Gwisin 랜섬웨어 공격자의 침투 및 배포 방법

2022-11-01 Ahnlab Gwisin ransomware attackers' infiltration and distribution methods

https://asec.ahnlab.com/ko/41084/

Thumbnail for Gwisin 랜섬웨어 공격자의 침투 및 배포 방법

AhnLab describes Gwisin ransomware intrusions in which attackers compromised externally exposed servers and used them as footholds to distribute ransomware inside victim networks. The report says the actors appeared to scan exposed web servers and attempt SQL injection to steal system credentials, then used web shells and Python reverse shells for access. After compromising Linux systems, they installed Nmap for internal scanning, dumped LSASS memory on Windows systems to obtain credentials, and used reverse connections for internal control. For deployment, the attackers installed IIS on a controlled system, placed Windows and Linux ransomware packages under the web root, and distributed them to internal hosts.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 13eef02d5e5f5543e83ad8c8a8c8ff9a 2022-11-01 2022-11-01
IPv4 158.247.221.23 2022-11-01 2022-11-01
HASH 95237d0c6e6b1822cecca34994c0d273 2022-08-24 2022-11-01

Related Reports

« Back