

Rewterz Threat Alert – IcedID banking Trojan – Active IOCs
July 13, 2022
Rewterz Threat Alert – BlackCat Ransomware Increasing Stakes Up To $2,5M In Demands – Active IOCs
July 13, 2022
Rewterz Threat Alert – IcedID banking Trojan – Active IOCs
July 13, 2022
Rewterz Threat Alert – BlackCat Ransomware Increasing Stakes Up To $2,5M In Demands – Active IOCs
July 13, 2022Severity
High
Analysis Summary
LockBit ransomware takes as little as five minutes to deploy the encryption routine on target systems once it lands on the victim network. LockBit attacks leave few traces for forensic analysis as the malware loads into the system memory, with logs and supporting files removed upon execution. In one case, they found that the attack began from a compromised Internet Information Server that launched a remote PowerShell script calling another script embedded in a remote Google Sheets document. This script connects to a command and control server to retrieve and install a PowerShell module for adding a backdoor and establish persistence. To evade monitoring and go unnoticed in the logs, the attacker renamed copies of PowerShell and the binary for running Microsoft HTML Applications (mshta.exe); this prompted Sophos to call this a “PS Rename“ attack. The backdoor is responsible for installing attack modules and executes a VBScript that downloads and executes a second backdoor on systems restart.
LockBit strives to target different sectors throughout the world and has just rebranded for the second time. The ransomware group is now known as LockBit 3.0 as of March 2022. LockBit 3.0, also known as LockBit Black, is active and out there, and the BFSI Sector makes up 1/3rd of its victims. This latest LockBit version has a new extortion model that allows them to purchase stolen data during attacks.
Impact
- Security Bypass
- Information Theft
- Files Encryption
Indicators of Compromise
MD5
- 38745539b71cf201bb502437f891d799
SHA-256
- 80e8defa5377018b093b5b90de0f2957f7062144c83a09a56bba1fe4eda932ce
SHA-1
- f2a72bee623659d3ba16b365024020868246d901
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment