PULSE NAME
Severe Ransomware Attacks Against Swiss SMEs
WHITE AlienVault 2019-05-09 Modified: 2019-05-09
7
IOCs
LOW VOLUME
As we have seen an ever-increasing number of ransomware cases that show a rather sophisticated modus operandi, we are publishing a warning via MELANI Newsletter along with this blog post, documenting technical details about the recent ransomware attacks against Swiss small and medium enterprises (SMEs). The goal of this blog post is to give you a better understanding of the various modus operandi of the most common ransomware families we have encountered hitting Swiss targets in the past months.
Indicators of Compromise (7)
All FileHash-SHA256 domain URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 fd93858f4e7356bebe30dd0dfe07367e3ddf6164bb78725e1c543b093558cf64 2019-05-09
domain dopearos.com 2019-05-09
URL http://dopearos.com:443/submit.php 2019-05-09
URL http://dopearos.com:443/8WyT 2019-05-09
URL http://dopearos.com:443/ 2019-05-09
URL http://dopearos.com:443/zDJT 2019-05-09
URL http://dopearos.com:443/en_US/all.js 2019-05-09