Magniber Ransomware Wants to Infect Only the Right People
2017-10-19 • Mandiant •
https://www.mandiant.com/resources/blog/magniber-ransomware-infects-only-the-right-people
Magniber samples examined by Mandiant targeted Korean systems and would not continue execution when the system language was not Korean. The analyzed campaign used ransomware payloads with the same behavior and infection vector as samples reported by Trend Micro, including AES128 encryption of user data. The sample dc2a2b84da359881b9df1ec31d03c715 carried a binary payload in its resource section and unpacked it in memory using reverse RC4 decryption. The report provides the RC4 key material for that sample and notes that the unpacked payload begins execution only after the locale check is satisfied. These details help defenders identify Magniber behavior beyond hashes by focusing on resource unpacking, language-gated execution, and ransomware encryption flow.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | dc2a2b84da359881b9df1ec31d03c715 | 2017-10-19 | 2017-10-19 |
| DOMAIN | fastprofit.me | 2017-10-19 | 2017-10-19 |
| DOMAIN | 4bg8l9095z0287fm1j5.bankme.date | 2017-10-19 | 2017-10-19 |
| DOMAIN | j2a3y50mi0a487230v1.bankme.date | 2017-10-19 | 2017-10-19 |
| DOMAIN | 7o12813k90oggw10277.bankme.date | 2017-10-19 | 2017-10-19 |