RIP REvil / Sodinokibi
The supposedly Russian based cyber-criminal gang who run the criminal ransomware operation REvil / Sodinokibi just self-hammered the last nail in their coffins it seems.
credit - under the breach

seen from United States

seen from United States

seen from United States
seen from United Kingdom

seen from Türkiye

seen from United States

seen from United Kingdom

seen from United Kingdom

seen from United States
seen from United Kingdom
seen from Brazil
seen from Türkiye
seen from Australia
seen from United States
seen from United Kingdom
seen from United States
seen from United States

seen from United States
seen from Netherlands

seen from Brazil
RIP REvil / Sodinokibi
The supposedly Russian based cyber-criminal gang who run the criminal ransomware operation REvil / Sodinokibi just self-hammered the last nail in their coffins it seems.
credit - under the breach
WSJ: Travelex, Foreign Exchange Company, Paid $23 in Ransomeware
WSJ Report Claims #Travelex Paid $23 Million #Ransomware -- #Xanjero
A recent report by The Wall Street Journal reveals that Travelex paid an astounding $23 million in ransomware through 285 Bitcoin…
London-based foreign exchange firm reportedly paid out $23 million in ransomeware to a hacking ring, according to a news report by The Wall Street Journal. The company purportedly paid out the demands visa-via 285 Bitcoin to recoup control of its operations.
WSJ Report…
View On WordPress
Sodinokibi decryptor.top TLD
IPs 45.138.96.206 🚽 - Null routed by Virtono - 16-JAN-2020 at 12:31 via Ticket ID: #105547 - report sent by Reportsp.am
162.251.120.66 🚽 - Null routed by Heymman Servers - 18-JAN-2020 at 08:44 - via Ticket ID: #513724 - report sent by Reportsp.am
94.103.87.78 ☢ - Pending - 18-JAN-2020 at 20:08 via Ticket ID: # [IBN-Y319RD4] - report sent by Reportsp.am
They will switch hosting soon, more reports due...?
Update 20-Jan-2020 - Domain decryptor.top suspended by registrar HKNET.
Sodinokibi ransomware | The ill-intented perpetrators behind Sodinokibi Ransomware attacks have posted stolen data of the victims for the first time. They did it since the ransom was not paid. Read on to know more.
Sodinokibi Ransomware Hit Travelex, Demands $6 M (400 BTC)
No payments sent yet:
35XFq6ShmZnzS2FSwhGBYLBCu7EgKYUCrS
Reports were supposedly ignored.
Interesting to see the outcome.
today 10-Jan-2020 two domains were registered:
Registrar, registrant and VPS (Host Europe) based in the UK 🇬🇧 > nslookup travelexdatabreach‧com Name: travelexdatabreach‧com Address: 94‧136‧40‧51
> nslookup travelexdata‧com Name: travelexdata‧com Address: 94‧136‧40‧51
credit: @bad_packets @GossiTheDog
bleepingcomputer
Domain DECRYPTOR.TOP
nslookup decryptor.top
Name: decryptor.top Address: 45.138.96.206 - Reported to VIRTONO 16-Jan-2020
2019年7月、8月のマルウェアレポートを公開~ランサムウェア「Sodinokibi」の被害が世界中で拡大~
2019年7月、8月のマルウェアレポートを公開~ランサムウェア「Sodinokibi」の被害が世界中で拡大~ #マルウエアレポート #キャノンMJ #ランサムウエア #Sodinokibi #添付ファイルからの感染
キャノンMJ が公開している、2019年~8月のマルウエアレポートです。
ランサムウェアによる被害が、目立っているようですね。
2019年7月、8月のマルウェアレポートを公開~ランサムウェア「Sodinokibi」の被害が世界中で拡大~ キヤノンMJ
キヤノンマーケティングジャパン株式会社(代表取締役社長:坂田正弘、以下キヤノンMJ)は、2019年7月、8月のマルウェア検出状況に関する最新のレポートを公開しました。世界中で被害が広がっているSodinokibiと呼ばれるランサムウェアの脅威ついて解説しています。
2019年7月、8月のマルウェアレポートを公開 – キャノンMJ
キヤノンMJのサイバーセキュリティに関する研究を担うマルウェアラボは、国内で利用されているウイルス対策ソフトウェア「ESETセキュリティ ソフトウェア…
View On WordPress
2019年7月、8月のマルウェアレポートを公開~ランサムウェア「Sodinokibi」の被害が世界中で拡大~
2019年7月、8月のマルウェアレポートを公開~ランサムウェア「Sodinokibi」の被害が世界中で拡大~ #マルウエアレポート #キャノンMJ #ランサムウエア #Sodinokibi #添付ファイルからの感染
キャノンMJ が公開している、2019年~8月のマルウエアレポートです。
ランサムウェアによる被害が、目立っているようですね。
2019年7月、8月のマルウェアレポートを公開~ランサムウェア「Sodinokibi」の被害が世界中で拡大~ キヤノンMJ
キヤノンマーケティングジャパン株式会社(代表取締役社長:坂田正弘、以下キヤノンMJ)は、2019年7月、8月のマルウェア検出状況に関する最新のレポートを公開しました。世界中で被害が広がっているSodinokibiと呼ばれるランサムウェアの脅威ついて解説しています。
2019年7月、8月のマルウェアレポートを公開 – キャノンMJ
キヤノンMJのサイバーセキュリティに関する研究を担うマルウェアラボは、国内で利用されているウイルス対策ソフトウェア「ESETセキュリティ ソフトウェア…
View On WordPress
Sodinokibi Ransomware Spreads via Fake Forums on Hacked Sites
Sodinokibi Ransomware Spreads via Fake Forums on Hacked Sites
A distributor for the Sodinokibi Ransomware is hacking into WordPress sites and injecting JavaScript that displays a fake Q & A forum post over the content of the original site. This fake post contains an “answer” from the site’s “admin” that contains a link to the ransomware installer.
As security software and people become more aware of the methods that are used to distribute ransomware and…
View On WordPress