EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Ransomware

#StopRansomware: Ghost (Cring) Ransomware

Fonte ufficiale
Sintesi operativa EudorIA

Cosa significa

Priorità 90/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Ghost (Cring). Le misure indicate vanno confrontate con esposizione, identita, segmentazione e capacita di ripristino.

Perché conta

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Benefici operativi potenziali

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indicazioni da confermare sul perimetro tecnico e organizzativo del cliente.
Controlli pertinentiVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
DestinatariITSOCCISOManagement
Centro informazioni

Traduzione in elaborazione

CISA

Il contenuto ufficiale è disponibile nella lingua originale. La versione italiana verrà pubblicata al termine dei controlli automatici.

Testo acquisito dalla fonte

Cybersecurity Advisory #StopRansomware: Ghost (Cring) Ransomware Release Date February 19, 2025 Alert Code AA25-050A Related topics: Cyber Threats and Response , Incident Response , Malware, Phishing, and Ransomware Actions for Organizations to Take Today to Mitigate Cyber Threats Related to Ghost (Cring) Ransomware Activity Maintain regular system backups stored separately from the source systems which cannot be altered or encrypted by potentially compromised network devices [CPG 2.R]. Patch known vulnerabilities by applying timely security updates to operating systems, software, and firmware within a risk-informed timeframe [CPG 2.F]. Common Vulnerabilities and Exposures (CVE): CVE-2018-13379, CVE-2010-2861, CVE-2009-3960, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207. Segment networks to restrict lateral movement from initial infected devices and other devices in the same organization [CPG 2.F]. Require Phishing-Resistant MFA for access to all privileged accounts and email services accounts. Summary Note: This joint Cybersecurity Advisory is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Federal Bureau of Investigation (FBI), Cybersecurity and Infrastructure Security Agency (CISA), and the Multi-State Information Sharing and Analysis Center (MS-ISAC) are releasing this joint advisory to disseminate known Ghost (Cring)—(“G

Indicatori CISA verificabili

65 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili.

Ultima verifica: 2026-09-26T06:00:37.959413+00:00

Scarica STIX 2.1

Questo allegato contiene 1 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.

TipoIndicatore (non cliccabile)File
MD5db38ef2e3d4d8cb785df48f458b35090sock.txt
MD5625bd7275e1892eac50a22f8b4a6355disx.txt
SHA-10979b2202e650444ffe61d9762cb756e7cdd6bf0isx.txt
SHA-256e0821121726dbe78c6423af0f46b2e938acf8ce74d4674751af4030d84be972aisx.txt
SSDEEP49152:Jri7bgnq+Tk/hkYD168uq6StA66ztND3Tv82putV6Cl:Jr0mFk/hX1/6h9rQ8isx.txt
MD5a2fd181f57548c215ac6891d000ec6b9main.txt
SHA-192e529aefd28e6a32b0ab9ef2289d211abbe435dmain.txt
SHA-2564a324fc6ab18f552b8669404219ba4f16ad167c6e534b61f5bc7831534eb23a1main.txt
SSDEEP49152:IPSQZsb3bimRrb/TwvO90d7HjmAFd4A64nsfJnP1Q3Wq9+YgSlD4byD1CFe9c74G:J3bim3OIFF7n2PMYmain.txt
MD5ff52fdf84448277b1bc121f592f753c5sp.txt
MD50a5c4ad3ec240fbfd00bdc1d36bd54ebx86.log
MD5c3b8f6d102393b4542e9f951c9435255x86.log
SHA-10183cf7515729edddc070ed0d564222b1d1e76d6x86.log
SHA-2564e9bb2de5712e0fdb7270cce45af0afb089c44d4424aa7cf8ca98219ec45a9c1x86.log
SSDEEP24576:oZSlJ2VULwYcNRv/D3cX8rJDAhPCDWBl4Z6ZH6GjMRCDPx9UhvkqVaTEKUYD1I/l:ITcXna6ZHru15YD1nzDsRkOXkyN47xCx86.log
MD5ef6a213f59f3fbee2894bd6734bbaed2Locker.exe
MD5d1c5e7b8e937625891707f8b4b594314ElysiumO.exe
SHA-1f031bba881a735e45b757548b9b981cc2dcd87ecElysiumO.exe
SHA-256c8acd8e65b46c86d0d01e961358bc6ab9aec70f90a57829aa15e39add536b5c8ElysiumO.exe
SSDEEP768:YBMQI6dpTIAcU+fipHZIpryQBwGZKBaja+jUZbB1hIl:YKAIAJJp5IIQCGVja+wZbB1elElysiumO.exe
MD5c9e35b5c1dc8856da25965b385a26ec4ElysiumO.exe
MD529e44e8994197bdb0c2be6fc5dfc15c2ElysiumO.exe
MD5d9c019182d88290e5489cdf3b607f982Ghost.exe
MD534b3009590ec2d361f07cac320671410Ghost.exe
email-addrrainbowforever[@]skiff[.]com
email-addrghost1998[@]tutamail[.]com
email-addrr[.]heisler[@]skiff[.]com
email-addrgenesis1337[@]tutanota[.]com
email-addrsummerkiller[@]mailfence[.]com
email-addrlockhelp1998[@]skiff[.]com
email-addrkev1npt[@]tuta[.]io
email-addrfileunlock[@]onionmail[.]org
email-addrshadowghost[@]skiff[.]com
email-addrkellyreiff[@]tutanota[.]com
email-addrevilcorp[@]skiff[.]com
email-addrghostsbackup[@]skiff[.]com
email-addrretryit1998[@]tutamail[.]com
email-addrghosts1337[@]tuta[.]io
email-addrcrptbackup[@]skiff[.]com
email-addrretryit1998[@]mailfence[.]com
email-addrghosts1337[@]skiff[.]com
email-addrcringghost[@]skiff[.]com
email-addrghostbackup[@]skiff[.]com
email-addrasauribe[@]tutanota[.]com
email-addrrainbowforever[@]tutanota[.]com
email-addrrsacrpthelp[@]skiff[.]com
email-addrhsharada[@]skiff[.]com
MD5ac58a214ce7deb3a578c10b97f93d9c3iex.txt; iex.exe; pro.txt
SHA-144396e35b328247dafd23b4a26b9d69c0011f54aiex.txt; iex.exe; pro.txt
SHA-2560500c9d0b91e62993447cdcf5f691092aff409eca24080ce149f34e48a0445e0iex.txt; iex.exe; pro.txt
SSDEEP49152:vSthBqV3933Mrb/TQvO90d7HjmAFd4A64nsfJkxw4d9WN0+YgSlD47zD1yRMV1r5:h3933vuIA1rYi0PMYiex.txt; iex.exe; pro.txt
email-addrshadowghosts[@]tutanota[.]com
email-addrjust4money[@]tutanota[.]com
email-addrsummerkiller[@]tutanota[.]com
email-addrd3svc[@]tuta[.]io
email-addrd3crypt[@]onionmail[.]org
email-addrsdghost[@]onionmail[.]org
email-addrfortihooks[@]protonmail[.]com
email-addrwebroothooks[@]tutanota[.]com
email-addrrsahelp[@]protonmail[.]com
MD5c5d712f82d5d37bb284acd4468ab3533Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SHA-13426e8dcb104d9b01874498fb44c6e460228a9a0Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SHA-256f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SSDEEP384:asgE0J/RBKbpdqPnrjBCokjvPGumOiZ81eAl6CjUj:asgEMJwbK/X8AAl6LjCring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
email-addreternalnightmare[@]tutanota[.]com

Provenienza

Allegato ufficiale CISA · 2025-02-18T19:14:27Z

SHA-512: e8573561411fb21c30e6e199de4c20c2071050022c6da837749dd8e94f08faa1fb8afcbc4ab927378c911601b5adc5dc69899cbe9d32f68c881e9133bb962a14

Questo allegato contiene 1 indicatori incompleti o non interpretabili, conservati nell'originale ma esclusi dall'export operativo. I valori mancanti non sono stati dedotti.

TipoIndicatore (non cliccabile)File
MD5db38ef2e3d4d8cb785df48f458b35090sock.txt
MD5625bd7275e1892eac50a22f8b4a6355disx.txt
SHA-10979b2202e650444ffe61d9762cb756e7cdd6bf0isx.txt
SHA-256e0821121726dbe78c6423af0f46b2e938acf8ce74d4674751af4030d84be972aisx.txt
SSDEEP49152:Jri7bgnq+Tk/hkYD168uq6StA66ztND3Tv82putV6Cl:Jr0mFk/hX1/6h9rQ8isx.txt
MD5a2fd181f57548c215ac6891d000ec6b9main.txt
SHA-192e529aefd28e6a32b0ab9ef2289d211abbe435dmain.txt
SHA-2564a324fc6ab18f552b8669404219ba4f16ad167c6e534b61f5bc7831534eb23a1main.txt
SSDEEP49152:IPSQZsb3bimRrb/TwvO90d7HjmAFd4A64nsfJnP1Q3Wq9+YgSlD4byD1CFe9c74G:J3bim3OIFF7n2PMYmain.txt
MD5ff52fdf84448277b1bc121f592f753c5sp.txt
MD50a5c4ad3ec240fbfd00bdc1d36bd54ebx86.log
MD5c3b8f6d102393b4542e9f951c9435255x86.log
SHA-10183cf7515729edddc070ed0d564222b1d1e76d6x86.log
SHA-2564e9bb2de5712e0fdb7270cce45af0afb089c44d4424aa7cf8ca98219ec45a9c1x86.log
SSDEEP24576:oZSlJ2VULwYcNRv/D3cX8rJDAhPCDWBl4Z6ZH6GjMRCDPx9UhvkqVaTEKUYD1I/l:ITcXna6ZHru15YD1nzDsRkOXkyN47xCx86.log
MD5ef6a213f59f3fbee2894bd6734bbaed2Locker.exe
MD5d1c5e7b8e937625891707f8b4b594314ElysiumO.exe
SHA-1f031bba881a735e45b757548b9b981cc2dcd87ecElysiumO.exe
SHA-256c8acd8e65b46c86d0d01e961358bc6ab9aec70f90a57829aa15e39add536b5c8ElysiumO.exe
SSDEEP768:YBMQI6dpTIAcU+fipHZIpryQBwGZKBaja+jUZbB1hIl:YKAIAJJp5IIQCGVja+wZbB1elElysiumO.exe
MD5c9e35b5c1dc8856da25965b385a26ec4ElysiumO.exe
MD529e44e8994197bdb0c2be6fc5dfc15c2ElysiumO.exe
MD5d9c019182d88290e5489cdf3b607f982Ghost.exe
MD534b3009590ec2d361f07cac320671410Ghost.exe
email-addrrainbowforever[@]skiff[.]com
email-addrghost1998[@]tutamail[.]com
email-addrr[.]heisler[@]skiff[.]com
email-addrgenesis1337[@]tutanota[.]com
email-addrsummerkiller[@]mailfence[.]com
email-addrlockhelp1998[@]skiff[.]com
email-addrkev1npt[@]tuta[.]io
email-addrfileunlock[@]onionmail[.]org
email-addrshadowghost[@]skiff[.]com
email-addrkellyreiff[@]tutanota[.]com
email-addrevilcorp[@]skiff[.]com
email-addrghostsbackup[@]skiff[.]com
email-addrretryit1998[@]tutamail[.]com
email-addrghosts1337[@]tuta[.]io
email-addrcrptbackup[@]skiff[.]com
email-addrretryit1998[@]mailfence[.]com
email-addrghosts1337[@]skiff[.]com
email-addrcringghost[@]skiff[.]com
email-addrghostbackup[@]skiff[.]com
email-addrasauribe[@]tutanota[.]com
email-addrrainbowforever[@]tutanota[.]com
email-addrrsacrpthelp[@]skiff[.]com
email-addrhsharada[@]skiff[.]com
MD5ac58a214ce7deb3a578c10b97f93d9c3pro.txt; iex.exe; iex.txt
SHA-144396e35b328247dafd23b4a26b9d69c0011f54apro.txt; iex.exe; iex.txt
SHA-2560500c9d0b91e62993447cdcf5f691092aff409eca24080ce149f34e48a0445e0pro.txt; iex.exe; iex.txt
SSDEEP49152:vSthBqV3933Mrb/TQvO90d7HjmAFd4A64nsfJkxw4d9WN0+YgSlD47zD1yRMV1r5:h3933vuIA1rYi0PMYpro.txt; iex.exe; iex.txt
email-addrshadowghosts[@]tutanota[.]com
email-addrjust4money[@]tutanota[.]com
email-addrsummerkiller[@]tutanota[.]com
email-addrd3svc[@]tuta[.]io
email-addrd3crypt[@]onionmail[.]org
email-addrsdghost[@]onionmail[.]org
email-addrfortihooks[@]protonmail[.]com
email-addrwebroothooks[@]tutanota[.]com
email-addrrsahelp[@]protonmail[.]com
MD5c5d712f82d5d37bb284acd4468ab3533Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SHA-13426e8dcb104d9b01874498fb44c6e460228a9a0Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SHA-256f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8Cring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
SSDEEP384:asgE0J/RBKbpdqPnrjBCokjvPGumOiZ81eAl6CjUj:asgEMJwbK/X8AAl6LjCring.exe; f7d270ca0f2b4d21830787431f881cd004b2eb102cc3048c6b4d69cb775511c8.bin
email-addreternalnightmare[@]tutanota[.]com

Provenienza

Allegato ufficiale CISA · 2025-02-18T19:14:31Z

SHA-512: 4ae95c99d46f09b232249cda7db130ca170130c022b425e292d1e557075915872064be4a6d65bb0be5aafe88156e2cd3b695ea15177a8f1408aed3cdb501e5d5

Fonte
CISA Cybersecurity Advisories
Entità pubblicatrice
CISA
Tipo entità
Autorità nazionale
Area
North America · US
Lingua originale
en · traduzione in preparazione
Pubblicazione
19/02/2025 13:00
Condivisione
TLP:CLEAR
MITRE ATT&CK
T1003, T1018, T1041, T1047, T1057, T1059.001, T1059.003, T1068, T1070.001, T1071.001, T1087.002, T1098, T1105, T1132.001, T1134.001, T1135, T1136.001, T1136.002, T1190, T1486, T1490, T1505.003, T1518, T1518.001, T1562.001, T1564.003, T1567.002, T1573
CVE
CVE-2018-13379, CVE-2010-2861, CVE-2009-3960, CVE-2021-34473, CVE-2021-34523, CVE-2021-31207, CVE-2019-0604, CVE-2020-1472, CVE-2014-1812, CVE-2017-0143, CVE-2017-0144
Classificazione
Critica
Gruppo attribuito dalla fonte
Ghost (Cring)
Paese indicato
US
Perimetro tecnico

Prodotti e versioni interessati

Verifica in corso
Informazione non ancora acquisita.

Il collector verificherà NVD e gli advisory vendor ufficiali disponibili.

Azione indicata dalla fonte

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Riferimenti tecnici ufficiali

Apri la fonte originale