Rewterz Threat Alert : ‘Love You’ MalSpam campaign dropping Grandcrab Ransomware, Phorpiex Spambot and Cryptocurrency miner - Rewterz
Common Information
Type Value
UUID 5eabe848-5217-440e-8e05-b4fbfa3ce13b
Fingerprint 87b124f12696be4b
Analysis status DONE
Considered CTI value 2
Text language
Published Jan. 15, 2019, 5:42 p.m.
Added to db Dec. 19, 2024, 11:04 a.m.
Last updated Dec. 24, 2024, 2:02 a.m.
Headline Rewterz Threat Alert : ‘Love You’ MalSpam campaign dropping Grandcrab Ransomware, Phorpiex Spambot and Cryptocurrency miner
Title Rewterz Threat Alert : ‘Love You’ MalSpam campaign dropping Grandcrab Ransomware, Phorpiex Spambot and Cryptocurrency miner - Rewterz
Detected Hints/Tags/Attributes 24/2/53
Attributes
Details Type #Events CTI Value
Details CVE 3
cve-2015-1283
Details Domain 67
icanhazip.com
Details Domain 3
slpsrgpsrhojifdij.ru
Details Domain 5
osheoufhusheoghuesd.ru
Details Domain 3
suieiusiueiuiuushgf.ru
Details Domain 4
www.2mmotorsport.biz
Details Domain 3
www.haargenau.biz
Details Domain 3
www.bizziniinfissi.com
Details Domain 3
www.holzbock.biz
Details Domain 2
www.fliptray.biz
Details Domain 8
gandcrabmfe6mnef.onion
Details Domain 1
8038.com
Details Domain 1
0354.com
Details Domain 1
1529.com
Details Domain 1
4302.com
Details Domain 1
5387.com
Details Domain 1
0437.com
Details Domain 1
8381.com
Details Domain 1
2804.com
Details Domain 1
4656.com
Details Domain 1
1659.com
Details Domain 87
rewterz.com
Details Email 54
soc@rewterz.com
Details sha256 2
72429571f4ca62fceb5a4fc0a17a8f8ab88c1ed01b9d657f7e9778c7939cea06
Details sha256 2
27ac0e9011294c2152d224052280f7fa434df572809a6f96f9a306f3d5c965e3
Details sha256 2
99a1e83e77850b59995cdf29b61e9f29f9c38882363027668030df0a62059645
Details sha256 2
06e61032bccfe0ccd51ddbab480e1eb6392bccb318639ecac0092e96b9d794ad
Details sha256 2
7818e108a16f096eb71feb564ce92095c4ac1e613933630169cc16606bb5f68d
Details sha256 2
0a27af16b991cbe0f5445022cb1d752a9144abeede6b8de0055247e6fd6c1698
Details sha256 2
32ee086fbc82ddd0675c0293656f813493ce6d96d02e0bcbeccee4d1a6adfb20
Details sha256 2
12e3038b2ed0663cba3c6a05ac0a27b61dce694dffc27aafb4cb3f2f229ff6b8
Details sha256 2
6ad3e68e2e8c5088bc8544bc230a2e333645d3c246ace772bf61f80cd0e93002
Details sha256 2
99fe714a365f8e4a74687592700b27f2016a59c7527b5d4ef7cfd97e63468349
Details sha256 2
d189f44528dfa3f8dba2632ae26f564a37931cb89668d31402fc7fb05ae63c1a
Details sha256 2
c3683096f91b00dfe248e388b4302d5471fb090ab8092c96c991a467c26f26b0
Details sha256 2
f3c369edc2ea96465c49a14f64bdce83c0a401e0ae12e809bced8f99b977c5dc
Details sha256 2
f4d3ba58e91dc95877ba13804df6fe307ef6efcef74d3a00792387625a624cf4
Details sha256 2
9ff78056e225c08ef1f1ff71f305201387f3ec766c8727361851287a74de1f45
Details sha256 2
ba23af4480611fb19fad2cd83a41bd347d183e0ef8e1c5477916bebe32955d87
Details sha256 2
cf9a20874089ec7aa1a84a27f74928c71266a684e7fee4c1ac8d37aaf57d6bf2
Details sha256 2
0de30f9dbe37aea5932e5df85b4f1aa5cefe28f3bffb58d4d8ae40ccd040a4a7
Details sha256 2
056b7eb0c06645e1f51ed77f4fa18a4bed47135108371a84f0482f141ae0d769
Details sha256 2
035ae8f389e0a4cb58428d892123bc3e3b646e4387c641e664c5552228087285
Details sha256 2
b8bf5b607b305139db81c48e96010a67768488b01edc8c615306ed303c545b0d
Details sha256 2
4b9d5841d38b8658466dcaf409c34c0f6d2d1f9ecb64254391a4621465daf79b
Details sha256 2
4c0103c745fa6e173821035c304863d751bea9c073d19070d9ebf8685da95040
Details IPv4 7
92.63.197.48
Details IPv4 2
198.105.244.228
Details IPv4 2
78.46.77.98
Details IPv4 2
217.26.53.161
Details IPv4 2
74.220.215.73
Details IPv4 3
136.243.13.215
Details IPv4 2
138.201.162.99