Gwisin 랜섬웨어 공격자의 침투 및 배포 방법
2022-11-01 • Ahnlab • Gwisin ransomware attackers' infiltration and distribution methods •
AhnLab describes Gwisin ransomware intrusions in which attackers compromised externally exposed servers and used them as footholds to distribute ransomware inside victim networks. The report says the actors appeared to scan exposed web servers and attempt SQL injection to steal system credentials, then used web shells and Python reverse shells for access. After compromising Linux systems, they installed Nmap for internal scanning, dumped LSASS memory on Windows systems to obtain credentials, and used reverse connections for internal control. For deployment, the attackers installed IIS on a controlled system, placed Windows and Linux ransomware packages under the web root, and distributed them to internal hosts.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 13eef02d5e5f5543e83ad8c8a8c8ff9a | 2022-11-01 | 2022-11-01 |
| IPv4 | 158.247.221.23 | 2022-11-01 | 2022-11-01 |
| HASH | 95237d0c6e6b1822cecca34994c0d273 | 2022-08-24 | 2022-11-01 |