Rewterz Threat Advisory – ICS: Johnson Controls exacqVision
June 25, 2021Rewterz Threat Alert – SmokeLoader Malware – Active IOCs
June 25, 2021Rewterz Threat Advisory – ICS: Johnson Controls exacqVision
June 25, 2021Rewterz Threat Alert – SmokeLoader Malware – Active IOCs
June 25, 2021Severity
Medium
Analysis Summary
PhoBos ransomware appeared at the beginning of 2019. It has been noted that this new strain of ransomware is strongly based on the previously known family: Dharma (a.k.a. CrySis), and probably distributed by the same group as Dharma. Phobos is one of the ransomware that are distributed via hacked Remote Desktop (RDP) connections. This isn’t surprising, as hacked RDP servers are a cheap commodity on the underground market, and can make for an attractive and cost-efficient dissemination vector for threat groups. This ransomware does not deploy any techniques of UAC bypass.
Impact
- File encryption
Indicators of Compromise
MD5
- a0690d20445d920d58cc5d2126b6ab33
- 7954d98100bf3af1c16d278c466f9dee
- 7fed7b2f78bc3f2410c22c735ecbc69f
- 159ae9262d5d4c5cf22ae9cb274b0109
SHA-256
- dd259cf568fb36bbc773ffd7b9f28e6cca5da8f709a49512fb8c119b17caae20
- 70d555c5c092b5949dcd99b9e2a46a28166951e7f96410cafaa1e28b1f4eb584
- 982e90e70544fa46a5e2d73923d03c8fbb6ab9c25939d26f82d669f2c627bffe
- b9c2f3cc9ab0a93091b3777bcb4e9f8d0a019fcc95a5eaa41703a91920bdc39c
SHA1
- 8725c1c5cdd93f32c6457e742569dfed8aa87a62
- f6e0807ab52d1976fbb638454a61c221c1fa378e
- 011ea122d727f5b3cf7448a32edd890378297e14
- b1ec6d165eb1055776c47a08c15621be6e9e76b0
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious of emails sent by unknown sender.