
Magniber Ransomware Used a Variant of Microsoft SmartScreen Bypass with Malformed Signature
MagniberSmartScreenRansomware
Magniber ransomware, which targeted Asian countries in 2017, continues to attack with expanded targets worldwide since 2021
Indicators of Compromise
themomerator.comSOCRadar2023-04-06
pastor.cntcog.orgSOCRadar2023-04-06
mayibeofservice.comSOCRadar2023-04-06
subscribe.3gbling.comSOCRadar2023-04-06
secure.azureSOCRadar2023-04-06
xinhewood-cn.comSOCRadar2023-04-06
travel.dianatokaji.comSOCRadar2023-04-06
ac.net.peSOCRadar2023-04-06
abuhureira.sc.keSOCRadar2023-04-06
mawuqiis.xyzSOCRadar2023-04-06
vividworld.netSOCRadar2023-04-06
coating.drrooter.comSOCRadar2023-04-06
whneat.comSOCRadar2023-04-06
quangdecalshop.comSOCRadar2023-04-06
orhung.spaceSOCRadar2023-04-06
longate.monsterSOCRadar2023-04-06
halldie.fitSOCRadar2023-04-06
dofight.monsterSOCRadar2023-04-06
googleanalyticstag.comSOCRadar2023-04-06
actsred.siteSOCRadar2023-04-06
sempersim.suSOCRadar2023-04-06
catat.siteSOCRadar2023-04-06
mail.jackbarber.comSOCRadar2023-04-06
blackcreekbarns.comSOCRadar2023-04-06
losthow.monsterSOCRadar2023-04-06
joyceyong.artSOCRadar2023-04-06
liveweatherupdate.onlineSOCRadar2023-04-06
mail.biateknos.comSOCRadar2023-04-06
abimatic-care.co.ukSOCRadar2023-04-06
buyaims.onlineSOCRadar2023-04-06
bankssy.comSOCRadar2023-04-06
polygons-stakes.siteSOCRadar2023-04-06
docs.azureSOCRadar2023-04-06
csmoved.spaceSOCRadar2023-04-06
abdullahcentre.comSOCRadar2023-04-06
achar724.comSOCRadar2023-04-06
luyensex.clubSOCRadar2023-04-06
tinpick.onlineSOCRadar2023-04-06
cerradoforte.comSOCRadar2023-04-06
bahisaltv79.comSOCRadar2023-04-06
gareloi-digit.comSOCRadar2023-04-06
mail.divinecellcare.lkSOCRadar2023-04-06
abundanceandbusinessacademy.comSOCRadar2023-04-06
codeforge.proSOCRadar2023-04-06
totwo.pwSOCRadar2023-04-06
cxitsolution.comSOCRadar2023-04-06
ittakes.funSOCRadar2023-04-06
pirlay.funSOCRadar2023-04-06
dach-loc.comSOCRadar2023-04-06
protection.cloudSOCRadar2023-04-06
lossend.casaSOCRadar2023-04-06
5avis.comSOCRadar2023-04-06
abre.com.mySOCRadar2023-04-06
echoesdesing.comSOCRadar2023-04-06
betdate.unoSOCRadar2023-04-06
spitecs.comSOCRadar2023-04-06
mini.ptipexcel.comSOCRadar2023-04-06
askills.questSOCRadar2023-04-06
hidwant.questSOCRadar2023-04-06
logharm.spaceSOCRadar2023-04-06
diary.lojjh.comSOCRadar2023-04-06
b23q.xyzSOCRadar2023-04-06
ftp.electrobist.comSOCRadar2023-04-06
owered.spaceSOCRadar2023-04-06
lowroll.unoSOCRadar2023-04-06
perwish.emailSOCRadar2023-04-06
putdear.emailSOCRadar2023-04-06
sportsgross.comSOCRadar2023-04-06
Campaign Guidance
Remediation, mitigation, notes, history and related intelligence
Remediations
Security Recommendation
- The Magniber ransomware relies on tricking people into opening fake software updates. Enterprises are advised to be cautious about the source of all software and operating system security updates, and only download them from trusted sources such as Windows Update and official software vendor websites. It is also advisable to avoid executing files from unknown sources.
- It is recommended to review whether there are abnormal work schedules and abnormal files on important servers or computers.
- It is recommended to tighten network access controls. If possible, it is recommended to create a trusted list and only allow clients to access certain categories of websites while blocking access to other nonessential external network services.
- Restrict the login sources and methods for high-privileged administrator accounts. For example, follow the principle of least privilege by only using administrator accounts when performing privileged tasks, or restrict privileged accounts to allow login only from secure management hosts.
- Regularly back up corporate data. It is recommended to follow the 3-2-1 principle by properly backing up important files with three copies, stored in two different types of devices, with one copy located in a remote or secure location.
Reports & References2
Observed Countries10
AU (392)
DE (303)
FR (168)
IT (708)
JP (60)
KP (974)
NZ (441)
TR (547)
TW (633)
US (643)