharma, a member of the CrySIS family, has been around since August 2017, targeting organizations such as hospitals. It managed to earn attackers over $25 million in ransom payments.

General description of Dharma ransomware

Dharma is considered to be advanced ransomware that uses powerful encryption. As a new variant of the CrySIS family, it was first spotted in the wild in 2017. It was operated by an unknown cyber gang who managed to remain mostly in the shadows to this day. CrySIS was offered as a RaaS (Ransomware-as-a-Service), meaning that “clients” could use it, if they purchased the ransomware from the attackers. This means that those who purchase the malware carry out the actual attacks rather than original creators.

Threat actors changed the name over to Dharma after decryption keys for CrySIS were leaked in late 2016. That was the first, but not the only time somebody published the decryption keys, but it was the only time attackers renamed the malware and re-branded the product.

Some researchers believe that Dharma is one of the most popular RaaS malware out there right now. The popularity of this ransomware is partly due to the constant updates that attackers have been rolling out throughout the years it was active.

In fact, there were instances where three new versions of the malware were reported during the same week. In addition, Dharma proved to be very adaptive, changing distribution channels as the underground community moved from mass spam emails to more targeted attacks in 2018 and 2019.

Another part that contributed to the popularity of Dharma is its flexibility. Although the ransom amount is usually set to one Bitcoin, it can be customized depending on the victim profile. This means that for smaller organizations that can’t pay this much (mind you, Bitcoin cost almost 20,000 USD in 2017), the payment amount can be lowered.

Although not unique to this malware, this flexibility and customization greatly enhanced its effectiveness. In fact, the FBI named Dharma the second most profitable ransomware operation.

Now, despite all of the above, Dharma has never really been available to the general public. The only places it could be found were inconspicuous underground forums. At least, until recently.

In late 2019, the source code of Dharma was observed being put for sale for 2,000 USD.

This made many researchers worried, as some predicted that putting the source code for sale will result in somebody uploading it to the public internet. If ransomware as advanced as Dharma gets in the hands of a mass audience, we can be up for a lot of trouble.

It should also be noted that in 2019 researchers reported new ransomware called Phobos, which has almost the same code as Dharma. Although some speculated that this could be another rebranding, Dharma samples are still constantly being found about as often as instances of Phobos malware use.

Dharma malware analysis

A video recorded in the ANY.RUN interactive malware hunting service shows how the execution of this ransomware unfolds from the victim’s point of view.

raccoon_process_graph

Figure 1: Displays the execution process of the Dharma ransomware This graph was generated by ANY.RUN.

raccoon_process_graph

Figure 2: Displays the Dharma ransomware ransom note

Dharma ransomware execution process

The execution process of the Dharma ransomware is relatively typical for this type of malware such as WannaCry. After the executable file makes its way into an infected system and runs, the main malicious activity begins. After the start of execution, the ransomware deletes shadow copies. After it encrypts all targeted files, Dharma drops a ransom note on the desktop.

Dharma ransomware distribution

Dharma has been observed using multiple distribution methods, but the following three are the most common.

  • Targeted emails with malicious attachments or links.
  • Use of compromised legitimate software, often antiviruses.
  • Targeted campaigns that abuse the RDP protocol.

Out of the three distribution channels, spam email campaigns are the most straightforward. It is also how threat actors relied on the most during the first years of malware operation, launching widespread campaigns and relying on sheer numbers of potential recipients.

However, as users and organizations become more educated about the dangers of cyberattacks, spam emails lose effectiveness. Dharma operators quickly adapted and restored to the other two methods for payload delivery.

Another method that Dharma is known to use is utilizing real compromised software. For example, some attacks involved targeted email campaigns that contained a download link. What made these attacks stand out is that upon clicking the link, the payload would be downloaded along with a compromised legitimate program. The program then would launch an installer designed to direct the victim's attention while the executable file is running in the background.

Finally, the last common distribution method is through the use of compromised RDP. RDP is a protocol developed by Microsoft used to establish a connection between multiple PCs over a network. It’s a completely legitimate protocol that technicians use to carry out remote technical support, among other uses. However, if a session becomes compromised, it gives hackers the ability to download and execute the malicious file as long as they have access to the remotely connected PC.

Conclusion

Dharma is dangerous ransomware. Since 2017 its popularity has been only growing, and continued use indicates that members of the underground hacking community see it as a reliable option. Given that even the FBI considers Dharma to be one of the most effective malware in its class, it’s no wonder that this malware is in demand.

However, even more, worrying is that despite all the attention that Dharma has been getting over the years, creators of this ransomware managed to evade researchers and evolve the ransomware along the way continually.

Although decryptors do exist for some versions of Dharma, the only reason they could be created is that somebody from the inside leaked master keys. Apart from these instances, little progress has been made to crack the encryption algorithm used by Dharma.

And now, with the source code appearing for sale, we run the risk of it popping up on the global Internet, which can spawn a new, massive wave of Dharma attacks.

Keeping this in mind, researchers should take time to study Dharma behavior to prepare for potential attacks carefully. Thankfully, ANY.RUN provides all the necessary tools to carry out Dharma analysis in a secure online environment.

HAVE A LOOK AT

Mamba 2FA screenshot
Mamba 2FA
mamba
Mamba 2FA is an advanced phishing-as-a-service (PhaaS) platform designed to bypass multi-factor authentication (MFA) and target Microsoft 365 accounts. It focuses on intercepting authentication flows in real-time and enables threat actors to hijack user sessions and access sensitive systems even when additional security measures are in place.
Read More
Prometei screenshot
Prometei
prometei
Prometei is a modular botnet malware family that silently infiltrates systems, hijacking their resources for illicit Monero (XMR) mining. Active since at least 2016, it combines stealth, persistence, and lateral movement capabilities. Notable for its global reach and opportunistic infection strategy, it is also used for credential theft.
Read More
Chaos Ransomware screenshot
Chaos ransomware is a malware family known for its destructive capabilities and diverse variants. It first appeared in 2021 as a ransomware builder and later acted as a wiper. Unlike most ransomware strains that encrypt data to extort payment, early Chaos variants permanently corrupted files, while later versions adopted more conventional encryption techniques.
Read More
HijackLoader screenshot
HijackLoader
hijackloader
HijackLoader is a modular malware acting as a vehicle for distributing different types of malicious software on compromised systems. It gained prominence during the summer of 2023 and has since been used in multiple attacks against organizations from various sectors, including hospitality businesses.
Read More
Salvador Stealer screenshot
Salvador Stealer
salvador
Salvador Stealer is a powerful, information-stealing Android malware designed to silently infiltrate systems, extract sensitive data, and exfiltrate it to cybercriminals. Often sold on underground forums, it is part of the growing ecosystem of “stealers-as-a-service” (SaaS) tools that target individuals and organizations alike.
Read More
BlackMoon screenshot
BlackMoon
blackmoon
BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.
Read More