Bitcoin Forum
May 11, 2024, 07:44:28 AM *
News: Latest Bitcoin Core release: 27.0 [Torrent]
 
   Home   Help Search Login Register More  
Pages: [1]
  Print  
Author Topic: {Warning}: New Avaddon Ransomware relaunch with IMG attachment  (Read 548 times)
Baofeng (OP)
Legendary
*
Offline Offline

Activity: 2590
Merit: 1658



View Profile
June 10, 2020, 09:48:42 AM
Last edit: June 10, 2020, 10:01:56 AM by Baofeng
Merited by TravelMug (1), DdmrDdmr (1)
 #1



Previous attack uses just a wink smiley face attachment. But this time, the new attack vector is spreading thru emails with IMG<number>.jpg.js.zip format. It is reported that since 300,000 messages have been filter out and growing.

How are you infected (if you extracted the file):

  • launches Windows scripting host to run a command launching PowerShell with the execution policy bypass flag.
  • A file named sava.exe is then downloaded from the IP of 217[.]8[.]117[.]63 into the local temp folder and saved as 5203508738.exe, before it’s executed.

The ransom note:



You will be given then a 7 day window to pay the ransom, $600 via BTC.

Quote
Indicators of Compromise

Main object  "IMG126172.jpg.js"
    sha256    cc4d665c468bcb850baf9baab764bb58e8b0ddcb8a8274b6335db5af86af72fb    
Dropped Executable File
    sha256    05af0cf40590aef24b28fa04c6b4998b7ab3b7f26e60c507adb84f3d837778f2    
Malicious IP Connection        217.8.117[.]63

https://appriver.com/resources/blog/june-2020/phorphiextrik-botnet-delivers-avaddon-ransomware



So if you received any suspicious emails specially with this attachments, permanently removed it from you inbox.

███████████████████████
████████████████████
██████████████████
████████████████████
███▀▀▀█████████████████
███▄▄▄█████████████████
██████████████████████
██████████████████████
███████████████████████
█████████████████████
███████████████████
███████████████
████████████████████████
███████████████████████████
███████████████████████████
███████████████████████████
█████████▀▀██▀██▀▀█████████
█████████████▄█████████████
███████████████████████
████████████████████████
████████████▄█▄█████████
████████▀▀███████████
██████████████████
▀███████████████████▀
▀███████████████▀
█████████████████████████
O F F I C I A L   P A R T N E R S
▬▬▬▬▬▬▬▬▬▬
ASTON VILLA FC
BURNLEY FC
BK8?.
..PLAY NOW..
1715413468
Hero Member
*
Offline Offline

Posts: 1715413468

View Profile Personal Message (Offline)

Ignore
1715413468
Reply with quote  #2

1715413468
Report to moderator
Advertised sites are not endorsed by the Bitcoin Forum. They may be unsafe, untrustworthy, or illegal in your jurisdiction.
1715413468
Hero Member
*
Offline Offline

Posts: 1715413468

View Profile Personal Message (Offline)

Ignore
1715413468
Reply with quote  #2

1715413468
Report to moderator
seoincorporation
Legendary
*
Offline Offline

Activity: 3150
Merit: 2933


Top Crypto Casino


View Profile
June 10, 2020, 02:57:45 PM
 #2

This looks like the WannaCry attack. Is crazy to see how the hackers are using this attack as their favorite new attack. Is easy to infect the machines with the malware, and there is nothing we can do because windows will keep installing programs without asking us.

If you want to be safe and secure, then use Linux and navigate on the internet wisely.

█████████████████████████
████▐██▄█████████████████
████▐██████▄▄▄███████████
████▐████▄█████▄▄████████
████▐█████▀▀▀▀▀███▄██████
████▐███▀████████████████
████▐█████████▄█████▌████
████▐██▌█████▀██████▌████
████▐██████████▀████▌████
█████▀███▄█████▄███▀█████
███████▀█████████▀███████
██████████▀███▀██████████
█████████████████████████
.
BC.GAME
▄▄░░░▄▀▀▄████████
▄▄▄
██████████████
█████░░▄▄▄▄████████
▄▄▄▄▄▄▄▄▄██▄██████▄▄▄▄████
▄███▄█▄▄██████████▄████▄████
███████████████████████████▀███
▀████▄██▄██▄░░░░▄████████████
▀▀▀█████▄▄▄███████████▀██
███████████████████▀██
███████████████████▄██
▄███████████████████▄██
█████████████████████▀██
██████████████████████▄
.
..CASINO....SPORTS....RACING..
█░░░░░░█░░░░░░█
▀███▀░░▀███▀░░▀███▀
▀░▀░░░░▀░▀░░░░▀░▀
░░░░░░░░░░░░
▀██████████
░░░░░███░░░░
░░█░░░███▄█░░░
░░██▌░░███░▀░░██▌
░█░██░░███░░░█░██
░█▀▀▀█▌░███░░█▀▀▀█▌
▄█▄░░░██▄███▄█▄░░▄██▄
▄███▄
░░░░▀██▄▀


▄▄████▄▄
▄███▀▀███▄
██████████
▀███▄░▄██▀
▄▄████▄▄░▀█▀▄██▀▄▄████▄▄
▄███▀▀▀████▄▄██▀▄███▀▀███▄
███████▄▄▀▀████▄▄▀▀███████
▀███▄▄███▀░░░▀▀████▄▄▄███▀
▀▀████▀▀████████▀▀████▀▀
hugeblack
Legendary
*
Offline Offline

Activity: 2506
Merit: 3650


Buy/Sell crypto at BestChange


View Profile WWW
June 10, 2020, 03:50:44 PM
 #3

Spam through the email is an old scam school, everyone should learn not to click on the links randomly.
I have not read all the data, but I do not think it is easy to close and encrypt all the data from a click of an image, any way you should be careful.

Use e-mail addresses with better filters, and do not publish them publicly.
Do not reply to any unknown e-mails.

.BEST..CHANGE.███████████████
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
██
███████████████
..BUY/ SELL CRYPTO..
TravelMug
Hero Member
*****
Offline Offline

Activity: 2632
Merit: 833



View Profile
June 11, 2020, 05:29:55 AM
 #4

This looks like the WannaCry attack. Is crazy to see how the hackers are using this attack as their favorite new attack. Is easy to infect the machines with the malware, and there is nothing we can do because windows will keep installing programs without asking us.

If you want to be safe and secure, then use Linux and navigate on the internet wisely.

It is being there are still non-educate individuals that can easily fall for this trick. They thought that it is interesting to see what the attach image are, click it and then it's too late, they feel victims. I agree that Linux are good, but it is not for everyone. Windows is still number one as far as desktop OS market share around the world.

Just think before you click and be very attentive on every mails coming into your inbox specially from unknown source.

R


▀▀▀▀▀▀▀██████▄▄
████████████████
▀▀▀▀█████▀▀▀█████
████████▌███▐████
▄▄▄▄█████▄▄▄█████
████████████████
▄▄▄▄▄▄▄██████▀▀
LLBIT
  CRYPTO   
FUTURES
 1,000x 
LEVERAGE
COMPETITIVE
    FEES    
 INSTANT 
EXECUTION
.
   TRADE NOW   
Pages: [1]
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.19 | SMF © 2006-2009, Simple Machines Valid XHTML 1.0! Valid CSS!