Magniber Ransomware Wants to Infect Only the Right People

2017-10-19 Mandiant

https://www.mandiant.com/resources/blog/magniber-ransomware-infects-only-the-right-people

Thumbnail for Magniber Ransomware Wants to Infect Only the Right People

Magniber samples examined by Mandiant targeted Korean systems and would not continue execution when the system language was not Korean. The analyzed campaign used ransomware payloads with the same behavior and infection vector as samples reported by Trend Micro, including AES128 encryption of user data. The sample dc2a2b84da359881b9df1ec31d03c715 carried a binary payload in its resource section and unpacked it in memory using reverse RC4 decryption. The report provides the RC4 key material for that sample and notes that the unpacked payload begins execution only after the locale check is satisfied. These details help defenders identify Magniber behavior beyond hashes by focusing on resource unpacking, language-gated execution, and ransomware encryption flow.

Indicators of Compromise

Type Value First Seen Last Seen
HASH dc2a2b84da359881b9df1ec31d03c715 2017-10-19 2017-10-19
DOMAIN fastprofit.me 2017-10-19 2017-10-19
DOMAIN 4bg8l9095z0287fm1j5.bankme.date 2017-10-19 2017-10-19
DOMAIN j2a3y50mi0a487230v1.bankme.date 2017-10-19 2017-10-19
DOMAIN 7o12813k90oggw10277.bankme.date 2017-10-19 2017-10-19

Related Reports

« Back