Magniber ransomware: exclusively for South Koreans
2017-10-17 • Malwarebytes •
https://www.malwarebytes.com/blog/news/2017/10/magniber-ransomware-exclusively-for-south-koreans
Magnitude exploit kit resurfaced with Magniber, a previously unknown ransomware family that was observed being dropped only through that exploit kit at the time of analysis. The ransomware applied multiple South Korea-specific checks, including public IP and installed language, and deleted itself on non-Korean systems. On accepted systems it copied itself to the temp directory, used scheduled tasks for deployment, encrypted many file types, and displayed a minimal TXT ransom note. Its generated domains served both command-and-control requests and victim payment pages, with example paths such as /new1 and /end1 returning 16-character strings only under expected conditions. The targeting logic and country-gated server responses made the campaign unusually selective for ransomware operations.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | b89df665e6d52446e3e353fc1cc44711 | 2017-10-17 | 2017-10-17 |
| HASH | ef70f414106ab23358c6734c434cb7dd | 2017-10-17 | 2017-10-17 |
| HASH | 9bb96afdce48fcf9ba9d6dda2e23c93… | 2017-10-17 | 2017-10-17 |
| HASH | 8968c1b7a7aa95931fcd9b72cdde841… | 2017-10-17 | 2017-10-17 |
| HASH | aa8f077a5feeb9fa9dcffd3c69724c9… | 2017-10-17 | 2017-10-17 |