Rewterz Threat Alert – WannaCry Ransomware – Active IOCs
March 8, 2022Rewterz Threat Alert – Lokibot Malware – Active IOCs
March 8, 2022Rewterz Threat Alert – WannaCry Ransomware – Active IOCs
March 8, 2022Rewterz Threat Alert – Lokibot Malware – Active IOCs
March 8, 2022Severity
High
Analysis Summary
Ryuk Ransomware is a ransomware family that was first found in the wild in August 2018. It is one of the most virulent ransomware strains on the market. Ryuk has been observed being used to attack companies or professional environments. This ransomware can lock your files or systems and hold them hostage for ransom. Ryuk targets high-profile enterprises in order to obtain essential information that will impair the victim’s operations.
Ryuk is a form of ransomware used in targeted attacks, in which threat actors encrypt important data to demand big ransom payments. Emotet or TrickBot malware is widely used to spread Ryuk ransomware. Ryuk’s code is comparable to that of the Hermes ransomware. The Ryuk ransomware is believed to be operated by the Russian cybercriminal group WIZARD SPIDER.
Impact
- File encryption
- Privilege Escalation
- Information Theft
- Data Exfiltration
- Network Compromise
Indicators of Compromise
Filename
- WindowsFormsApplication1[.]exe
MD5
- e41fc83160f142017797c80150f30375
- 2376e9b410221c40a7812650324cb4b8
- 9296a9b81bfe119bd786a6f5a8ad43ad
SHA-256
- e5386a6300e33a318571eab0659b5a8ff7b33a902f5c6a3027a1ca46de8102f1
- 89dff51d57c2ce36667add772052bce66827efa8a413b98473e0e72412be042e
- 0aaecf7f77132def96c13d480e32d759839fd65fa76c73e29f0f53c50714c591
SHA-1
- 13173093d6646f80b8be209b17a5f68bb219b53d
- df897d5d3f2b2d06571794e9c1894c4a10a57861
- 581cf7c453358cd94ceed70088470c32a7307c8e
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment