You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
These IOCs were released as part of PTI team research.
Threat actors, including Cuba Ransomware group, Wizard Spider and others, are using a private encrypting service to evade AV detections. The system is designed explicitly for the Cobalt Strike beacons, making conducting reverse engineering on the samples challenging. The encrypter readme file is available (here)
Running:
ff.exe 11985756
ff_dd.exe
RunDll32 TstDll.dll,AllocConsole 1198576
if you see error
"A fatal error is occured"
this mean:
ff.exe illegal command line
ff_dd.exe internet nothing
ff_dd.exe need time for run, ~1 minute
Note:
using cobalt's mimikatz from the rundll or exe process will ruin the crypt