2017-01-12 - "BLANK SLATE" CAMPAIGN SENDS CERBER RANSOMWARE
NOTICE:
- The zip archives on this page have been updated, and they now use the new password scheme. For the new password, see the "about" page of this website.
ASSOCIATED FILES:
- 2017-01-12-Cerber-infection-traffic.pcap.zip 1.4 MB (1,355,698 bytes)
- 2017-01-12-Cerber-malspam-traffic-all-examples.pcap (1,956,943 bytes)
- 2017-01-12-Blank-Slate-emails-and-Cerber-ransomware.zip 2.0 MB (1,994,256 bytes)
- 2017-01-12-Blank-Slate-malspam-0712-UTC.eml (64,983 bytes)
- 2017-01-12-Blank-Slate-malspam-1006-UTC.eml (43,899 bytes)
- 2017-01-12-Blank-Slate-malspam-1331-UTC.eml (59,956 bytes)
- 2017-01-12-Blank-Slate-malspam-1363-UTC.eml (42,923 bytes)
- 2017-01-12-Blank-Slate-malspam-1809-UTC.eml (46,496 bytes)
- 2017-01-12-Blank-Slate-malspam-2004-UTC.eml (45,169 bytes)
- 2017-01-12-Blank-Slate-maslpam-tracker.csv (992 bytes)
- 859214.zip (34,114 bytes)
- 236247851.zip (44,081 bytes)
- 434359441.zip (32,187 bytes)
- 7663013333.zip (47,800 bytes)
- 1617772479879.zip (33,133 bytes)
- 654700336027276.zip (31,459 bytes)
- 5770.doc (77,824 bytes)
- 11796.doc (79,360 bytes)
- 20431.doc (118,784 bytes)
- 20629.doc (80,896 bytes)
- 21040.doc (81,408 bytes)
- 32703.doc (109,568 bytes)
- 2017-01-12-Cerber-ransomware-from-11796.doc.exe (293,984 bytes)
- 2017-01-12-Cerber-ransomware-from-20431.doc.exe (300,773 bytes)
- 2017-01-12-Cerber-ransomware-from-20629.doc.exe (296,260 bytes)
- 2017-01-12-Cerber-ransomware-from-32703.doc.exe (293,458 bytes)
- 2017-01-12-Cerber-ransomware-from-5770.doc.exe (293,458 bytes)
NOTES:
- For background on this campaign, see the Palo Alto Networks Unit 42 Blog: "Blank Slate" Campaign Takes Advantage of Hosting Providers to Spread Ransomware.
- The Cerber ransomware is downloaded from IP addresses belonging to Amazon Web Services (AWS).
EMAILS
Read: date/time -- received from mailserver at -- sender (spoofed) -- subject -- attachment name -- extracted zip -- extracted doc
- 2017-01-12 07:12 UTC -- 91.240.141[.]213 -- <vroak@otmail[.]it> -- (no subject) -- 7663013333.zip -- N/A -- 20431.doc
- 2017-01-12 10:06 UTC -- charter[.]com -- <clayton.lively@cogentpowerinc[.]com> -- (no subject) -- 434359441.zip -- 5770_ZIP.zip -- 5770.doc
- 2017-01-12 13:31 UTC -- surnet[.]ru -- <kasserer@villingevand[.]dk> -- (no subject) -- 236247851.zip -- 32703_ZIP.zip -- 32703.doc
- 2017-01-12 13:53 UTC -- douglasfast[.]net -- <nmismash@robertdebry[.]com> -- (no subject) -- 654700336027276.zip -- 11796_ZIP.zip -- 11796.doc
- 2017-01-12 18:09 UTC -- hinet[.]net -- <highlandersboxingclub@live[.]com> -- (no subject) -- 859214.zip -- 20629_ZIP.zip -- 20629.doc
- 2017-01-12 20:04 UTC -- nordext[.]net -- <rbrown@rsu13[.]org> -- (no subject) -- 1617772479879.zip -- 21040_ZIP.zip -- 21040.doc
TRAFFIC

Shown above: Traffic from all the infections filtered in Wireshark.
ASSOCIATED DOMAINS:
- 35.165.60[.]239 port 80 - cunumlicgaf.bid - GET /read.php?f=0.dat [Cerber ransomware download from the Word macro]
- 54.212.239[.]185 port 80 - truthforeyoue.top - GET /search.php [Cerber ransomware download from the Word macro]
- 54.201.122[.]81 port 80 - bestflowstou.wang - GET /search.php [Cerber ransomware download from the Word macro]
- 58.43.12[.]0 to 58.43.12[.]31 (58.43.12[.]0/27) UDP port 6892 - Cerber ransomware post-infection UDP traffic
- 91.1.48[.]0 to 91.1.48[.]31 (91.1.48[.]0/27) UDP port 6892 - Cerber ransomware post-infection UDP traffic
- 91.239.24[.]0 to 91.239.25[.]255 (91.239.24[.]0/23) UDP port 6892 - Cerber ransomware post-infection UDP traffic
- 193.201.224[.]34 port 80 - p27dokhpz2n7nvgr.16gjpm[.]top - Cerber ransomware post-infection HTTP traffic
FILE HASHES
ATTACHED ZIP ARCHIVES:
- 4982817a3920b0cd7201d7ac28dda48c87ed10a1c11f3ff0481939d8f9719068 - 859214.zip
- dacce199d34cb204efbd3ab0746a01d081d55b9eef04adf3ed125b211fc6e2b4 - 236247851.zip
- d59f0e10ab90cacb0f900c3a23759f12619df459fb6733247291c2a20034cd9f - 434359441.zip
- 3522aa6d899ba14b792a5d7263fe2e6ecb9e349947edaf8d6611bf55363170ea - 7663013333.zip
- 981bbd1ec9e78fc58de70261696820bcb1077998a2e97b6e008dd733e5873c43 - 1617772479879.zip
- cafb51365adfe850cba0fe0731619d6fb2518a762f35f6fc5bb27c9b91ccdfbc - 654700336027276.zip
EXTRACTED MICROSOFT WORD DOCUMENTS:
- 13fda44b4e2eec7d9bf83d7bea97dd5757208dd0bba6a26539624c9e9add9ce2 - 5770.doc
- a586cc97a6a8939d03335b5af8e26d60e588100e4042a10b6a675b875b435a71 - 11796.doc
- 99d8396bc1f32d524e9deb034274b3ed270ee8d57968bfd31da7a5400f003803 - 20431.doc
- 504a6d325c3ff85c7da33a0688eeaa68d01ec082556c798eb5bd9afc4451327a - 20629.doc
- 325ea437720c05bd6251e554703ceda435fedadfcfaa993b1d1c3a8b9149f456 - 21040.doc
- 80291aaacf6ff25ebb2d1d741a162eebe7f611cb51a60b9ceef684dc0215004a - 32703.doc
DOWNLOADED CERBER RANSOMWARE SAMPLES:
- 9c3e5de601d3c1f6961bbd8c587a4d0d2f11ca3071392d07d739d7d851a545e0 - Cerber ransomware from 11796.doc
- b8f29a92d31241e9ee4ededc6fcc3c91835991914d342e588ffeedf8b19fd1b4 - Cerber ransomware from 20431.doc/li>
- e634144fea15d297a99309d53b219d50197f3ef3c77776e64cda2ada1d419660 - Cerber ransomware from 20629.doc/li>
- f7a44aa207a440b8a5b2094aac08dc3f9b435fce152e34842255069e7190109b - Cerber ransomware from 32703.doc/li>
- f7a44aa207a440b8a5b2094aac08dc3f9b435fce152e34842255069e7190109b - Cerber ransomware from 5770.doc
Click here to return to the main page.
