

Rewterz Threat Alert – Trickbot malware – Active IOCs
December 19, 2022
Rewterz Threat Alert – Mirai Botnet aka Katana – Active IOCs
December 20, 2022
Rewterz Threat Alert – Trickbot malware – Active IOCs
December 19, 2022
Rewterz Threat Alert – Mirai Botnet aka Katana – Active IOCs
December 20, 2022Severity
High
Analysis Summary
Conti ransomware was discovered in December 2019 and is delivered via TrickBot. It’s been utilized against large companies and government institutions across the world, especially in North America. Conti steals important files and information from targeted networks and threatens to disseminate it unless the ransom is paid. Conti ransomware enhances performance by utilizing “up to 32 simultaneous encryption operations,” and is very likely directly controlled by its controllers. This ransomware can target network-based resources while ignoring local files. This feature has the noticeable impact of being able to create targeted harm in an environment in a way that might hinder incident response actions.
Impact
- Sensitive File Theft
- File Encryption
Indicators of Compromise
MD5
- 7c97284ac8ce095d1a48d24c5a9e98c1
- fbbb40defd1c971112be14f1de681c0c
SHA-256
- bcf49782d7dc8c7010156b31d3d56193d751d0dbfa2abbe7671bcf31f2cb190a
- a4337294dc51518284641982a28df585ede9b5f0e3f86be3c2c6bb5ad766a50f
SHA-1
- 2d429e2eb99cdfe08961b826ffdd4357aa9d2e24
- 88902d65274f40f3dd180c25d38f4bfec5cdeac1
Remediation
- Search for IOCs in your environment.
- Block all threat indicators at your respective controls.