Rewterz Threat Alert – Nemty Ransomware Delivered via Trik Botnet Using SMB Protocol
November 6, 2019Rewterz Threat Alert – Crafted ZIP Files Bypass Secure Email Gateways to Drop Nanocore
November 7, 2019Rewterz Threat Alert – Nemty Ransomware Delivered via Trik Botnet Using SMB Protocol
November 6, 2019Rewterz Threat Alert – Crafted ZIP Files Bypass Secure Email Gateways to Drop Nanocore
November 7, 2019Severity
High
Analysis Summary
Bitpaymer Ransomware dropped using Powershell and malware packed with the Dridex Crypter. First reported on November 4, 2019, an unattributed threat actor conducted a ransomware attack on at least two confirmed Spanish networks, Everis, an IT consulting firm, and SER, Spain’s largest radio network. Open source reporting indicated that the attacker demanded approximately $835,000 USD in ransom for the decryptor.
Impact
File encryption
Indicators of Compromise
Hostname
click[.]clickanalytics208[.]com
IP
- 185[.]92[.]74[.]215
- 45[.]129[.]96[.]9
- 195[.]123[.]213[.]19
- 195[.]123[.]238[.]51
MD5
d0409052256c6efc85b155f58cc03f70
SH256
- 794093ea46b083ce3fac466d726aab7d5b013cd84d81e3e4c1c65aabc13c440c
- 1d778359ab155cb190b9f2a7086c3bcb4082aa195ff8f754dae2d665fd20aa05
- bd327754f879ff15b48fc86c741c4f546b9bbae5c1a5ac4c095df05df696ec4f
- 628c181e6b9797d8356e43066ae182a45e6c37dbee28d9093df8f0825c342d4c
URL
- http[:]//45[.]129[.]96[.]9[:]443
- http[:]//195[.]123[.]238[.]51[:]443
- http[:]//195[.]123[.]213[.]19[:]443
- https[:]//esancendoc[.]esan[.]edu[.]pe/
- https[:]//click[.]clickanalytics208[.]com/s_code[.]js?cid=240&v=73a55f6de3dee2a751c3
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails about sent by unknown senders.
- Never click on the links/attachments sent by unknown senders.