Rewterz Threat Alert – APT29 Cozy Bear – Active IOCs
June 10, 2022Rewterz Threat Alert – DarkCrystal RAT (DCRat) – Active IOCs
June 10, 2022Rewterz Threat Alert – APT29 Cozy Bear – Active IOCs
June 10, 2022Rewterz Threat Alert – DarkCrystal RAT (DCRat) – Active IOCs
June 10, 2022Severity
High
Analysis Summary
Conti ransomware was discovered in December 2019 and is delivered via TrickBot. It’s been utilized against large companies and government institutions across the world, especially in North America. Conti steals important files and information from targeted networks and threatens to disseminate it unless the ransom is paid. Conti ransomware enhances performance by utilizing “up to 32 simultaneous encryption operations,” and is very likely directly controlled by its controllers. This ransomware can target network-based resources while ignoring local files. This feature has the noticeable impact of being able to create targeted harm in an environment in a way that might hinder incident response actions.
Indicators Of Compromise
MD5
- 33879eb9115a2045d638ca19edcf926b
- 5a28712d40414a60844ae5b702db9276
- 710a77804637f65e22a2e230ff6444f9
SHA-256
- 04bf10cd8186fa18bdec9948ae88099dd86ef444af46b20b444b351929a8f71b
- 05c8aaae3fb6c9605f5c69f8eb73cc2c1f08bd72213492e24f221a2ef60508a3
- 0aaacd11d8b956d317489d060e72946d28ab6aef9be1b541aff9904a750f4b51
SHA-1
- a8e67ea6cdd4f51a6901a45979bfb74c973d7738
- 860882cd36e56bb92ce8953e07ad8385a1e0b223
- 371530db6c207d304511d92222a985e6cb4429b2
Impact
- File Encryption
- Cyber Espionage