Rewterz
Rewterz Threat Alert – SystemBC Malware – Active IOCs
September 6, 2022
Rewterz
Rewterz Threat Alert – STOP/DJVU Ransomware – Active IOCs
September 7, 2022

Rewterz Threat Alert – Conti Ransomware – Active IOCs

Severity

High

Analysis Summary

Conti ransomware was discovered in December 2019 and is delivered via TrickBot. It’s been utilized against large companies and government institutions across the world, especially in North America. Conti steals important files and information from targeted networks and threatens to disseminate it unless the ransom is paid. Conti ransomware enhances performance by utilizing “up to 32 simultaneous encryption operations,” and is very likely directly controlled by its controllers. This ransomware can target network-based resources while ignoring local files. This feature has the noticeable impact of being able to create targeted harm in an environment in a way that might hinder incident response actions.

Impact

  • Sensitive File Theft
  • File Encryption

Indicators of Compromise

MD5

  • 1acdaba338e67c748e56aa81a27a9831

SHA-256

  • b14cde376a8a7a9d7ad34cdfd07108c132ad8be7f60c5c0a0f17b6b63eb28b49

SHA-1

  • 79a708e70747351688a3efdaf3b6ddb4afd24ef2

Remediation

  • Search for IOCs in your environment.
  • Block all threat indicators at your respective controls