Metode Pengiriman: Phishing
Brain Cipher Ransomware dikirimkan terutama melalui kampanye phishing. Kampanye ini sering menggunakan email menipu untuk mengelabui penerima agar mengunduh dan menjalankan file berbahaya.
Indikator Kompromi (IOCs)
– MD5: 448f1796fe8de02194b21c0715e0a5f6
– SHA1: 935c0b39837319fda571aa800b67d997b79c3198
– SHA256: eb82946fa0de261e92f8f60aa878c9fef9ebb34fdababa66995403b110118b12
– SSDEEP: 3072
– Alamat IP: 199.232.214.172 (AS), 224.0.0.252
– Web: http://mybmtbgd7aprdnw2ekxht5qap5daam2wch25coqerrq2zdioanob34ad.onion
– Email: brain.support@cyberfear.com
– VirusTotal: VirusTotal Link
MITRE ATT&CK
Eksekusi
– T1059.003: Windows Command Shell
– T1204.002: User Execution Malicious File
Eskalasi Hak Istimewa
– T1548.002: Bypass User Account Control