Ransom.Win64.MAGNIBER.J
July 27, 2022
ALIASES:
Trojan.Win64.Injector (IKARUS)
PLATFORM:
Windows
OVERALL RISK RATING:
DAMAGE POTENTIAL:
DISTRIBUTION POTENTIAL:
REPORTED INFECTION:
INFORMATION EXPOSURE:

Threat Type: Ransomware
Destructiveness: No
Encrypted:
In the wild: Yes
OVERVIEW
This Ransomware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
It is capable of encrypting files in the affected system.
It drops files as ransom note.
TECHNICAL DETAILS
File Size: 284,152 bytes
File Type: Other
Initial Samples Received Date: 26 Jul 2022
Arrival Details
This Ransomware arrives on a system as a file dropped by other malware or as a file downloaded unknowingly by users when visiting malicious sites.
Other Details
This Ransomware connects to the following possibly malicious URL:
- http://{random}cbjidtkxmr.{BLOCKED}.co/bjidtkxmr&{random}&{random}&{random}&{random}&{random}
It is capable of encrypting files in the affected system.
Ransomware Routine
This Ransomware appends the following extension to the file name of the encrypted files:
- .bjidtkxmr
It drops the following file(s) as ransom note:
- {Encrypted Directory}\README.html