Mallox Ransomware Implements New Infection Strategy
Common Information
Type Value
UUID f2c1e558-2f32-4d96-a631-9f655188734e
Fingerprint a6c3a3f00c7783c5
Analysis status DONE
Considered CTI value 2
Text language
Published June 22, 2023, midnight
Added to db Oct. 24, 2023, 1:19 p.m.
Last updated Nov. 17, 2024, 6:56 p.m.
Headline Mallox Ransomware Implements New Infection Strategy
Title Mallox Ransomware Implements New Infection Strategy
Detected Hints/Tags/Attributes 82/4/30
RSS Feed
Attributes
Details Type #Events CTI Value
Details Domain 4
whyers.io
Details File 149
msbuild.exe
Details File 1
c:\users\user_name\desktop\ransomware.bat
Details File 1208
powershell.exe
Details File 1
c:\users\user_name \desktop\ransomware.bat
Details File 1
ransomware.bat
Details File 3
killerrr.bat
Details File 11
ap.php
Details File 3
tst.bat
Details md5 4
dcf060e00547cfe641eff3f836ec08c8
Details md5 2
9a239885dc7044a9289610d58585167b
Details sha1 2
8054569d8b449e4cd0211cb2499c19f42557fb21
Details sha1 2
28b8b4c9fe29ba0e815e525d2529b92217877e85
Details sha256 2
5158b0a023299c1922423a065b9825fd1769f1a87ffd2031375a0e893d523318
Details sha256 2
0de0da8037176c3c9cb403e2865a7699e53ff5a013070132ba512b9dab7a0126
Details IPv4 10
80.66.75.116
Details MITRE ATT&CK Techniques 420
T1204
Details MITRE ATT&CK Techniques 504
T1140
Details MITRE ATT&CK Techniques 235
T1562
Details MITRE ATT&CK Techniques 265
T1222
Details MITRE ATT&CK Techniques 107
T1564
Details MITRE ATT&CK Techniques 348
T1036
Details MITRE ATT&CK Techniques 247
T1070
Details MITRE ATT&CK Techniques 1006
T1082
Details MITRE ATT&CK Techniques 585
T1083
Details MITRE ATT&CK Techniques 472
T1486
Details MITRE ATT&CK Techniques 444
T1071
Details Url 3
https://whyers.io/qwewqdsvsf/ap.php
Details Url 1
http://whyers.io/qwewqdsvsf/ap.php
Details Url 3
http://80.66.75.116/tst.bat