Gunra 랜섬웨어 분석 보고서
2025-07-25 • Genians • Gunra Ransomware Analysis Report •
Genians analyzed Windows and Linux variants of Gunra ransomware, a family first observed in April 2025 with code-structure similarities to leaked Conti source code. The Windows build enumerates drives and user directories, excludes selected system and security-related paths, encrypts files with ChaCha20, protects keys with RSA-2048, appends the CRYPT extension, and creates R3adm3.txt ransom notes. It also queries and deletes Volume Shadow Copies through WMI and WMIC to inhibit recovery. The Linux build supports command-line options for target paths, extensions, thread counts, encryption ratio, key files, storage paths, and size limits, then uses threaded ChaCha20 encryption and renames files with the .ENCRT extension. The report maps these behaviors to Genian EDR detections for IoC-based execution, mass document renaming, shadow copy deletion, and repeated ransom-note creation.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 22c47ec98718ab243f2f474170366a1… | 2025-07-25 | 2025-10-22 |
| HASH | 91f8fc7a3290611e28a35a403fd8155… | 2025-07-25 | 2025-08-27 |