Blurring The Lines: Intrusion Shows Connection With Three Major Ransomware Gangs
Key TakeawaysThe intrusion began when a user downloaded and executed a malicious file impersonating DeskSoft’s EarthTime application but instead dropped...
Key TakeawaysThe intrusion began when a user downloaded and executed a malicious file impersonating DeskSoft’s EarthTime application but instead dropped...
OverviewBumblebee malware has been an initial access tool used by threat actors since late 2021. In 2023 the malware was...
Researchers from The DFIR Report, in partnership with Proofpoint, have identified a new and resilient variant of the Interlock ransomware...
Table of Contents:Case SummaryAnalystsInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCommand and ControlExfiltrationImpactTimelineDiamond ModelIndicatorsDetectionsMITRE ATT&CKCase SummaryIn late June 2024, an unpatched Confluence...
Score: 8 MALWARE FAMILY: bankerTAGS:banker, evasion, ransomwareMD5: 3e7f87ff8fba7c78349284a6f4b9838bSHA1: 7d3f3b9cf7834b490f4ebfd7b714de5ba7ac67cbANALYSIS DATE: 2023-07-07T06:43:06ZTTPS: ScoreMeaningExample10Known badA malware family was detected.8-9Likely maliciousOne or more...
Score: 10 MALWARE FAMILY: ransomwareTAGS:ransomware, spyware, stealerMD5: 99a4a7145a78577d18ab6547210e5fecSHA1: 20374dec61f839f1392bab96fc8e71f0e18ff334ANALYSIS DATE: 2023-07-07T06:25:15ZTTPS: T1005, T1081, T1012 ScoreMeaningExample10Known badA malware family was detected.8-9Likely...
Score: 9 MALWARE FAMILY: ransomwareTAGS:ransomwareMD5: e7e442f7f42d61cdebfddc801f4b03dcSHA1: 3b16dbc84446cb30963b4886600b16b4cb545dd7ANALYSIS DATE: 2023-07-07T08:35:42ZTTPS: ScoreMeaningExample10Known badA malware family was detected.8-9Likely maliciousOne or more known damaging...
Score: 10 MALWARE FAMILY: coperTAGS:family:coper, family:octo, banker, evasion, infostealer, ransomware, rat, trojanMD5: 49f67ec7bcfd5d8b01c1fb92820481f5SHA1: 19bf5e03023516b25bd2d0747773186911bdbf2fANALYSIS DATE: 2023-07-07T08:10:51ZTTPS: ScoreMeaningExample10Known badA malware family...
Score: 10 MALWARE FAMILY: gandcrabTAGS:family:gandcrab, backdoor, persistence, ransomwareMD5: 34ab0498c4925a311934b1083c6b5162SHA1: 178039f4f3c93f6b752988b42aa125d5a3e8ea2aANALYSIS DATE: 2023-07-06T15:08:57ZTTPS: T1012, T1082, T1060, T1112, T1120 ScoreMeaningExample10Known badA malware...
Score: 10 MALWARE FAMILY: gandcrabTAGS:family:gandcrab, backdoor, persistence, ransomwareMD5: 34bab29b5836cc7242f064c418184e93SHA1: 1c0c29b08ad128f8d57aa89a47593bc83524ffabANALYSIS DATE: 2023-07-06T15:09:30ZTTPS: T1012, T1082, T1060, T1112, T1120 ScoreMeaningExample10Known badA malware...
Score: 10 MALWARE FAMILY: gandcrabTAGS:family:gandcrab, backdoor, persistence, ransomwareMD5: 350c339d99553a882c4963f1b4694c19SHA1: 3fa5ada4878db4f9d5584ac83ea3f5bb149cfda6ANALYSIS DATE: 2023-07-06T15:10:47ZTTPS: T1060, T1112, T1012, T1120, T1082 ScoreMeaningExample10Known badA malware...
Score: 10 MALWARE FAMILY: evasionTAGS:evasion, persistence, spyware, stealer, trojanMD5: 36f81225cafa18f7b8e822be969801f6SHA1: a156ccdad9ee3e44b66b764bdf937c92e6b124fdANALYSIS DATE: 2023-07-06T15:34:51ZTTPS: T1012, T1082, T1060, T1112, T1088, T1089, T1158,...
Score: 10 MALWARE FAMILY: evasionTAGS:evasion, persistence, spyware, stealer, trojanMD5: 362146d6a410440a779030ad65deabb9SHA1: 454ac225175d472c01dbdec4212e99648f48c413ANALYSIS DATE: 2023-07-06T15:27:18ZTTPS: T1060, T1112, T1158, T1088, T1089, T1082, T1005,...
Score: 10 MALWARE FAMILY: evasionTAGS:evasion, persistence, ransomware, spyware, stealer, trojanMD5: 37924698d48454df2b486429f3f75c8cSHA1: 04a99995340a925fc814198801ef98dc7cb2290cANALYSIS DATE: 2023-07-06T15:39:15ZTTPS: T1082, T1060, T1112, T1158, T1088, T1089,...
Score: 10 MALWARE FAMILY: evasionTAGS:evasion, persistence, spyware, stealer, trojanMD5: 37a26b8eb3e6511ce138660bf3957f38SHA1: ec0dc7e37c95c0b6abf45f98859f9a3441eff7b9ANALYSIS DATE: 2023-07-06T15:39:43ZTTPS: T1005, T1081, T1060, T1112, T1088, T1089, T1158,...
Score: 10 MALWARE FAMILY: evasionTAGS:evasion, persistence, ransomware, spyware, stealer, trojanMD5: 38d5ec0a8454a00e9afc0cdbdcbe473fSHA1: 31976f6600b641081736e2756729fabc1a172d44ANALYSIS DATE: 2023-07-06T15:48:41ZTTPS: T1082, T1005, T1081, T1012, T1060, T1112,...
Score: 10 MALWARE FAMILY: gandcrabTAGS:family:gandcrab, backdoor, persistence, ransomwareMD5: 379e61b50cd1c3e8c07e8a8f47acd5a4SHA1: 87e8ee5de1d993aac78c28e18fa6f7fde155257cANALYSIS DATE: 2023-07-06T15:39:37ZTTPS: T1012, T1082, T1060, T1112, T1120 ScoreMeaningExample10Known badA malware...
Score: 10 MALWARE FAMILY: evasionTAGS:evasion, persistence, ransomware, spyware, stealer, trojanMD5: 38cc2a7b78c1bedcda6c85baacd9e91fSHA1: ed0e33ec80d4a10f19b860dd235a365ba87c5aa4ANALYSIS DATE: 2023-07-06T15:46:30ZTTPS: T1158, T1112, T1088, T1089, T1082, T1005,...
Score: 5 MALWARE FAMILY: evasionTAGS:evasion, ransomwareMD5: 7b18abac83783eb3b1e8786b431cf8c7SHA1: 31608f1eda05aad2006ee281fb383d38c800d789ANALYSIS DATE: 2023-07-06T15:56:51ZTTPS: ScoreMeaningExample10Known badA malware family was detected.8-9Likely maliciousOne or more known...
Score: 10 MALWARE FAMILY: gandcrabTAGS:family:gandcrab, backdoor, persistence, ransomwareMD5: 395556b7d98a99932853e48353613e79SHA1: 1232964b10e0a7783ea1c8233dafb8e53dd05c68ANALYSIS DATE: 2023-07-06T15:51:41ZTTPS: T1012, T1082, T1060, T1112, T1120 ScoreMeaningExample10Known badA malware...
Score: 5 MALWARE FAMILY: ransomwareTAGS:ransomwareMD5: abee9b0674e9ea15654f9b7252891dd2SHA1: ffbae089ab9ae9fa32e5aeb8ba06085996ee74f0ANALYSIS DATE: 2023-07-06T15:57:06ZTTPS: T1491, T1112, T1012, T1082 ScoreMeaningExample10Known badA malware family was detected.8-9Likely maliciousOne...
Score: 10 MALWARE FAMILY: evasionTAGS:evasion, persistence, spyware, stealer, trojanMD5: 38f0592fcb6c2c893adb3ae80e1b9bacSHA1: 9e0e1b27bfac985776f1846c95b33ef156433589ANALYSIS DATE: 2023-07-06T15:50:36ZTTPS: T1005, T1081, T1060, T1112, T1158, T1088, T1089,...
Score: 10 MALWARE FAMILY: gandcrabTAGS:family:gandcrab, backdoor, persistence, ransomwareMD5: 3acfe4bb3b0b134205112e77c6de0196SHA1: 4af9ed029d0c04c625e2af140e934fa26483827aANALYSIS DATE: 2023-07-06T16:07:56ZTTPS: T1060, T1112, T1012, T1120, T1082 ScoreMeaningExample10Known badA malware...
Score: 10 MALWARE FAMILY: evasionTAGS:evasion, persistence, ransomware, spyware, stealer, trojanMD5: 39ee4e0b4f9ad44a5c3707bb5934d450SHA1: 34dcf50c5008dd894e0e808d4b42fbc8751f858bANALYSIS DATE: 2023-07-06T15:59:09ZTTPS: T1005, T1081, T1012, T1082, T1088, T1089,...