Hermes ransomware distributed to South Koreans via recent Flash zero-day
2018-03-14 • Malwarebytes •
Malwarebytes observed Hermes ransomware being delivered to South Korean users through a compromised Korean website and the Magnitude exploit kit using the Flash zero-day CVE-2018-4878. The infection chain used malicious redirection hidden in page source code with Base64 and RC4 encoding, then deployed Hermes 2.1 as the payload. Hermes copied itself into temporary locations, used Startup-folder persistence through a batch script, created the mutex "tech," skipped systems using Russian, Belarusian, or Ukrainian language settings, and encrypted local and network-accessible files. The ransomware generated per-victim RSA material, appended a HERMES marker and encrypted session-key blob to files, dropped ransom material under C:\Users\Public, and aggressively deleted shadow copies and backup files. The targeting of South Korean users and prior reporting around Hermes make the campaign relevant to DPRK-focused tracking, while the excerpt does not provide enough evidence to assert attribution beyond the source's cautious references.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | a5a0964b1308fdb0aeb8bd5b2a0f306… | 2018-03-14 | 2018-03-14 |
| HASH | 237eee069c1df7b69cee2cc63dee24e6 | 2018-03-14 | 2018-03-14 |
| [email protected] | 2018-03-14 | 2018-03-14 | |
| [email protected] | 2018-03-14 | 2018-03-14 | |
| DOMAIN | name.secondadvertisements.com | 2018-03-14 | 2018-03-14 |
| DOMAIN | bannerssale.com | 2018-03-14 | 2018-03-14 |
| DOMAIN | hunting.bannerexposure.info | 2018-03-14 | 2018-03-14 |
| DOMAIN | switzerland.innovativebanner.in… | 2018-03-14 | 2018-03-14 |
| DOMAIN | accompanied.bannerexposure.info | 2018-03-14 | 2018-03-14 |
| DOMAIN | technologies.roadadvertisements… | 2018-03-14 | 2018-03-14 |
| DOMAIN | keemail.me | 2018-03-14 | 2018-03-14 |
| DOMAIN | staradvertsment.com | 2018-03-14 | 2018-03-14 |
| DOMAIN | aquaadvertisement.com | 2018-03-14 | 2018-03-14 |
| DOMAIN | marketing.roadadvertisements.com | 2018-03-14 | 2018-03-14 |
| DOMAIN | assessed.secondadvertisements.c… | 2018-03-14 | 2018-03-14 |
| IPv4 | 207.148.104.5 | 2018-03-14 | 2018-03-14 |
| IPv4 | 159.65.131.94 | 2018-03-14 | 2018-03-14 |
| IPv4 | 28.0.0.137 | 2018-02-02 | 2018-03-14 |