

Rewterz Threat Alert – ProtonVPN Scam Campaign – Active IOCs
August 16, 2021
Rewterz Threat Advisory –Multiple Linux Kernel Vulnerabilities
August 17, 2021
Rewterz Threat Alert – ProtonVPN Scam Campaign – Active IOCs
August 16, 2021
Rewterz Threat Advisory –Multiple Linux Kernel Vulnerabilities
August 17, 2021Severity
High
Analysis Summary
Phobos ransomware appeared at the beginning of 2019. It has been noted that this new strain of ransomware is strongly based on the previously known family: Dharma (a.k.a. Crysis), and probably distributed by the same group as Dharma. Phobos is one of the ransomware that is distributed via hacked Remote Desktop (RDP) connections. This isn’t surprising, as hacked RDP servers are a cheap commodity on the underground market, and can make for an attractive and cost-efficient dissemination vector for threat groups. This ransomware does not deploy any techniques of UAC bypass. When we try to run it manually, the UAC confirmation pops up:
Impact
- File encryption
Indicators of Compromise
MD5
- e24b5171dddbfd898f02ba8bdc43d2e5
SHA-256
- a9f4b3276b860a2cbe00ad01f9de8d480fae9201ad95ff9fa4570836d8d244d8
SHA-1
- 786c9873fccef811313a33bb6581bb8053b3b19a
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.