consumerWiper: architecture and mechanism of operation. part 2
More in Malware
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- .exe .docm .xlsm
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…
Conclusions
Analysis of this malware demonstrates a rational approach by the attackers. Since overwriting large files takes quite a lot of time, they resort to staged destruction. At the first stage, partial corruption of as many files as possible occurs, and only after that is a full overwrite of all files performed. This strategy allows the malware to inflict as much damage as possible in a short time.
Hash sums (SHA256):
7A00F5219F61850B5999BDE9669094AC8932971E15978D11962E42AF964C096C
89E0F599AFA7705DF55BF345C41236E70EFA813C7E82CAEE4171DCE678010B66
E4DFCF17AAB37F01B0D24010CAB1875F28EE545A9D330C85DE1A21EC682E840F
8554F4062D3FC3DD8EFEDA65B8620CE74D98B125627D5BE72BCA7B0930EDF737
5CFCE12D2C8687EBA1529EC82F93B85FF2B503959D19D82E9873C0C473CAEBE1
BA2D428D5B4E0EE1CC4A952FEC254DE453D8514E546F64919ABD13C0BBC59473Code language: plaintext (plaintext)#ioc #dfir #ir #wiper #malware
@ptescalator
More in Malware
- This is Siemens...
Recently, our colleagues from the Positive Industrial Expertise Center discovered a curious Windows sample on MalwareBazaar.…
- Anti-antivirus
Recently, we came across an APK with an intriguing and trust-inspiring name: «Антивирус ФСБ.apk». After installing…
- .exe .docm .xlsm
.exe .docm .xlsm Malicious files with these extensions are most often found in corporate network traffic.…
- Operation Chewbacca
At the end of June, the PT ESC team, during incident investigations, discovered a new group…
- Your Zimbra server is at risk
Recently, our PT ESC IR team encountered a new attack by ransomware groups on Zimbra mail…






