Surtr Ransomware Being Distributed in Korea - ASEC BLOG
Common Information
Type Value
UUID de08b822-305e-4460-a750-58d34157e23d
Fingerprint b406a8f94ef6925d
Analysis status DONE
Considered CTI value 2
Text language
Published Nov. 3, 2022, 2:23 p.m.
Added to db Nov. 7, 2022, 7:40 p.m.
Last updated Nov. 17, 2024, 6:55 p.m.
Headline Surtr Ransomware Being Distributed in Korea
Title Surtr Ransomware Being Distributed in Korea - ASEC BLOG
Detected Hints/Tags/Attributes 32/1/18
Source URLs
RSS Feed
Attributes
Details Type #Events CTI Value
Details Domain 58
mailfence.com
Details Domain 95
ip-api.com
Details Email 1
dycriptersupp@mailfence.com
Details File 1
surtr_readme.txt
Details File 345
vssadmin.exe
Details File 18
fsutil.exe
Details File 43
wbadmin.exe
Details File 249
schtasks.exe
Details md5 1
ad539ebdf9e34e02be487134cf9a6713
Details md5 1
e31b96b8a74075935360b5e5a18926e9
Details md5 2
674e7ee905d24a89af47b53b53ffc23c
Details Windows Registry Key 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer
Details Windows Registry Key 1
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\NonEnum
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WinRE
Details Windows Registry Key 2
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Backup\Client
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Backup\Server
Details Windows Registry Key 1
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\WMI\Autologger\EventLog-System