Tag: pseudoDarkleech

p

pseudoDarkleech to RIG-v EK’s

IOCs: 107.181.172.103 – lovlose.com – Compromised site 109.234.37.178 – new.buttock.toys – RIG-v EK Cerber check-in traffic via UDP port 6892 1.22.15.0/27 2.23.16.0/27 91.239.24.0/24 91.239.25.0/24 IOCs: 184.168.136.128 – tarboushgrill.com – Compromised site 81.177.139.86 – see.soulartspublishing.com – RIG-v EK Cerber check-in traffic via UDP port 6892 77.4.1.0/27 77.15.1.0/27 91.239.24.0/24 91.239.25.0/24 IOCs: 141.138.168.111 – hoolhoevebriards.com – Compromised site ...

&

‘Tis the Season for Cerber: Rig-V EK at 195.133.201.249 and Drops, you guessed it, Cerber Ransomware

IOCs: 205.251.140.114 – northrivercommission.org – Compromised site 195.133.201.249 – add.medlucency.info – RIG-v EK Cerber check-in traffic via UDP port 6892: 93.223.40.0/27 92.145.32.0/27 91.239.24.0/24 91.239.25.0/24 148.251.6.214 – btc.blockr.info – Bitcoin block explorer 84.200.4.130 – ffoqr3ug7m726zou.17vj7b.top – Cerber Decryptor site Traffic: Hashes: SHA256: a309461e89391f4432949d391d8ba4bcc8fee4f1def2bf01bf439da1c11e21dd File name: RIGV EK UA Gate.html SHA256: 052d05cbca3b82357ccd8d19fe4c2ed2207ba8286d57b0d4f24f88dce8ce6611 File name: RIGV EK Landing ...

p

pseudoDarkleech Script Redirects Host to Rig-V EK at 195.161.62.232. EK Drops Cerber.

IOCs: 184.172.50.36 – chicago.fdmaps.com – Compromised site 195.161.62.232 – new.underinsuredamerican.org – Rig-V EK Cerber check-in traffic via UDP port 6892: 37.15.20.0/27 77.1.12.0/27 91.239.24.0/24 91.239.25.0/24 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 84.200.4.130 – ffoqr3ug7m726zou.1mstqg.top – Cerber Decryptor site Traffic: Hashes: SHA256: 814d06968bd54aadd13f3e352d5c6b792decdb1c8eeec8d35e7aeaa0cde72b57 File name: RigV UA check.html SHA256: 7e285aee3f54b9a289d03f8a6904eeed8dd88c3028f92ce9d62d8f2c333a52d7 File name: RigV EK Landing Page.html ...

p

pseudoDarkleech Redirects Host to Rig-V EK at 81.177.6.49 and Drops Cerber

IOCs: 162.255.161.10 – luckystavern.com – Compromised site 81.177.6.49 – will.warondoctors.info – Rig-V EK Cerber check-in traffic via UDP port 6892: 37.15.20.0/27 77.1.12.0/27 91.239.24.0/24 91.239.25.0/24 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 23.152.0.137 – ffoqr3ug7m726zou.13inb1.top – Cerber Decryptor site Traffic: Hashes: SHA256: 948785c8a2c441345317ea80e1fd7c622599932dade375872b9c5b9030a61145 File name: RigV UA check page.html SHA256: 699fe5529a3a6928717e47300646d18f36a6ce21823228fffdd52d06e9aa9cd5 File name: RigV EK Landing ...

p

pseudoDarkleech Redirects to Rig-V at 195.133.49.182 Which Drops Cerber

IOCs: 166.62.25.210 – dunlogginvet.com – Compromised website 195.133.49.182 – art.thinleadermd.com – Rig-v EK sub-domain Cerber check-in traffic via UDP port 6892: 37.15.20.0/27 77.1.12.0/27 91.239.24.0/24 91.239.25.0/24 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 185.82.200.167 – avsxrcoq2q5fgrw2.1gaje2.top – Cerber Decryptor site Traffic: Hashes: SHA256: df65f65dc15cfa999f07869b587c74c645da66129c009db5d8b8c2c29ae4fadf File name: Rig-V Flash Exploit.swf SHA256: 9f93a612da234591aa2645277aa0672ad53cfebe2697bdcf5e38e0920e270d35 File name: OTTYUADAF SHA256: d6a7f7253e30ffbfddc85c34a905dd9022819df0629c698fe71bec384b041f6d ...

p

pseudoDarkleech Leads to Rig-V EK at 46.30.46.210 and Drops Cerber

IOCs: 74.220.207.74 – neilfoote.com – Compromised website 46.30.46.210 – new.toyotaoflaramie.com – Rig-V EK Cerber check-in traffic via UDP port 6892: 15.49.2.0/27 122.1.13.0/27 194.165.16.0/24 194.165.17.0/24 ICMP traffic from 95.141.21.37 via destination port 6892 185.98.87.153 – ffoqr3ug7m726zou.zgyua4.top 148.251.6.214 – btc.blockr.io – Bitcoin block explorer ffoqr3ug7m726zou.162egg.top – Cerber Decryptor site ffoqr3ug7m726zou.rssh31.bid – Cerber Decryptor site ffoqr3ug7m726zou.onion.to – Cerber ...

p

pseudoDarkleech Leads to Rig-V EK at 194.87.238.148 and Drops Cerber

IOCs: 142.147.9.32 – carrollgymnastics.com – Compromised website 194.87.238.148 – new.ehrlichusedautos.com – Rig-V EK Cerber checkin UDP traffic via port 6892 (3 times for all IPs in each subnet listed below): 15.49.2.0/27 122.1.13.0/27 194.165.16.0/24 194.165.17.0/24 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 54.91.45.162 – ffoqr3ug7m726zou.41c920.top – Cerber Decryptor site 54.91.45.162 – ffoqr3ug7m726zou.rovr6i.top – Cerber Decryptor site ...

p

pseudoDarkleech Leads to Rig EK at 5.200.55.126 and Drops Cerber

IOCs: 66.147.244.158 – tbcphoenix.org – Compromised website 5.200.55.126 – ew.albanyparklocksmithchicago.com – Rig EK 194.165.16.0/24, 194.165.17.0/24, 194.165.18.0/24, 194.165.19.0/24 – UDP port 6892 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 136.243.157.171 – ffoqr3ug7m726zou.le2brr.bid – Cerber Decryptor site Traffic: Hashes: SHA256: 79cfb143bb59ba051584be153aa1b0669eaa872630ebc647befaf7109a93d3df File name: RigEK Landing Page.html SHA256: 4f2936fc74f7982fb450a0edfd0e200c0301b3cba56f3e55cc08cf92d423917d File name: RigEK Flash Exploit.swf SHA256: 0601888775c21e42d533e028678b91ad70ed7656a2a7aa68f5d46fad2c1c6fbe File name: ...

p

pseudoDarkleech Leads to Rig EK at 212.116.121.122 & Drops Cerber Ransomware

IOCs: 192.185.28.237 – eureka-resources.com – Compromised website 212.116.121.122 – try.jessicajw.com – Rig EK 31.184.234.0/24 and 31.184.235.0/24 – UDP traffic via port 6892 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 107.161.95.138 – ffoqr3ug7m726zou.zn90h4.bid – Cerber Decryptor payment site Traffic: Hashes: SHA256: 2cfbbe508cdfe85767c4ad9f097adce52bb8a630598f9b2d191b7dc82f195069 File name: RigEK Landing Page.html SHA256: 3474904d1dfd8943d3c779d621aa9767465532f288523bae6b57194b35fb3e6e File name: RigEK Flash Exploit.swf SHA256: 05d0f6625551fc4787430495d8c4f103e00624e7e64eb93b3c3bdbfb789981b2 ...

R

Rig EK at 212.116.121.122 Drops Cerber Ransomware

IOCs: 50.62.216.150 – heathfoodstorenewsmyrna.com – Compromised website 212.116.121.122 – we.jessicaandclayton.com – Rig EK 31.184.234.0/24 and 31.184.235.0/24 – UDP traffic via port 6892 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 107.161.95.138 – ffoqr3ug7m726zou.zn90h4.bid – Cerber Decryptor payment site Traffic: Hashes: SHA256: 2c68d7b4f7bb14a8b9f3986360bd351f34565eb0a4029ee01cc8588bcddb8c50 File name: RigEK Landing Page.html SHA256: 3474904d1dfd8943d3c779d621aa9767465532f288523bae6b57194b35fb3e6e File name: RigEK Flash Exploit.swf SHA256: 05d0f6625551fc4787430495d8c4f103e00624e7e64eb93b3c3bdbfb789981b2 ...