Rewterz Threat Advisory – Multiple Microsoft Windows Products Vulnerabilities
January 24, 2023Rewterz Threat Alert – STOP (DJVU) Ransomware – Active IOCs
January 24, 2023Rewterz Threat Advisory – Multiple Microsoft Windows Products Vulnerabilities
January 24, 2023Rewterz Threat Alert – STOP (DJVU) Ransomware – Active IOCs
January 24, 2023Severity
High
Analysis Summary
Conti is a type of ransomware that was first discovered in December 2019. It is a highly sophisticated and dangerous malware that is designed to encrypt files on a victim’s computer and demand a ransom payment in exchange for the decryption key. The ransomware is typically spread through phishing emails or by exploiting vulnerabilities in unpatched software. Once a computer is infected, Conti will encrypt files and append the “.conti” extension to the file names. The malware also drops a ransom note on the victim’s desktop, which provides instructions on how to pay the ransom and regain access to the encrypted files. It is important to note that paying the ransom does not guarantee that the files will be decrypted, and it is generally not recommended to pay the ransom as it only encourages the attackers to continue their activities.
Impact
- Sensitive File Theft
- File Encryption
Indicators of Compromise
MD5
- 845687a6196ccee51b99b04de02ade33
- 305e637d5bbf2a4d4560a6c883e60d6d
- 0faecac8f707d1b361f1ca36987a5c3b
- 3bb8454a62645e0b364781503c7312f0
SHA-256
- fbe45ed19fa942cc5e767acc0ef638447c4aa4b52d4900627a0a0ae71d543bee
- d29080809ab1fb959dbab1a1168e9b136aece03c7f91f071f7283aaa445e7eec
- 8f11bb9536cb885bc57144392bc35e19dbc0f683d57c2c423c87a9d1c6d9d0ae
- ff48dd7bebddf4d5a36c8ef9f5b6057172ee738a19182a12c06bdc20129da0f2
SHA-1
- 772dd1e895e8311a6b1e9134fac0848e54712729
- 8034919a72802521c49bffe70c08fe460c4b8c87
- 3ba9e5f2d4d4c1824224aa6d9d9d9a96f1d61059
- d7477038041404086d3ea5374929f24d9b1fa37f
Remediation
- Search for IOCs in your environment.
- Block all threat indicators at your respective controls.