Update: CVE-2024-4577 quickly weaponized to distribute Ransomware
June 11, 2024, 10:31 a.m.
Description
The report describes an attack campaign leveraging the CVE-2024-4577 vulnerability to deliver the "TellYouThePass" ransomware. The attackers use the vulnerability to execute arbitrary PHP code and run a malicious HTML application that loads a .NET variant of the ransomware into memory. Upon execution, the ransomware contacts a command-and-control server, enumerates directories, terminates processes, encrypts files, and leaves a ransom note.
Tags
Date
- Created: June 11, 2024, 10:13 a.m.
- Published: June 11, 2024, 10:13 a.m.
- Modified: June 11, 2024, 10:31 a.m.
Indicators
- 9562ad2c173b107a2baa7a4986825b52e881a935deb4356bf8b80b1ec6d41c53
- 5a2b9ddddea96f21d905036761ab27627bd6db4f5973b006f1e39d4acb04a618
- 95279881525d4ed4ce25777bb967ab87659e7f72235b76f9530456b48a00bac3
- bc1qnuxx83nd4keeegrumtnu8kup8g02yzgff6z53l
- 88.218.76.13