Magniber ransomware: exclusively for South Koreans

2017-10-17 Malwarebytes

https://www.malwarebytes.com/blog/news/2017/10/magniber-ransomware-exclusively-for-south-koreans

Thumbnail for Magniber ransomware: exclusively for South Koreans

Magnitude exploit kit resurfaced with Magniber, a previously unknown ransomware family that was observed being dropped only through that exploit kit at the time of analysis. The ransomware applied multiple South Korea-specific checks, including public IP and installed language, and deleted itself on non-Korean systems. On accepted systems it copied itself to the temp directory, used scheduled tasks for deployment, encrypted many file types, and displayed a minimal TXT ransom note. Its generated domains served both command-and-control requests and victim payment pages, with example paths such as /new1 and /end1 returning 16-character strings only under expected conditions. The targeting logic and country-gated server responses made the campaign unusually selective for ransomware operations.

Indicators of Compromise

Type Value First Seen Last Seen
HASH b89df665e6d52446e3e353fc1cc44711 2017-10-17 2017-10-17
HASH ef70f414106ab23358c6734c434cb7dd 2017-10-17 2017-10-17
HASH 9bb96afdce48fcf9ba9d6dda2e23c93… 2017-10-17 2017-10-17
HASH 8968c1b7a7aa95931fcd9b72cdde841… 2017-10-17 2017-10-17
HASH aa8f077a5feeb9fa9dcffd3c69724c9… 2017-10-17 2017-10-17

Related Reports

« Back