Magniber ransomware improves, expands within Asia

2018-07-15 Malwarebytes

https://www.malwarebytes.com/blog/news/2018/07/magniber-ransomware-improves-expands-within-asia

Thumbnail for Magniber ransomware improves, expands within Asia

Magnitude exploit kit campaigns evolved from South Korea-focused Magniber delivery to a broader Asia-Pacific targeting pattern. The infection chain used Magnigate redirection, obfuscated JavaScript, Base64-encoded VBScript, and exploitation of Internet Explorer CVE-2018-8174 before downloading an XOR-obfuscated Magniber payload. The downloaded component acted as a loader that unpacked and injected the Magniber core DLL, after which the ransomware encrypted files and dropped a README.txt ransom note. Newer Magniber versions added stronger obfuscation, dynamic API resolution by checksums, reflective loading, per-file AES keys protected by a hardcoded RSA public key, and expanded language checks covering additional Asian locales. Reported infrastructure included Magnigate, Magnitude EK, and Magniber hosts such as 178.32.62[.]130, 94.23.165[.]192, 92.222.121[.]30, and 149.202.112[.]72.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 60af42293d2dbd0cc8bf1a008e06f394 2018-07-15 2018-07-15
HASH 8a0244eedee8a26139bea287a7e419d9 2018-07-15 2018-07-15
HASH 7fb69fbd045315b42d7f962a83fdc300 2018-07-15 2018-07-15
HASH 72fce87a976667a8c09ed844564adc75 2018-07-15 2018-07-15
HASH 6e57159209611f2531104449f4bb86a… 2018-07-15 2018-07-15
HASH fb6c80ae783c1881487f2376f5cace7… 2018-07-15 2018-07-15
HASH 19599cad1bbca18ac6473e64710443b7 2018-07-15 2018-07-15
IPv4 178.32.62.130 2018-07-15 2018-07-15
IPv4 94.23.165.192 2018-07-15 2018-07-15
IPv4 149.202.112.72 2018-07-15 2018-07-15
IPv4 92.222.121.30 2018-07-15 2018-07-15

Related Reports

« Back