EudorIACyber Intelligence
Operational monitoring Newsletter IT EN
← Back to intelligence
Ransomware

#StopRansomware: Snatch Ransomware

Official source
EudorIA operational summary

What it means

Priority 95/100

CISA Cybersecurity Advisories ha pubblicato un advisory sul ransomware Snatch. La fonte descrive vulnerabilita o tecniche gia osservate in attacchi e richiede una verifica prioritaria.

Why it matters

L'advisory descrive attivita ransomware osservate e misure difensive pubblicate da un'autorita. Non prova che il proprio perimetro sia compromesso, ma richiede una verifica prioritaria di esposizione e controlli.

Potential operational benefits

  • Prioritizzazione delle esposizioni Internet e delle vulnerabilita sfruttate
  • Verifica dei controlli su accessi remoti, movimento laterale ed esfiltrazione
  • Validazione documentata della capacita di ripristino
Indications to confirm against the customer's technical and organisational perimeter.
Relevant controlsVulnerability managementIdentity and access managementNetwork segmentationBackup and recoveryDetection and response
AudienceITSOCCISOManagement
Information centre

Translation in progress

CISA

The official content is available in the original language. The Italian version will be published once automated checks are complete.

Text acquired from the source

Cybersecurity Advisory #StopRansomware: Snatch Ransomware Release Date September 20, 2023 Alert Code AA23-263A Related topics: Malware, Phishing, and Ransomware , Cyber Threats and Response Actions to take today to mitigate malicious cyber activity: Secure and closely monitor Remote Desktop Protocol (RDP). Maintain offline backups of data. Enable and enforce phishing-resistant multifactor authentication (MFA). SUMMARY Note: This joint Cybersecurity Advisory (CSA) is part of an ongoing #StopRansomware effort to publish advisories for network defenders that detail various ransomware variants and ransomware threat actors. These #StopRansomware advisories include recently and historically observed tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) to help organizations protect against ransomware. Visit stopransomware.gov to see all #StopRansomware advisories and to learn more about other ransomware threats and no-cost resources. The Federal Bureau of Investigation (FBI) and the Cybersecurity and Infrastructure Security Agency (CISA) are releasing this joint CSA to disseminate known ransomware IOCs and TTPs associated with the Snatch ransomware variant identified through FBI investigations as recently as June 1, 2023. Since mid-2021, Snatch threat actors have consistently evolved their tactics to take advantage of current trends in the cybercriminal space and leveraged successes of other ransomware variants’ operations. Snatch threat actors have targeted a wide range of critical infrastructure sectors including the Defense Industrial Base (DIB), Food and Agriculture, and Information Technology sectors. Snatch threat actors conduct ransomware operations involving data exfiltration and double extortion. After data exfiltration often involving direct

Indicatori CISA verificabili

71 valori IOC dalla fonte ufficiale. Non sono una lista di blocco automatica: verificare data, contesto e applicabilita.

Copertura parziale: sono mostrati solo gli indicatori verificati e interpretabili. 1 allegati richiedono ancora verifica o un formato supportato.

Ultima verifica: 2026-09-26T04:30:36.312980+00:00

Scarica STIX 2.1
TipoIndicatore (non cliccabile)File
mutexgcc-hmem-tdm2-sjlj_once
mutexgcc-shmem-tdm2-fc_key
MD555310bb774fff38cca265dbc70ad6705eqbglqcngblqnl.bat
SHA-1cb8d76e9fd38a0b253056e5f204dab5441fe932beqbglqcngblqnl.bat
SHA-2561fbdb97893d09d59575c3ef95df3c929fe6b6ddf1b273283e4efadf94cdc802deqbglqcngblqnl.bat
SSDEEP3:mKDDlyJdZSrhwXrdq:hAJdZYqXrMeqbglqcngblqnl.bat
MD5395dad45c4761490c6480308a8359c06evhgpp.bat
SHA-1050304668d55e64f6088b407836cffd31d4b3414evhgpp.bat
SHA-256b998a8c15cc19c8c31c89b30f692a40b14d7a6c09233eb976c07f19a84eccb40evhgpp.bat
SSDEEP6:hwsfok/KnwJvUxIuDqisfok/KnwJqExIuD2uAxFeYMY26xFeYMYewxFeXawqFeI:j5/rJsxIuDqj5/rJqExIuD25jNjLqlGhevhgpp.bat
MD5304f8f54fb79bb470f3ccddd2befc5dargibdcghzwpk.bat
SHA-1c7cfc5a1b4dee08427bc11d202be13723ff19b9brgibdcghzwpk.bat
SHA-25684e1476c6b21531de62bbac67e52ab2ac14aa7a30f504ecf33e6b62aa33d1fe5rgibdcghzwpk.bat
SSDEEP3:mKDDFGFOvsXoML14NLfpAdiFhMW4crWadADiK2XAFTcAWpMEyIt0EGXReL5cGTdx:hgFOvsoNLqioWRCZNwgEbt0EFBdkP0rgibdcghzwpk.bat
SHA-256ed0fd61bf82660a69f5bfe0e66457cfe56d66dd2b310e9e97657c37779aef65dWRSA.exe
MD5f9bf364f42f6e4d4bdc2cae74d6ca4ccSetup.exe
SHA-1b3759d5a6412d085556fb081fd710ce62f18687fSetup.exe
SHA-256510e9fa38a08d446189c34fe6125295f410b36f00aceb65e7b4508e9d7c4e1d1Setup.exe
SSDEEP196608:q3+W+dIynSobLcB4f4fxn37ZdCACjqu3ILkaCbJJsv6tWKFdu9Ck5Q7V:q3+WfeVHorZdyjV3/NFJsv6tWKFdu9ClSetup.exe
SHA-2566992aaad3c47b938309fc1e6f37179eb51f028536f8afc02e4986312e29220c0PRETTYOCEANApplicationdrs.bi
SHA-256fc31043b5f079ce88385883668eeebba76a62f77954a960fb03bf46f47dbb066
SHA-2567018240d67fd11847c7f9737eaaae45794b37a5c27ffd02beaacaf6ae13352b3safe.exe
MD53d29e9cdd2a9d76e57e8a3f9e6ed3643safe.exe
SHA-15ad94f5303aed57a9d4f0055f15076454840064asafe.exe
SHA-2565950b4e27554585123d7fca44e83169375c6001201e3bf26e57d079437e70bcdsafe.exe
SSDEEP98304:R4Hf6JMfWTMVWWqoMVBk+B4D79mXPepfDgsC8yVP2SuxHf846FAP01B7ZVzO:R4HFtqrVm+B4D7k94LHf8FAKcsafe.exe
domain-namesezname[.]cz
email-addrsnatch[.]vip[@]protonmail[.]com
email-addrdatasto100[@]tutanota[.]com
email-addrmailz13morales[@]proton[.]me
email-addrrussellrspeck[@]protonmail[.]com
email-addrrussellrspeck[@]seznam[.]cz
email-addrfunny385[@]proton[.]me
email-addrfunny385[@]swisscows[.]email
email-addrsn[.]tchnews[.]top[@]protonmail[.]me
SHA-1c8a0060290715f266c89a21480fed08133ea2614safe.exe
domain-nameairmail[.]cc
MD52202e846ba05d7f0bb20adbc5249c359
SHA-14115d2d15614503456aea14db61d71a756cc7b8c
SHA-2560965cb8ee38adedd9ba06bdad9220a35890c2df0e4c78d0559cd6da653bf740f
SSDEEP3:mKDDAREBIfOmdCflKCW:hUiFmctRW
MD5c95c81ca4e6b8153b458d29186e696bcsafe.exe
SHA-1f97f8f78abb205dda329d89143aae34ba04d13dfsafe.exe
SHA-25628e82f28d0b9eb6a53d22983e21a9505ada925ebb61382fabebd76b8c4acff7csafe.exe
SSDEEP49152:lQg2p4oH77z/vVYyuI2LxaafnQqrfHdYmGD2u24ccQ9B1AzA7NUkZ+no6pzUiFR+:9oRG2kZ+nxxEGBRHYFzupjUqvbdwjsafe.exe
MD53a24a7b7c1ba74a5afa50f88ba81d550UsersmcsadminDesktopDefenderControl.exe; DefenderControl.exe
SHA-15da4de1dbba55774891497297396fd2e5c306cf5UsersmcsadminDesktopDefenderControl.exe; DefenderControl.exe
SHA-256a201f7f81277e28c0bdd680427b979aee70e42e8a98c67f11e7c83d02f8fe7aeUsersmcsadminDesktopDefenderControl.exe; DefenderControl.exe
SSDEEP12288:baWzgMg7v3qnCi3ErQohh0F4JCJ8lnydQ79QudhzYOejoiQv2ju8S0c/J:uaHMv6CDrjRnydQu+ejMZ1RUsersmcsadminDesktopDefenderControl.exe; DefenderControl.exe
MD56d9d31414ee2c175255b092440377a88ghnhfglwaplf.bat
SHA-1c24aee8fa0a81a82fe73bf60e0282b1038d6ea80ghnhfglwaplf.bat
SHA-2562155a029a024a2ffa4eff9108ac15c7db527ca1c8f89ccfd94cc3a70b77cfc57ghnhfglwaplf.bat
SSDEEP3:mKDDFNoF9YojMA26bK40dlojMA2elK40dlojMA2wdwoK40dlvn:h4YPtkYeQtkYuwXt1nghnhfglwaplf.bat
MD554fe4d49d7b4471104c897f187e07f91bsfyqgqeauegwyfvtp.bat
SHA-118f963dbee830e64828991d26a06d058326c1ddbbsfyqgqeauegwyfvtp.bat
SHA-2566c9d8c577dddf9cc480f330617e263a6ee4461651b4dec1f7215bda77df911e7bsfyqgqeauegwyfvtp.bat
SSDEEP3:mKDDV1A2wdB6hn:hNuAhbsfyqgqeauegwyfvtp.bat
MD5891708936393b69c212b97604a982fedpxyicmajjlqrtgcnhi.bat
SHA-15b86cf095fe515b590d18b2e976d9e544c43f6capxyicmajjlqrtgcnhi.bat
SHA-256a80c7fe1f88cf24ad4c55910a9f2189f1eedad25d7d0fd53dbfe6bdd68912a84pxyicmajjlqrtgcnhi.bat
SSDEEP3:mKDDknnFHtu582k/KRx8VJBuqQWvn:hwFHc5k/Kn8JuGpxyicmajjlqrtgcnhi.bat
MD53d33a19bb489dd5857b515882b43de12ygariiwfenmqteiwcr.bat
SHA-10882f2e72f1ca4410fe8ae0fa1138800c3d1561dygariiwfenmqteiwcr.bat
SHA-2563295f5029f9c9549a584fa13bc6c25520b4ff9a4b2feb1d9e935cc9e4e0f0924ygariiwfenmqteiwcr.bat
SSDEEP3:mKDDV1A2eoVhn:hNewhygariiwfenmqteiwcr.bat
MD53e36d3dc132e3a076539acc9fcd5535cnllraq.bat
SHA-189be35c19a65b9e6f7a277e1a9f66ab76d024378nllraq.bat
SHA-256251427c578eaa814f07037fbe6e388b3bc86ed3800d7887c9d24e7b94176e30dnllraq.bat
SSDEEP3:mKDDV1A26n6hn:hN26hnllraq.bat
domain-namecock[.]li
mutexgcc-shmem-tdm2-use_fc_key

Provenance

Allegato ufficiale CISA · 2023-09-19T17:45:36Z

SHA-512: 689a34e87fe7e47081bcbcf710639700d23407cd959755f718544371edf75492f2e08f96457c723789f34b349979a9b128f39b37ffd113fe0579fb1d5d1b4470

Source
CISA Cybersecurity Advisories
Publishing entity
CISA
Entity type
National authority
Area
North America · US
Original language
en · translation in preparation
Publication
20/09/2023 14:00
Sharing
TLP:CLEAR
MITRE ATT&CK
T1005, T1012, T1021, T1021.001, T1027, T1036, T1057, T1059, T1059.003, T1070, T1070.004, T1071, T1071.001, T1078, T1078.002, T1110, T1110.001, T1112, T1133, T1486, T1490, T1555.005, T1562, T1562.001, T1562.009, T1569, T1569.002, T1583, T1583.003, T1590
Classification
Critical
Group attributed by the source
Snatch
Stated country
US

Action indicated by the source

Verificare e correggere con priorita i sistemi Internet-facing indicati dalla fonte; applicare MFA resistente al phishing, segmentazione e backup offline immutabili con prove di ripristino.

Official technical references

Open the original source