PadCrypt is a .NET-based ransomware family known for using a time-dependent deterministic domain generation algorithm (DGA) for command-and-control resilience. Documented variants include versions 2.2.86.1, 2.2.97.0, and 2.2.120.0. The malware has been observed protected with DeepSea 4.1 obfuscation and built for .NET Framework 4.5.
A notable characteristic of PadCrypt is its SHA-256-based DGA, which derives domains from the current date and a sequential domain index. Reported variants generate either 24 or 72 domains per day depending on version, with daily rotation and no delay between sequentially generated candidates. The algorithm produces 16-character second-level domains and selects top-level domains from a hard-coded list, with fallback behavior that disproportionately favors .com. Differences between versions include changes to the separator used in the DGA seed string.
PadCrypt is primarily associated with ransomware activity on Windows systems. High-confidence reporting in the available facts supports its classification as ransomware and its use of DGA-based network infrastructure, but does not provide sufficiently corroborated detail here on specific delivery vectors, victim sectors, or actor attribution.
Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
2 distinct techniques documented for this family, organized by ATT&CK tactic.
14 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
4 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Ransomware family discussed in detail for its domain generation algorithm (DGA). The article analyzes PadCrypt versions 2.2.86.1 and 2.2.97.0, showing that it generates daily domains via SHA-256-based hashing using the current date and domain index, likely for command-and-control or related infrastructure rotation.
Ransomware family that encrypts victim data and demands payment.
Ransomware family that encrypts victim data and demands payment.
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.