2017-07-31 - GLOBEIMPOSTER RANSOMWARE INFECTION

NOTICE:

ASSOCIATED FILES:

BLOG AND TWEET RELATED TO THIS WAVE OF MALSPAM:

TODAY'S NOTES:


Shown above:  Some DMs today on Twitter with @BleepinComputer.

 

EMAILS


Shown above:  Screenshot from one of the emails.

 

10 SAMPLES FROM TODAY'S MALSPAM:

(Read: Date/Time   --   sending address (spoofed)   --   Subject   --   Attachment name)

 


Shown above:  One of the attachments and its extracted VBS file.

 

10 ATTACHMENTS FROM TODAY'S MALSPAM:

(Read: Attachment name   --   Extracted VBS file)

 

TRAFFIC


Shown above:  Traffic from an infection filtered in Wireshark.

 

URLS GENERATED BY THE EXTRACTED VBS FILES TO GET THE RANSOMWARE:

 

ASSOCIATED URLS FROM THE 2017-07-29 SAMPLE NOTED TODAY:

 

SHA256 HASHES

FILE ATTACHMENTS (ZIP ARCHIVES):

 

EXTRACTED VBS FILES:

 

GLOBEIMPOSTER EXE BINARIES DOWNLOADED BY VBS FILES:

 

IMAGES


Shown above:  Desktop of a Windows host infected with today's BTCware sample.

 


Shown above:  Decryption instructions for the 2017-07-28 GlobeImposter sample.

 


Shown above:  Decryptor for the 2017-07-28 GlobeImposter sample.

 


Shown above:  Some indicators this is GlobeImposter ransomware.

 

Click here to return to the main page.