Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
High
A PHP file is often the delivery mechanism for downloading the malware dropper. The JScript link used in the attack is written in Russian. Translated, the file name is “Details of the order of JSC Airline Ural Airlines”, possibly in an attempt by the hackers to convince potential victims that the link is legitimate. If clicked by the victim, the JScript begins downloading the executable, which is pulled from compromised websites. Once the malware begins its encryption process, one key is used to encrypt the file name and another key is used to encrypt the contents of the file. While encrypting, Troldesh also pulls data about the system and sends it back to its command and control servers. The README.txt file left behind contains instructions on how to contact the attackers for payment and the decryption method. If the victim is unable to make contact via email, a TOR .onion URL is also provided.
File encryption
Filename
Details of the order of JSC Airline Ural Airlines
Malware Hash (MD5/SHA1/SH256)