Advertisement
Bank_Security

Malspam pushing Sigma ransomware

Mar 14th, 2018
677
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.88 KB | None | 0 0
  1. Malspam pushing Sigma ransomware
  2.  
  3. Indicators
  4.  
  5. See below for a list of URLs, domains, and file hashes associated with this malspam.
  6.  
  7. SHA256 hashes for all attachments:
  8.  
  9. f504eaea0e389859e38156255661e879def47fb3a667f032fa06b7dfb84276de - Alane Resume.doc
  10. e8e485a340a56774ee7c83bbc2be48e4185ed1aeefd17e45f75e445cdb561d8a - Becki Resume.doc
  11. cfba52ab5d939ba45d38179b743a98832f76eb091d37b6e6f2784e95b58eb566 - Beth Resume.doc
  12. 9793bef2fa003523961862973b946f09f51005b8ac15bfe3a080d7922fa37ee3 - Braidy Resume.doc
  13. a27328898c137448a745dc37855881dd22aa15d3502b2f2f578fe4d8d6a60b71 - Deandra Resume.doc
  14. 5d7a4340695f91d50658cc45a815c1f57998c3eb96eb313f5bfe11c135a1f2ad - Eva Resume.doc
  15. 5fc458775799db577eafc6fb52e8a42ca3938beed8877a76a5b71f02518a9795 - Felicia Resume.doc
  16. 58510fbc104d73199361b1bfb93cc44c86f64f422ba04df1b29dd96ba3402f8a - Gary Resume.doc
  17. c7b041e0f7b34a8ac2a2cdb5e55bf3cc72d9cbcd22a453a78338754914824a0f - Kiaran Resume.doc
  18. 3fa03e6adab2c240c9da3bf51509453e946be78cc75200e177aae969ce44f0fd - Lorne Resume.doc
  19. The following are malware samples retrieved from my infected lab host:
  20.  
  21. SHA256 hash: cd25aa002c73bfb68e0c952d8be90b5380a56972e9d3d90f0769a3a312e687cc
  22. File size: 3,207,168 bytes
  23. File location: C:\Users\[username]\AppData\Roaming\BITF881.tmp
  24. SHA256 hash: cbbb8b1b14b3df9d331ece7167ca9ab2b7da61839742a107142016d8d9c6f8e8
  25. File size: 3,207,168 bytes
  26. File location: C:\Users\[username]\AppData\Roaming\taskwgr.exe
  27. File location: C:\Users\[username]\AppData\Roaming\Microsoft\[ransom ID]\taskwgr.exe
  28.  
  29. The following are URLs and domains associated with these infections:
  30.  
  31. 120.132.8.132 port 80 - onlinedocuments.ir - GET /email.bin (ransomware binary)
  32. port 80 - ip-api.com - GET /json (IP check, not inherently malicious)
  33. various IP addresses - various TCP ports - tor traffic
  34. yowl2ugopitfzzwb.onion.link (HTTP link for Sigma decryptor)
  35. yowl2ugopitfzzwb.onion (tor address for Sigma decryptor)
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement