Rewterz
Rewterz Threat Advisory – ICS: Hitachi Energy Retail Operations and CSB Software
December 1, 2021
Rewterz
Rewterz Threat Alert – APT21 aka BlackTech Targeting East Asian Countries
December 1, 2021

Rewterz Threat Alert – Phobos Ransomware – Active IOCs

Severity

High

Analysis Summary

Phobos ransomware appeared at the beginning of 2019. It has been noted that this new strain of ransomware is strongly based on the previously known family: Dharma (a.k.a. Crysis), and probably distributed by the same group as Dharma. Phobos is one of the ransomware that is distributed via hacked Remote Desktop (RDP) connections. This isn’t surprising, as hacked RDP servers are a cheap commodity on the underground market, and can make for an attractive and cost-efficient dissemination vector for threat groups. This ransomware does not deploy any techniques of UAC bypass. When we try to run it manually, the UAC confirmation pops up:

Impact

  • File Encryption
  • Data Exfiltration

Indicators of Compromise

SHA-256

  • 3cd8aad9adbe1e1b683163aa4099f8c3a584d736316a229124acf103f57d60aa
  • 9e1fde04ae19c92310aaa1acc1e00a31f73283a137f041e6e3f54470702493d2
  • 57c8c5c356c170575debd6e7df5d958fd56fbceaa6bd8dd4ccb16ba77b2d8011
  • 2bf2b4a5eed3e6f29932258988c93ba4f22cb07a189ddf3837ff132fb715df6d

Remediation

  • Block all threat indicators at your respecitive controls.
  • Search for IOCs in your environment.