BlackBit Ransomware Being Distributed in Korea - ASEC BLOG
Common Information
Type Value
UUID 29812ed4-e976-47bd-8c7e-8f428117b381
Fingerprint 84f2ea6b40f78249
Analysis status DONE
Considered CTI value 0
Text language
Published April 20, 2023, 8:27 a.m.
Added to db April 20, 2023, 1:44 a.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline BlackBit Ransomware Being Distributed in Korea
Title BlackBit Ransomware Being Distributed in Korea - ASEC BLOG
Detected Hints/Tags/Attributes 34/1/9
Source URLs
RSS Feed
Attributes
Details Type #Events CTI Value
Details File 1122
svchost.exe
Details File 10
winlogin.exe
Details File 409
c:\windows\system32\cmd.exe
Details File 2
c:\users\rapit\appdata\roaming\winlogon.exe
Details File 351
recycle.bin
Details File 38
restore-my-files.txt
Details md5 2
3a7c3e8a378cd7a4fd83910937c23b19
Details Windows Registry Key 13
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System
Details Windows Registry Key 22
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows