Severity
High
Analysis Summary
Bitpaymer Ransomware dropped using Powershell and malware packed with the Dridex Crypter. First reported on November 4, 2019, an unattributed threat actor conducted a ransomware attack on at least two confirmed Spanish networks, Everis, an IT consulting firm, and SER, Spain’s largest radio network. Open source reporting indicated that the attacker demanded approximately $835,000 USD in ransom for the decryptor.
Impact
File encryption
Indicators of Compromise
Hostname
click[.]clickanalytics208[.]com
IP
- 185[.]92[.]74[.]215
- 45[.]129[.]96[.]9
- 195[.]123[.]213[.]19
- 195[.]123[.]238[.]51
MD5
d0409052256c6efc85b155f58cc03f70
SH256
- 794093ea46b083ce3fac466d726aab7d5b013cd84d81e3e4c1c65aabc13c440c
- 1d778359ab155cb190b9f2a7086c3bcb4082aa195ff8f754dae2d665fd20aa05
- bd327754f879ff15b48fc86c741c4f546b9bbae5c1a5ac4c095df05df696ec4f
- 628c181e6b9797d8356e43066ae182a45e6c37dbee28d9093df8f0825c342d4c
URL
- http[:]//45[.]129[.]96[.]9[:]443
- http[:]//195[.]123[.]238[.]51[:]443
- http[:]//195[.]123[.]213[.]19[:]443
- https[:]//esancendoc[.]esan[.]edu[.]pe/
- https[:]//click[.]clickanalytics208[.]com/s_code[.]js?cid=240&v=73a55f6de3dee2a751c3
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails about sent by unknown senders.
- Never click on the links/attachments sent by unknown senders.