Satan ransomware rebrands as 5ss5c ransomware
ID: 45e039b6-c08c-5feb-b37c-3ec935a79ecf
STIX ID: report--45e039b6-c08c-5feb-b37c-3ec935a79ecf
Feed Name: Blaze's Security Blog
This report documents the rebranded 5ss5c ransomware—linked to the Satan/DBGer/Lucky family—detailing its infection chain (downloader down.txt, spreader c.dat leveraging EternalBlue and hardcoded credentials, and payload cpt.dat), credential theft tools (Mimikatz), C2 communication with 61.186.243.2, and operational features such as mutexes, exclusions, targeted file extensions, and a Chinese-only ransom note. The actors use multiple packers (MPRESS, Enigma, Enigma VirtualBox) and a ‘poc.exe’ spreader, indicating active development/testing. Extensive IOCs (hashes, URLs, IPs, file paths, commands, mutexes, email) are provided for detection and response.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
