date
02 August 2019 Friday. 15:08:22 UTC
scammer/abuser
GermanWiper
description
stadtmailer[.]com (46.166.129.227)
rasendmail[.]com (185.212.129.78)
nrwmail[.]com (46.166.129.223)
mailplatz[.]com (46.166.129.215)
moneymaker[.]software (178.33.106.120)
Writeup:
https://dissectingmalwa.re/tfw-ransomware-is-only-your-side-hustle.html
File Extensions
https://pastebin.com/rUGpEBfD
BleepingComputer Forum:
https://www.bleepingcomputer.com/forums/t/701735/germanwiper-ransomware-with-random-extensions-08kja-avco3-oqn1b/
Sandbox Analysis:
https://any.run/report/41364427dee49bf544dcff61a6899b3b7e59852435e4107931e294079a42de7c/52f1d8cc-a37f-4f1c-8624-ae761a48213a
https://www.vmray.com/analyses/41364427dee4/report/overview.html
Article:
https://www.pcrisk.com/removal-guides/15527-germanwiper-ransomware
Virustotal:
https://www.virustotal.com/gui/file/41364427dee49bf544dcff61a6899b3b7e59852435e4107931e294079a42de7c/community