Ransomware Research
Dharma Ransomware
Dharma is a malicious ransomware strain that encrypts victim files and demands ransom payment for decryption. First observed in the wild on November 1, 2016, this ransomware has been actively targeting systems worldwide.
Quick Facts
- Ransomware Family
 - Dharma
 - First Seen
 - November 1, 2016
 
How Dharma Ransomware Works
File Encryption Patterns
Dharma modifies encrypted files using specific patterns to mark them as encrypted:
File extensions added after encryption:
..2020..2021..2048..8800..888..0day..1btc..1dec..2new..4k..aa1..abc..acuf2..adobe..aim..air..amber..aqva..arena..arrow..asd..asus..auf..aye..azero..back..bang..bat..bear..beets..best..betta..bgtx..bip..bitx..biz..bizer..bk666..bkp..bkpx..blend..bmd..bmo..boost..bot..brrr..bsc..btc..btix..cap..carcn..cash..cesar..cezar..cl..cmb..cmd..cobra..com..com2..combo..crash..crown..cry..cu..data..ddos..dharma..dqb..dr..drweb..ebola..eth..fire..frend..funny..gamma..gate..get..gif..gold..good..group..gtf..hack..harma..hat..hccapx..heets..html..hunt..imi..ipm..jack..java..karls..kick..kjh..korea..kr..krab..ldpr..like..live..lock..log..LOL..love..love$..lx..mark..mers..mgs..mnbzr..money..monro..ms13..msh..msplt..myjob..n3..ncov..news..ninja..nqix..nw24..nwa..one..onion..oo7..pay..pbd..pdf..php..plex..plomb..plut..pphl..prnds..q1g..qbix..qbtex..qbx..qwex..r2d2..rec..ridik..risk..rsa..rxx..santa..save..self..smpl..start..stun..syss..tcprx..teren..tor13..tron..usa..uta..vanss..virus..vival..waifu..wal..wallet..war..week..why..wiki..wrar..write..xati..xda..xtbl..xwx..xxxx..xxxxx..yg..ykup..z9..zoh..zzzzz..[crypt7@qq.com]..[decryptoperator@qq.com]..[f-data@protonmail.com]..[helpsok@cock.li]..[infinity@firemail.cc]..blm..EUR..chuk..AHP..AUDIT..lina..WSHLP..fresh..cve..FLYU..zxcv..gtsc..dme..LCK..bH4T..YUFL..kut..259..Elvis..zimba..sss..help..dex..ZIN..SWP..cvc..SUKA..msf..21btc..mpr..bk..gac..4help..yoAD..14x..hub..aol..dis..ROGER..NOV..22btc..Avaad..crypt..TomLe..text..con30..LOTUS..wcg..word..pauq..four..urs..clman..ORAL..Jessy..ROG..biden..eofyd..duk..LAO..pirat..liz..bqd2..4o4..ctpl..error..2122..HPJ..bdev..cum..eye..dhlp..root..rdp..DELTA..PARTY..cnc..ZIG..nmc..ZEUS..pr09..PB..DT..PcS..pause..OFF..grej..dance..TOR..GanP..CLEAN..JRB..filters..c0v..dts..TCYO..6ix9..RZA..MS..C1024..zphs..video..ZILLA..[quacksalver@onionmail.org].ver..[MailPayment@decoding.biz].BTC..credo..ior.-info@kraken.cc_worldcza@email.cz..vbox..[ht2707@email.vccs.edu].comRansom Note and Payment Demands
After encrypting files, Dharma displays ransom notes demanding payment for file recovery:
How to decrypt your files.txtHOW TO DECRYPT YOUR DATA.txtRansom message:
notes/HOW TO DECRYPT YOUR DATA.txt
Note locations:
DesktopStartUpINFORMATION ! ATTENTION!!!.txtRansom message:
notes/INFORMATION ! ATTENTION!!!.txt
Note locations:
DesktopStartUpDANGIR DATA BLOKED.txtRansom message:
notes/DANGIR DATA BLOKED.txt
Note locations:
DesktopStartUpgrand car back data.txtRansom message:
notes/grand car back data.txt
Note locations:
RootDiscsDesktopcrann--recovery.txtRansom message:
notes/crann--recovery.txt
Note locations:
RootDiscsDesktopFILES ENCRYPTED.txtRansom message:
notes/FILES ENCRYPTED.txt
Note locations:
RootDiscsDesktopBACK DATA BASE.txtRansom message:
notes/BACK DATA BASE.txt
Note locations:
RootDiscsDesktopmanual.txtRansom message:
notes/manual.txt
Note locations:
RootDiscsDesktopFiles encrypted!!.txtRansom message:
notes/Files encrypted!!.txt
info-hunt.txtRansom message:
notes/info-hunt.txt
Note locations:
RootDiscsDesktopRETURN FILES.txtRansom message:
notes/RETURN FILES.txt
Note locations:
RootDiscsDesktopDecryption instructions mia.kokers recovery.txtRansom message:
notes/Decryption instructions mia.kokers recovery.txt
Note locations:
RootDiscsDesktopREADME!.txtRansom message:
notes/README!.txt
Note locations:
RootDiscsDesktopinfo.txtRansom message:
notes/info.txt
Note locations:
RootDiscsDesktopMANUAL.txtRansom message:
notes/MANUAL.txt
Note locations:
RootDiscsDesktopDATA BACK.txtRansom message:
notes/DATA BACK.txt
Note locations:
RootDiscsDesktopMANUALdata.txtRansom message:
notes/MANUALdata.txt
Note locations:
RootDiscsDesktopZILLA-INFO.txtRansom message:
notes/ZILLA-INFO.txt
Note locations:
RootDiscsDesktopGood morninng.txtRansom message:
notes/Good morninng.txt
Note locations:
RootDiscsDesktopInfo.htaRansom message:
notes/Info.hta
Note locations:
StartUpSTOPPER.txtRansom message:
notes/STOPPER.txt
Note locations:
DesktopStartUpdangir!data bloked.txtRansom message:
notes/dangir!data bloked.txt
Note locations:
DesktopRansom message:
notes/Decryption instructions.jpg
Note locations:
DesktopRansom message:
notes/INFORMATION HOoW TO DECRYYPT FILES.jpg
Note locations:
DesktopRansom message:
notes/MORE INFORMATION.jpg
Note locations:
DesktopRansom message:
notes/Hello!!!.jpg
Note locations:
DesktopTechnical Indicators
Associated Executable Files
The following executable files are associated with Dharma ransomware:
AcroTray.exeVIBOH96JASRVFASI.exedh.exeadobe.exeworm.exeDharma.exeSkanda.exeSkanda.exe.bindharma1.exe.dontrunTMBT11.exeMedieval.exeinter0712_bendix_cr2.exesetup.exe122334455.exe.POZOR1.exe1adobe.exepayload_132MMK.exe_Viruspayload_132MMK.exeaaaa2.exevolantem_diem@aol.com.exevolantem_diem@aol.com.exe.172903.gzquarvirus.exe.binpayload_139MMK.exemandanos.exe30GAGSAS.exechivas@aolonline.top.exeIPV0Z3QN.exeQAHHC504.exe1FFVVT6D.exeRollVibratinRollVibratin.exe_psi.exe23.EXESERVICE_2017-11-04_12-18.EXEFILE_178payload_56TGSS.exeprogram.exe1taskmgr.exeosnova.exetaskmgr.exeexplore.exe1taskhoste.exebild.exe.exeFILE_3bacon_2018-03-03_16-46.exeCrySiS.exe5401P0_payload.exe.binpleasedvfm.exemyfile.exe1cry.exedetrimentalnue.exe1smscry.execrysis.exewithlove.exedharma.binexecutable.exeaee.exePenland KilbyPenland Kilby.exe0609.EXESdnSdn.exe0709.exe0709.EXEHEAL.EXEPassGen.exeWscParentWscParent.exeunlikexpc.exedllhost1cr.exesoftware.exeSauvegardeProjet.exetrbnugt3.exeliketesc.exefile.execrysis_2018-10-30 - copy.exeSandraCombineProgSnake.exew2rujjry.exeUnlock.exeUnlock1BULD_0611.EXEScanEnginea2engine.dllScCls.dllexpIorer.exeexpiorer.exerealtek.exe_SVHOST.EXEsvhost.binsvhost.exerealtek.exeTaskifierV.exek1zdujh2.exeexlorer64.exe.bakexlorer64.exeexplorer64.execejeoh.exe123.EXE123.exe1nl.exeXMLViewer.exebwrdcmwd.exe1vera.exe1Veravera.exe1Vera.exe1vera.exe.del1vera.exe1sx5102_payload.exesx5102_payload.exe12DiscveryDiscvery.exe!Apache HTTP.exe2Explorer.ex_AAAA.exe2Explorer.exewinhost.exeCosmetics1801.exeLogSession.exeantimalware.exeviabba~1.exeexe.exe_shafao.exeshaofao.exeEbay Option0402.exe0402.exe1locki.exeupdate.exepayload.exepayload - copy.exeexp1mod.exechrome64.binA7E776078C.tmpchrome64b.exe1csrss.exe1csrss.exe1211.exeload0.execrysis_mers.exeCrysis.exepayload3.exetaskhost.exemtapu.exeexpIorer32.exePgpayload2.execurve.exep.exeexpiorer321.exereaItek.exeagent1c.exedemo.exeMicosoftSearch.exeArepartmgr.sysdmx111lm.exe6IYL8XYU.exeAGENT1C.EXEBiosForhisLevelledPeaked.exedmx35pd.exeloadpay.exeL3QZJ6_payload.exe1c_x64_agent.exed2.pe32d2.exe1svhostru.exeCommon Startupfile.pe32UnsolicitedAntialiased1Black.exeVPN_Express_license_generator.exe3G6885.exeRelative DiscussionLeftoverspayload.pe32gjfkyfli;.exeK2EY9PNL.exedmx777amx.pe32dmx777amx.exe1ElephantS.exe5QA0BONA.exeKTEO9SX7.exeTakeaway (2).exeComplex.exen.exeZipcloak Under1c_bit.exeadamsCopy.vexeexec.exeUncImmune1с_.exeStatement.exeContinuumLooselyunpacked.exedmx777.execrysis_roger.exeXDJIEAWU.exeshaofao.pe32Zip.exeWinRar.exewinhost.exeedriver.pe32driver.exe05484199.exeCoronaVirus.exeKMS_VL_ALL_AIO.exe2_5474224874345991605.exeRansomware.CoronaVirus.exeTrojan.Ransom.CoronaVirusFortnite.exeCoronaVirus Ransomware.exeTrojan.Ransom.CoronaVirus.exeCOVID-19.exeCoronavirus.exe1svhostru.exepizdavam.exe004tmp.exe1pgp.exesample1.binsvchost.exemewler.exeDesktopTuner.exe1U9C8B9.exeExplorer.exeDHL.exeavflantuheems1984.exenotepad.exereaitek.exeE5M99S_payload.exechk_crysis_10_dec_19.exexxx.exeSYSDEFENDER.EXEpayload.exe-11lsas.exeASLIPUHA.EXE1data_recovery.exe1sass.exe1task.exe1344.exeClearWin.exe1pros.exe
Elastio Can Help You
Don't let Dharma ransomware take over your data
Elastio provides advanced ransomware protection and recovery solutions to keep your organization safe.
About This Analysis
This Dharma ransomware analysis is part of Elastio's comprehensive ransomware detection database. Elastio provides advanced ransomware protection and recovery solutions, helping organizations defend against and recover from ransomware attacks like Dharma.
Last updated: October 30, 2025
Recent Ransomware
Explore other threats in our database