Rewterz
Rewterz Threat Alert – Nemty Ransomware Delivered via Trik Botnet Using SMB Protocol
November 6, 2019
Rewterz
Rewterz Threat Alert – Crafted ZIP Files Bypass Secure Email Gateways to Drop Nanocore
November 7, 2019

Rewterz Threat Alert – Everis Bitpaymer Ransomware – IOC’s

Severity

High

Analysis Summary

Bitpaymer Ransomware dropped using Powershell and malware packed with the Dridex Crypter. First reported on November 4, 2019, an unattributed threat actor conducted a ransomware attack on at least two confirmed Spanish networks, Everis, an IT consulting firm, and SER, Spain’s largest radio network. Open source reporting indicated that the attacker demanded approximately $835,000 USD in ransom for the decryptor.

Image result for Everis Bitpaymer Ransomware

Impact

File encryption

Indicators of Compromise

Hostname

click[.]clickanalytics208[.]com

IP

  • 185[.]92[.]74[.]215
  • 45[.]129[.]96[.]9
  • 195[.]123[.]213[.]19
  • 195[.]123[.]238[.]51

MD5

d0409052256c6efc85b155f58cc03f70

SH256

  • 794093ea46b083ce3fac466d726aab7d5b013cd84d81e3e4c1c65aabc13c440c
  • 1d778359ab155cb190b9f2a7086c3bcb4082aa195ff8f754dae2d665fd20aa05
  • bd327754f879ff15b48fc86c741c4f546b9bbae5c1a5ac4c095df05df696ec4f
  • 628c181e6b9797d8356e43066ae182a45e6c37dbee28d9093df8f0825c342d4c

URL

  • http[:]//45[.]129[.]96[.]9[:]443
  • http[:]//195[.]123[.]238[.]51[:]443
  • http[:]//195[.]123[.]213[.]19[:]443
  • https[:]//esancendoc[.]esan[.]edu[.]pe/
  • https[:]//click[.]clickanalytics208[.]com/s_code[.]js?cid=240&v=73a55f6de3dee2a751c3

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails about sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.