Hermes ransomware distributed to South Koreans via recent Flash zero-day

2018-03-14 Malwarebytes

https://blog.malwarebytes.com/threat-analysis/2018/03/hermes-ransomware-distributed-to-south-koreans-via-recent-flash-zero-day/

Thumbnail for Hermes ransomware distributed to South Koreans via recent Flash zero-day

Malwarebytes observed Hermes ransomware being delivered to South Korean users through a compromised Korean website and the Magnitude exploit kit using the Flash zero-day CVE-2018-4878. The infection chain used malicious redirection hidden in page source code with Base64 and RC4 encoding, then deployed Hermes 2.1 as the payload. Hermes copied itself into temporary locations, used Startup-folder persistence through a batch script, created the mutex "tech," skipped systems using Russian, Belarusian, or Ukrainian language settings, and encrypted local and network-accessible files. The ransomware generated per-victim RSA material, appended a HERMES marker and encrypted session-key blob to files, dropped ransom material under C:\Users\Public, and aggressively deleted shadow copies and backup files. The targeting of South Korean users and prior reporting around Hermes make the campaign relevant to DPRK-focused tracking, while the excerpt does not provide enough evidence to assert attribution beyond the source's cautious references.

Indicators of Compromise

Type Value First Seen Last Seen
HASH a5a0964b1308fdb0aeb8bd5b2a0f306… 2018-03-14 2018-03-14
HASH 237eee069c1df7b69cee2cc63dee24e6 2018-03-14 2018-03-14
EMAIL [email protected] 2018-03-14 2018-03-14
EMAIL [email protected] 2018-03-14 2018-03-14
DOMAIN name.secondadvertisements.com 2018-03-14 2018-03-14
DOMAIN bannerssale.com 2018-03-14 2018-03-14
DOMAIN hunting.bannerexposure.info 2018-03-14 2018-03-14
DOMAIN switzerland.innovativebanner.in… 2018-03-14 2018-03-14
DOMAIN accompanied.bannerexposure.info 2018-03-14 2018-03-14
DOMAIN technologies.roadadvertisements… 2018-03-14 2018-03-14
DOMAIN keemail.me 2018-03-14 2018-03-14
DOMAIN staradvertsment.com 2018-03-14 2018-03-14
DOMAIN aquaadvertisement.com 2018-03-14 2018-03-14
DOMAIN marketing.roadadvertisements.com 2018-03-14 2018-03-14
DOMAIN assessed.secondadvertisements.c… 2018-03-14 2018-03-14
IPv4 207.148.104.5 2018-03-14 2018-03-14
IPv4 159.65.131.94 2018-03-14 2018-03-14
IPv4 28.0.0.137 2018-02-02 2018-03-14

Related Reports

« Back