Tag: Ransomware

“Bill for Papers” Drops Locky (.Osiris) (/checkupdate)
IOCs: 162.144.116.161 – aghadiinfotechforclient.com/jht76gh – Download location found in script 222.124.206.41 – simperizinan.sragenkab.go.id/jht76gh – Download location found in script 199.101.51.76 – livingfreehomeramps.com/jht76gh – Download location found in script 107.180.1.210 – adenadataediting.com/jht76gh – Download location found in script 176.121.14.95 – POST /checkupdate – C2 IP Traffic: Hashes: SHA256: d2984c1181749bc2bd0d2ad56c6d5865d38dee3c29276cb41297f4b20543a544 File name: 765-HIGV0613.wsf Hybrid-Analysis Submission SHA256: 40db24cd899efd4381dbe76eb82a10b29a7b5acff901da9ce9a1b3284d3830be ...

pseudoDarkleech Points to Rig-V EK at 195.133.48.182 and Drops Cerber
IOCs: 206.188.193.241 – sienahotel.com – Compromised website 195.133.48.182 – new.mulchguystoledo.com – Rig-V EK Cerber check-in traffic via UDP port 6892: 15.49.2.0/27 122.1.13.0/27 194.165.16.0/24 194.165.17.0/24 ICMP traffic from 95.141.21.37 via destination port 6892 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 185.44.105.11 – ffoqr3ug7m726zou.16iqt6.top – Cerber Decryptor site 185.100.85.150 – ffoqr3ug7m726zou.onion.to – Cerber Decryptor site 185.69.153.226 – ...

“Payment Receipt” Drops Locky (.osiris)
IOCs: 62.75.162.77 – test.grafixx.org – GET /098tb?oAzjRAPD=HlElhIQVI Additional Download Locations (contained in obfuscated JS downloader): u-niwon.com/098tb – 218.232.104.232 chanet.jp/098tb – 210.196.232.211 valuationssa.com.au/098tb – 104.27.149.238 More compromised sites being used as download locations (posted by Techhelplist): aetech-solutions.com/098tb – 37.59.51.53 bigtrust.co.kr/098tb – 211.40.221.90 braindouble.com/098tb – 207.45.186.214 haibeiwuliu.com/098tb – 122.114.99.100 laferwear.com/098tb – 97.74.215.147 malamut.org/098tb – 212.85.104.64 markettv.ro/098tb – ...

“Card Receipt” Leads to Locky (.osiris)
IOCs: 116.255.193.108 – yulexiuba.com – GET /1324w?oohNgc=hswXFnBHeja – Distribution Site Additional Distribution Sites: wiktorek140.cba.pl (95.211.144.65) yourwebstek.nl (185.87.184.130) xxmaoyi.com (120.25.161.125) eroicgrvh38j3f3.com (94.231.77.230) 91.142.90.46 – POST /checkupdate Traffic: Hashes: SHA256: 3fa9335000e47b944dca40defb9107fd2624e73e6ce3efd2de1408afcda9cdea File name: img(194).jse Hybrid-Analysis Link (JS Nemucod) SHA256: 9dde9d37349bf3b28c2e36f514d98b7ce27c580fa8dcf747d0d77bc9480333f6 File name: msTTSUO1 SHA256: 053e51da8f8e2c53f7e11ea305fa8a09554c24a67ef0b4ec0db3eec993ae59a1 File name: msTTSUO1.dll Hybrid-Analysis Link Email: The attached file is a ZIP ...

Malspam Leads to Locky (.zzzzz)
IOCs: 185.25.149.13 – xn--pasaer-spb.pl – Distribution Site 139.224.165.195 – temail.com – Distribution Site DNS queries: bqukfjfv.org (69.195.129.70) abwwngsovislmi.info sqoygkkolb.biz vbtjntlcl.info akhsipwfesvxmer.xyz iwswtkibjbsrqj.ru eltbqgwtjmqvf.su hmthqpva.su hxbvgunernmw.pw vqpiuffvpgdop.pw qrdobtle.pw udfkorp.xyz wibcjkwrk.ru szwanrong.com (119.29.99.214) amnclgo.click ktlgpiilbj.biz hhmunlxtxjpv.xyz egxjtbh.work nrkvwucxxqgbi.org qijftdcnky.click Traffic: Hashes: SHA256: ee530b2234501b4d24adfc2505ae940082750fb32d6ed8a4c43cb8342d8b92a7 File name: 201612031056373427451410.vbs Hybrid-Analysis Link SHA256: 6a186b353bbd729a2cbaa42b0c78ee67cfe69d3b1e56e1a10f1d33afc5ac473e File name: uQzqIRdHQ.34 SHA256: 17f455cc3d24b2333ef999b8ae61040fc459f6ad5798f33abbbbb5407a8174bf File name: ...

pseudoDarkleech Leads to Rig-V EK at 46.30.46.210 and Drops Cerber
IOCs: 74.220.207.74 – neilfoote.com – Compromised website 46.30.46.210 – new.toyotaoflaramie.com – Rig-V EK Cerber check-in traffic via UDP port 6892: 15.49.2.0/27 122.1.13.0/27 194.165.16.0/24 194.165.17.0/24 ICMP traffic from 95.141.21.37 via destination port 6892 185.98.87.153 – ffoqr3ug7m726zou.zgyua4.top 148.251.6.214 – btc.blockr.io – Bitcoin block explorer ffoqr3ug7m726zou.162egg.top – Cerber Decryptor site ffoqr3ug7m726zou.rssh31.bid – Cerber Decryptor site ffoqr3ug7m726zou.onion.to – Cerber ...

pseudoDarkleech Leads to Rig-V EK at 194.87.232.99 and Drops Cerber. New Fingerprinting Technique / Gate?
IOCs: 178.248.39.186 – innovatemyschool.com – Compromised website 194.87.232.99 – add.smartpettags.org – Rig-V EK Cerber checkin UDP traffic via port 6892: 15.49.2.0/27 122.1.13.0/27 194.165.16.0/24 194.165.17.0/24 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 104.36.83.52 – avsxrcoq2q5fgrw2.4vona2.top 103.232.215.140 – avsxrcoq2q5fgrw2.17rmvr.top – Cerber Decryptor site 104.36.83.52 – avsxrcoq2q5fgrw2.wiaikl.top – Cerber Decryptor site 217.197.83.197 – avsxrcoq2q5fgrw2.onion.to – Cerber Decryptor site ...

pseudoDarkleech Leads to Rig-V EK at 194.87.238.148 and Drops Cerber
IOCs: 142.147.9.32 – carrollgymnastics.com – Compromised website 194.87.238.148 – new.ehrlichusedautos.com – Rig-V EK Cerber checkin UDP traffic via port 6892 (3 times for all IPs in each subnet listed below): 15.49.2.0/27 122.1.13.0/27 194.165.16.0/24 194.165.17.0/24 148.251.6.214 – btc.blockr.io – Bitcoin block explorer 54.91.45.162 – ffoqr3ug7m726zou.41c920.top – Cerber Decryptor site 54.91.45.162 – ffoqr3ug7m726zou.rovr6i.top – Cerber Decryptor site ...

Malspam Contains WSF, Downloads Locky (.thor) (/linuxsucks.php)
IOCs: 93.185.104.25 – bestline.cz – GET /76vvyt?cFqotowK=rUUwhHw 37.153.89.141 – carmenortigosa.com – GET /76vvyt?cFqotowK=rUUwhHw 108.163.209.27 – decactus.cl – GET /76vvyt?cFqotowK=rUUwhHw 194.1.239.152 – POST /linuxsucks.php 51.255.107.20 – POST /linuxsucks.php 194.28.87.26 – POST /linuxsucks.php Traffic: DNS Requests: Domain IP Address Country iyemdymjdev.pl qcatgljdsgfvcqq.pw pllyggakgcuto.org moyihqyicfciqf.ru mygyylys.biz uxwamyckkeyfndcrg.xyz odysdabvtgvjqguls.pw bestline.cz 93.185.104.25 Czech Republic decactus.cl 108.163.209.27 United States hrogqamrchfj.info qsrxtej.info ...

“Urgent Payment Request” Malspam Leads to Locky (.thor) (/message.php)
IOCs: 185.17.41.83 – dx-team.org – GET /jhb6576?GChuOAtzYEq=GVUYNDbBRRE 69.195.129.70 – disvfthejnadoufh.biz – POST /message.php 176.103.56.119 – POST /message.php 109.234.35.230 – POST /message.php Traffic: DNS Requests: Domain IP Address Country xbgokbdvilnrlw.info cwvmkawujq.su ukyrrqcxd.su jkvhihqdaaoyd.org ihdteyhyewuaid.click bjbsbpmhlpwaxf.pl torproject.org 82.195.75.101 Germany ojxbkeexoqrbirtq.org bqpkcrxsx.su dx-team.org 185.17.41.83 Poland mwddgguaa5rj7b54.onion.to 185.100.85.150 Romania kcnwtdns.pw jyvityqhfggxicasf.pw mwddgguaa5rj7b54.tor2web.org 38.229.70.4 United States Hashes: SHA256: 9fd3e2fc50b2b44d174cb37964016ea0a12c2c8657a32ae6039c4fdc851e9be0 File ...