logo

Satan ransomware adds EternalBlue exploit

ID: 59dc87dd-299d-59a8-8b62-ecbc6f3e539b

STIX ID: report--59dc87dd-299d-59a8-8b62-ecbc6f3e539b

Feed Name: Blaze's Security Blog

Threat Score
75/100

Date Published: 2018-04-22

Date Updated: 2026-04-19

Author: Bart

...
...

Technical analysis of a Satan ransomware variant shows it uses EternalBlue and DoublePulsar to spread via SMB, downloads components (sts.exe, ms.exe, client.exe) from 198.55.107.149 with a custom User-Agent, drops Cryptor.exe, kills database processes, excludes specific directories, and appends .satan while tagging files with [email protected]; it communicates with a C2, creates mutex SATANAPP, demands 0.3 BTC, and includes detailed IOCs (hashes, IPs, file paths, commands, BTC wallet) along with disinfection and MS17-010 patching guidance.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.