2017-03-03 - SHADE (TROLDESH) RANSOMWARE INFECTION

ASSOCIATED FILES:

  • 2017-03-03-Shade-ransomware-infection.pcap   (17,849,841 bytes)
  • 2017-03-03-Shade-ransomware-decryption-instructions.txt   (4,170 bytes)
  • 2017-03-03-Shade-ransomware-desktop-background.bmp   (2,087,494 bytes)
  • 2017-03-03-fake-IRS-email-1342-UTC.eml   (2,176 bytes)
  • 2017-03-03-malware-downloaded-by-js-file.exe   (952,470 bytes)
  • 75FA005B.exe   (173,084 bytes)
  • 82E39F81.exe   (887,808 bytes)
  • A86B5C6747183B1C9BBB4181C53F302D.dll   (1,012,224 bytes)
  • C9AA35DA.exe   (1,032,704 bytes)
  • D88AD939.exe   (1,497,600 bytes)
  • Realty.tax.division.xls.js   (22,539 bytes)
  • Realty.tax.division.xls.zip   (9,445 bytes)

NOTES:


Shown above:  Flowchart for this infection traffic.

 

EMAIL


Shown above:  Screenshot from the email.

 

EMAIL HEADERS:

 

EMAIL MESSAGE:

Dear Citizen,

It is Dick Richardson, I am the tax manager of the Internal Revenue Service, Realty Tax Department.

My office is responsible for informing of citizens, explanation of the tax system for them, supporting citizens on issues related to tax procedures, arrears, and payments, etc.

In this particular case, I have to notify you that you have the considerable tax arrears related to your property. To the point, there is the tax debt for your realty - the realty tax. Generally, we make no actions in case of such delays for 4-6 months, but in your context, the overdue period comes to 7 months. This way, we must take relevant measures to remedy the situation.

Particularly for your convenience, our specialists have prepared the full and comprehensive report for you. It contains the full information regarding realty tax accrual, your debt (including the total amount), and the chart of overdue payments for each month of the arrears period.

Please download the report directly from the official server of the IRS, going to the link:
[link to malicious zip file]

Please study the document at the earliest possible moment. Actually, after receiving this message, you have only 1 day to contact your tax manager and provide them with the details you get in the report in order to resolve the problem. Else, significant charges and fines may apply.

Kindest Regards,

Dick Richardson,
Realty Tax Division
Internal Revenue Service

 

DOWNLOADED FILE:


Shown above:  Zip archive downloaded from link in the email.

 

TRAFFIC


Shown above:  Traffic from the infection filtered in Wireshark.

 

ASSOCIATED DOMAINS:

 

FILE HASHES

FROM LINK IN THE EMAIL:

 

ARTIFACTS FROM THE INFECTED HOST:

 

IMAGES


Shown above:  Desktop of the infected Windows host.

 


Shown above:  Some (not all) alerts on the post-infection traffic from the ETPRO ruleset using Sguil on Security Onion.

 

Click here to return to the main page.