Black friday Up to 3 extra licenses FOR FREE + Special offer for TI LOOKUP Get it now
Webinar
February 26
Better SOC with Interactive Sandbox Practical Use Cases
Register now
120
Global rank
106 infographic chevron month
Month rank
111 infographic chevron week
Week rank
0
IOCs

Troldesh is ransomware — a malware that demands a payment in order to unlock encrypted files. It is also can search and steal information from the banking programs if such are found on the infected machine.

Ransomware
Type
Unknown
Origin
1 January, 2014
First seen
15 August, 2026
Last seen
Also known as
Encoder.858

How to analyze Troldesh with ANY.RUN

Type
Unknown
Origin
1 January, 2014
First seen
15 August, 2026
Last seen

IOCs

IP addresses
40.126.32.140
185.199.108.215
172.217.118.4
185.199.108.133
172.217.114.4
23.52.181.141
2.21.239.157
48.209.6.48
142.251.13.94
140.82.121.4
34.104.35.123
185.199.111.215
48.209.133.15
142.251.14.100
34.117.223.223
140.82.121.6
34.111.175.102
142.251.127.84
142.251.20.94
172.211.123.248
Hashes
837def894a069786ff70e524b6b9cc16a7d745954c20f4623b6e6783150e5d37
2aab13d49b60001de3aa47fb8f7251a973faa7f3c53a3840cdf5fd0b26e9a09f
8b6ce3a640e2d6f36b0001be2a1abb765ae51e62c314a15911e75138cbb544bb
adeed015f06efa363d504a18acb671b1db4b20b23664a55c9bc28aef3283ca29
2f1f93ede80502d153e301baf9b7f68e7c7a9344cfa90cfae396aac17e81ce5a
004ce6de53fd7543043a504c4515636a909ef241c395f039f047fa4a237f65d8
19322ac147bd34d05da760265497cb3ebb9507141136e391a910a11f9edd19a0
3eb16d6c28b502ac4cfee8f4a148df05f4d93229fa36a71db8b08d06329ff18a
6cce5ad8d496bc5179fa84af8afc568eeba980d8a75058c6380b64fb42298c28
eaea1c7eeb2af4fcb59c7db541df61057c4ccdb8a4d4f70af75776d70aa1850c
7852fce59c67ddf1d6b8b997eaa1adfac004a9f3a91c37295de9223674011fba
f48c9d93cc216af13bbfad15dd5e6d1679cd35d318e664029ddf61efc6e51a5d
a0bc246e8e160a9bb32fa60f4e7a04d148a17125f426509466031e07731fdf81
20b91160e2611d3159ad82857323febc906457756678ab73f305c3a1e399d18d
8d21fe1bd251856bfaeaedd6a72ab78f153a047b6042e0fc614f57a32b56d340
f36e9baeb8e56b8d34d4833caf25cd28d2b4be214016dc068abfff3535c11635
a0956386dc64fd9f4883c8741f950cd60a56859616b159c9e4251c9eb0ac5534
3c88fd9805746be38b8d567b81dccee7c790ed17ca58902e69506b1e4c41fd3f
f3d6e0446e4eb9dcbde624a799bbe66ca89d30fddc51a34de5ce5e89cfa300b5
3ad86e3c79ac3361688f6f0f287a8fbbe83d68c40dd778024f50747bcf4c290b
Domains
ocsp.sectigo.com
client.wns.windows.com
github.com
github.githubassets.com
settings-win.data.microsoft.com
download.ccleaner.com
avatars.githubusercontent.com
www.microsoft.com
user-images.githubusercontent.com
o.pki.goog
www.ccleaner.com
api.github.com
ip-info.ff.avast.com
collector.github.com
ocsp.digicert.com
fe3cr.delivery.mp.microsoft.com
c.pki.goog
github-cloud.s3.amazonaws.com
optimizationguide-pa.googleapis.com
slscr.update.microsoft.com
URLs
http://ocsp.digicert.com/mfewtzbnmeswstajbgurdgmcgguabbq50otx%2fh0ztl%2bz8sipi7wewvxdlqqutijuibiv5unu5g%2f6%2brks7qyxjzkceaz1vqyrvgl0erhqlcpm8gy%3d
https://go.microsoft.com/fwlink/?linkid=2257403&clcid=0x409
https://login.live.com/ppsecure/deviceaddcredential.srf
http://clients2.google.com/time/1/current?cup2key=8:aptgqki_ctaxsyg19667yml7eeogfznwbnyjgnwskwi&cup2hreq=e3b0c44298fc1c149afbf4c8996fb92427ae41e4649b934ca495991b7852b855
https://safebrowsingohttpgateway.googleapis.com/v1/ohttp/hpkekeyconfig?key=aizasya2klwbx3mkfo30om9lufyqhpqloa_bnhe
https://github.com/pyran1/malwarecollection
https://clientservices.googleapis.com/chrome-variations/seed?osname=win&channel=stable&milestone=133
https://accounts.google.com/listaccounts?gpsia=1&source=chromiumbrowser&json=standard
https://github.githubassets.com/assets/light-707b19cf061aa459.css
https://github.githubassets.com/assets/light_high_contrast-fc4b867e16562d12.css
https://github.githubassets.com/assets/dark-93f3c6b445d800ff.css
https://github.githubassets.com/assets/dark_high_contrast-49511e11e3ed53a8.css
https://github.githubassets.com/assets/primer-primitives-9f1db623a2d85734.css
https://github.githubassets.com/assets/primer-73a0e2225731ad3f.css
https://github.githubassets.com/assets/github-59fc16002818df36.css
https://github.githubassets.com/assets/28375.3135372361979447.module.css
https://github.githubassets.com/assets/global-558303a14f5c5e97.css
https://github.githubassets.com/assets/code-12d60eb17c94521c.css
https://github.githubassets.com/assets/repository-aea2d17ec2db3121.css
https://github.githubassets.com/assets/app-runtime.bed436009292e433.module.css
Last Seen at
Last Seen at

Recent blog posts

post image
Mirage2FA Hijacks Companies’ Microsoft 365 Se...
watchers 195
comments 0
post image
Intelligence-Driven SOC: Modernizing Threat M...
watchers 11403
comments 0
post image
Supply Chain Security: How ANY.RUN Helps US a...
watchers 6519
comments 0

What is Troldesh ransomware?

Troldesh, also known as Encoder.858, is ransomware belonging to the Shade ransomware family. It was created in 2014. The malware encrypts files on the victim's machine and demands a ransom for the data to be restored.

Attempting to get as much information as possible, the malware also scans the target PC for banking files or banking programs to squeeze every last penny.

General description of Troldesh

Attacking Windows users mainly in Russia, Ukraine, and Germany, Troldesh is one of Russia's most commonly used encryption software.

In addition to this behavior, Troldesh ransomware often comes in conjunction with two particular malware samples, namely Mexar, and Teamspy, which allows attackers to control the victim's PC remotely and gives the virus the ability to install other malware, including trojans on the infecting PC.

In fact, unlike most other ransomware Nemty or others, this virus does not stop executing after encrypting the victim's files. Instead, it starts an infinite loop where it requests URLs of other malicious programs from the command server, downloading and installing them on a contaminated machine. This strategy means that most victims contaminated with Troldesh may end up with a whole host of infections on their PC. And even with removal tools and decryptors, it can be challenging to get rid of this issue.

Even though the malware itself has not evolved a lot throughout its lifespan, attackers' method to demand the ransom has changed. The first malware samples were used to provide an email address at which the victim could contact the hackers and negotiate the payment. In newer campaigns, ransom node demands victims to use the Tor browser to navigate to a payment page that is located on the Dark Web.

Trodlesh, as part of the Shade family, shares several familiarities with related malware: they are written in C++, utilize CTL, use a static link with a Tor client. Every particular malware sample also has a hardcoded URL of the command server. Malicious programs of this family are also known to exhibit similar or identical behavior. As such, they create ten identical ransom notes in two languages – Russian and English and name them README1.txt or README10.txt.

Troldesh malware analysis

A video simulation recorded on ANY.RUN allows us to examine the lifecycle of the Troldesh malware in a lot of detail.

process graph of a troldesh ransomware execution Figure 1: Process graph generated by ANY.RUN helps us visualize the life cycle of the virus

Troldesh execution process

Troldesh ransomware is spread in the form of a script file, either Javascript or JScript. Usually, these files are packed in an archive file that is sometimes protected with a password. In the simulation performed on ANY.RUN, after a script file was unpacked and launched, it installed an executable file from the internet. It should be noted that in the case of Troldesh, executable files typically have "not suspicious" extensions along with the likes of .jpg. After being downloaded, the files are renamed and executed.

As shown in the ANY.RUN simulation, after running, the file immediately began performing the malicious activity, namely: encrypting files, stealing personal data, deleting shadow copies, and changing autorun values in the registry. Files encrypted by the latest versions of Troldesh are known to have a .crypted000007 extension which was also the case in our simulation. Lastly, after encryption was completed, the malicious executable file dropped ransomware instructions on the desktop.

process tree of a troldesh ransomware execution Figure 2: Process tree of a Troldesh ransomware execution

How to avoid infection by Troldesh?

Since Troldesh is commonly distributed using malspam campaigns that mimic real company newsletters, a good way of staying safe is thoroughly checking for the authenticity of emails before downloading any attachments. If necessary, one can get in touch with a company that is the presumable author of the newsletter and verify that they have sent the email.

Once infected, Troldesh installs several secondary malware samples on the victim's PC, thus after Troldesh removal – malware deletes itself from the PC, it is vital to conduct a global system scan and make sure that one's machine is not swarming with other viruses as well.

Distribution of Troldesh

Troldesh ransomware is known to utilize two main attack vectors – email spam and exploit kits. Malspam campaigns usually mimic legitimate information newsletters from actual Russian companies, including banks and large supermarket chains. The emails themselves contain an archive file in which another script file is included.

Upon unpacking the archive and clicking on the file, a malicious loader is installed. It in turn downloads and installs the main payload – Troldesh itself. The loader is known to be stored on legitimate but compromised WordPress websites where it is hidden as an image file.

Troldesh is also known to utilize Axpergle and Nuclear exploit kits, and these attacks are, arguably, more dangerous than email spam as they don't require active actions from the user for the contamination process to begin. Instead, upon visiting a compromised URL, which can be a website hosted by the attackers or a legitimate website that has been hacked, the malware utilizes a vulnerability either in the browser itself or in one of the browser plugins, successfully penetrating into the users PC and starting the execution automatically. Thus, victims can get infected without ever realizing the danger, so get a removal program and a decryptor.

Communication with C&C

Address information of C&C servers is embedded in the body of each malware sample. Servers themselves are hosted on the dark web and communication is established with the use of a Tor client.

Once installed on a victim's PC, the malware requests a public key value from the server to encrypt the victim's files. Should the connection attempt fail, the virus uses one of one hundred private key values stored in its memory.

How to detect Troldesh using ANY.RUN?

Since Troldesh ransomware writes into the registry analysts can detect it by looking at registry keys. Choose the process by clicking on it in the process tree of the task then click on the "More info" button. In the "Advanced details of process" window switch to the "Registry changes" tab and take a closer look. If the analyzed sample writes a value "906D0F2E2F604F839E04" with the name "xi" into the key HKLM\SOFTWARE\System32\Configuration it's Troldesh.

Registry changes created by Troldesh Figure 3: Registry changes created by Troldesh

Conclusion

Troldesh is an extremely dangerous ransomware that is able to contaminate victims who simply end up browsing to the wrong place at the wrong time, ending up on a website hacked by the attackers. Unlike much other ransomware that simply demands money in exchange for user's encrypted data, Troldesh doesn't stop there and goes the extra mile to spread other dangerous malware samples on a victim's PC.

Utilizing analysis services like ANY.RUN is a great way to examine the virus from a safe environment and develop a sufficient defense strategy.

P.S.

On the 27th of April, 2020 authors behind Troldesh ransomware announced that they stopped distribution of the ransomware and publish the decryption keys with a decryptor and instructions. They said that apologize to all the victims of the trojan and hope that the keys they published will help them to recover their data. The same scenario had a couple of other ransomware writers, even the infamous Maze.

You can take a look at the task in which their keys and tool were used to decrypt data.

HAVE A LOOK AT

ValleyRAT screenshot
ValleyRAT
valleyrat
ValleyRAT is a classic remote access trojan first documented in 2023, targeting mainly Windows systems. It is used by threat actors to gain persistent access to infected devices, steal data, and control compromised machines. ValleyRAT is notable for its relatively advanced evasion techniques and its connections to a prominent Chinese APT group.
Read More
DarkComet screenshot
DarkComet
darkcomet rat darkcomet rat
DarkComet RAT is a malicious program designed to remotely control or administer a victim's computer, steal private data and spy on the victim.
Read More
Cephalus screenshot
Cephalus
cephalus
Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.
Read More
GuLoader screenshot
GuLoader
guloader
GuLoader is an advanced downloader written in shellcode. It’s used by criminals to distribute other malware, notably trojans, on a large scale. It’s infamous for using anti-detection and anti-analysis capabilities.
Read More
MetaStealer screenshot
MetaStealer
metastealer
MetaStealer is an info-stealing malware primarily targeting sensitive data like login credentials, payment details, and browser history. It typically infects systems via phishing emails or malicious downloads and can exfiltrate data to a command and control (C2) server. MetaStealer is known for its stealthy techniques, including evasion and persistence mechanisms, which make it difficult to detect. This malware has been actively used in various cyberattacks, particularly for financial theft and credential harvesting from individuals and organizations.
Read More
Salty 2FA screenshot
Salty 2FA
salty2fa
Salty 2FA is a sophisticated Phishing-as-a-Service (PhaaS) framework tailored to hijack user sessions, steal credentials, and gain unauthorized access to corporate systems. Delivered primarily via targeted emails, this kit employs multi-stage evasion tactics, making it a stealthy tool for cybercriminals aiming at high-value enterprise accounts.
Read More