Surtr Ransomware Being Distributed in Korea - ASEC BLOG
Tags
attack-pattern: | Malware - T1587.001 Malware - T1588.001 Server - T1583.004 Server - T1584.004 Software - T1592.002 |
Common Information
Type | Value |
---|---|
UUID | de08b822-305e-4460-a750-58d34157e23d |
Fingerprint | b406a8f94ef6925d |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Nov. 3, 2022, 2:23 p.m. |
Added to db | Nov. 7, 2022, 7:40 p.m. |
Last updated | Nov. 17, 2024, 6:55 p.m. |
Headline | Surtr Ransomware Being Distributed in Korea |
Title | Surtr Ransomware Being Distributed in Korea - ASEC BLOG |
Detected Hints/Tags/Attributes | 32/1/18 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://asec.ahnlab.com/en/41092/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 17 | ✔ | ASEC | https://asec.ahnlab.com/en/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 58 | mailfence.com |
|
Details | Domain | 95 | ip-api.com |
|
Details | 1 | dycriptersupp@mailfence.com |
||
Details | File | 1 | surtr_readme.txt |
|
Details | File | 345 | vssadmin.exe |
|
Details | File | 18 | fsutil.exe |
|
Details | File | 43 | wbadmin.exe |
|
Details | File | 249 | schtasks.exe |
|
Details | md5 | 1 | ad539ebdf9e34e02be487134cf9a6713 |
|
Details | md5 | 1 | e31b96b8a74075935360b5e5a18926e9 |
|
Details | md5 | 2 | 674e7ee905d24a89af47b53b53ffc23c |
|
Details | Windows Registry Key | 1 | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
|
Details | Windows Registry Key | 1 | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum |
|
Details | Windows Registry Key | 1 | HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRE |
|
Details | Windows Registry Key | 2 | HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows |
|
Details | Windows Registry Key | 1 | HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Backup\Client |
|
Details | Windows Registry Key | 1 | HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Backup\Server |
|
Details | Windows Registry Key | 1 | HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System |