{"id":219798,"date":"2019-08-01T11:07:04","date_gmt":"2019-08-01T09:07:04","guid":{"rendered":"https:\/\/www.intrinsec.com\/?p=219798"},"modified":"2019-08-01T11:07:04","modified_gmt":"2019-08-01T09:07:04","slug":"ransomware-wordpress","status":"publish","type":"post","link":"https:\/\/www.intrinsec.com\/en\/ransomware-wordpress\/","title":{"rendered":"An (almost) perfect ransomware distribution ecosystem"},"content":{"rendered":"<p>[et_pb_section fb_built=\u00a0\u00bb1&Prime; _builder_version=\u00a0\u00bb3.26.5&Prime;][et_pb_row _builder_version=\u00a0\u00bb3.26.5&Prime;][et_pb_column type=\u00a0\u00bb4_4&Prime; _builder_version=\u00a0\u00bb3.26.5&Prime;][et_pb_text _builder_version=\u00a0\u00bb3.26.5&Prime;]<\/p>\n<p><a href=\"https:\/\/www.intrinsec.com\/cert-intrinsec\/\" target=\"_blank\" rel=\"noopener noreferrer\">CERT Intrinsec<\/a> <strong>have faced many ransomware attacks this year<\/strong>, many interesting techniques were spotted when responding to these attacks including the uniqueness of samples, the use of advanced offensive tools and frameworks (ex. <em>Cobalt Strike)<\/em>, the use of powerful botnets with brute forcing capabilities (ex. <em>GoldBrute<\/em>) etc.<\/p>\n<p>While many researchers and security vendors have dissected these ransomware samples and came out with great papers and articles explaining the TTPs of the attackers, their motivations and how they get into victims systems; CERT Intrinsec didn\u2019t spot any deep dive in Watering holes-like techniques used for ransomware distribution and targeting (un)specific victims.<\/p>\n<p>The distribution technique that we are going to expose, even if it targets a given population, does not fit in targeted attacks behind any motivations. <strong>Threat actors, whom we are going to speak about target (un)specific users needing some type of documents, mostly French documents models or templates<\/strong>.<\/p>\n<p>&nbsp;<\/p>\n<h2><strong>Distribution Infrastructure <\/strong><\/h2>\n<p>The most remarkable part of these attacks is the infrastructure used to distribute and deliver their malicious samples, which consisted mainly of hacked WordPress legitimate websites. <strong>Malware distributed actively during this campaign was GandCrab<\/strong>, on its version 5.x.<\/p>\n<p>While we started tracking websites that threat actors were manipulating by adding malicious links to download ransomware samples, we spotted many redirection techniques when visiting the compromised pages or links.<\/p>\n<p>The page below represents an example of malicious content spotted ITW, which was present on a government website of Ministry of Finance:<\/p>\n<p>[\/et_pb_text][et_pb_image src=&quot;https:\/\/www.intrinsec.com\/wp-content\/uploads\/2019\/07\/1-2.png&quot; align=&quot;center&quot; _builder_version=&quot;3.26.5&quot; width=&quot;66%&quot;][\/et_pb_image][et_pb_text _builder_version=&quot;3.26.5&quot;]<\/p>\n<p style=\"text-align: center;\"><em><span style=\"color: #808080;\">\u00a0Malicious page on compromised website recovered from<\/span> <a href=\"http:\/\/web.archive.org\/web\/20190730082638\/http:\/webcache.googleusercontent.com\/search?q=cache:tdaIAkNgH5IJ:finance.gov.ms\/%3Fp%3D7805+&amp;cd=1&amp;hl=fr&amp;ct=clnk&amp;gl=fr\">Google cache<\/a><\/em><\/p>\n<p>&nbsp;<\/p>\n<p>The content added to this Montserrat government website was surprisingly in French (attribution indicator?), <strong>and many malicious URLs were embedded in the post that are maybe an indicator of SEO for malicious content distribution<\/strong>:<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=\u00a0\u00bb3.26.5&Prime; border_width_all=\u00a0\u00bb2px\u00a0\u00bb custom_margin=\u00a0\u00bb|-2px||0px|false|false\u00a0\u00bb custom_padding=\u00a0\u00bb22px|0px|22px|12px|false|false\u00a0\u00bb]<\/p>\n<p><strong>hxxp:\/\/www[.]itls[.]tech\/wordpress\/?p=5995<\/strong><\/p>\n<p><strong>hxxp:\/\/www[.]eips[.]nl\/index[.]php?p=3798 <\/strong><\/p>\n<p><strong>hxxp:\/\/dmuller[.]net\/wp\/?p=5643 <\/strong><\/p>\n<p><strong>hxxp:\/\/ereadcost[.]eu\/exemples-de-phrases-de-transition-dissertation\/ <\/strong><\/p>\n<p><strong>hxxp:\/\/mhpc[.]cz\/exemple-de-lettre-de-dommage-et-interet\/ <\/strong><\/p>\n<p><strong>hxxp:\/\/taylorboger[.]com\/wordpress\/?p=5345 <\/strong><\/p>\n<p><strong>hxxp:\/\/www[.]koob[.]com[.]sa\/exemple-de-diaporama-pour-le-parcours-avenir\/ <\/strong><\/p>\n<p><strong>hxxp:\/\/www[.]bettingtopplista[.]se\/exemple-de-la-fonction-si\/ <\/strong><\/p>\n<p><strong>hxxp:\/\/podestakada[.]pl\/?p=5174 <\/strong><\/p>\n<p><strong>hxxp:\/\/ashdeetech[.]com\/wp\/2018\/12\/14\/exemple-cas-pratique-controle-de-gestion\/<\/strong><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=\u00a0\u00bb3.26.5&Prime; custom_padding=\u00a0\u00bb14px|||||\u00a0\u00bb]<\/p>\n<p>The majority of these URLs were pointing, as discussed before, to document models and templates hosted on other websites. Pivoting on the first spotted URL, <strong>with a simple Google dork, we got the following results<\/strong>:<\/p>\n<p>[\/et_pb_text][et_pb_image src=&quot;https:\/\/www.intrinsec.com\/wp-content\/uploads\/2019\/08\/2.png&quot; _builder_version=&quot;3.26.6&quot; align=&quot;center&quot;][\/et_pb_image][et_pb_text _builder_version=&quot;3.26.5&quot;]<\/p>\n<p style=\"text-align: center;\"><span style=\"color: #808080;\"><em>Google Dork search<\/em><\/span><\/p>\n<p style=\"text-align: left;\"><span style=\"color: #808080;\"><\/span><\/p>\n<h2><strong>The two faced webpage<\/strong><\/h2>\n<p style=\"text-align: left;\"><span style=\"color: #000000;\">While navigating to the first URL, visiting the same webpage twice resulted in two different views, we were thinking of <strong>a traffic redirection system<\/strong> (most commonly used by Exploit Kits) and it was almost the case.<\/span><\/p>\n<p>[\/et_pb_text][et_pb_image src=&quot;https:\/\/www.intrinsec.com\/wp-content\/uploads\/2019\/07\/3-2.png&quot; align=&quot;center&quot; _builder_version=&quot;3.26.5&quot; width=&quot;87.4%&quot; min_height=&quot;436px&quot; custom_margin=&quot;|62px||61px||&quot; custom_padding=&quot;0px|1px|0px|0px||&quot;][\/et_pb_image][et_pb_text _builder_version=&quot;3.26.5&quot;]<\/p>\n<p style=\"text-align: center;\"><span style=\"color: #808080;\"><em>The first time visiting the webpage<\/em><\/span><\/p>\n<p>When navigating to the webpage for the first time, a<strong> fake forum page<\/strong> showed where a small conversation is simulated (or faked) where the threat actor pretends to be the admin and link a download to the (malicious) document\u2019s model. Look at the page above and remember it since we are going to find exactly the same template on many other compromised websites.<\/p>\n<p>[\/et_pb_text][et_pb_image src=&quot;https:\/\/www.intrinsec.com\/wp-content\/uploads\/2019\/08\/CaptureD.png&quot; align=&quot;center&quot; _builder_version=&quot;3.26.6&quot; width=&quot;88%&quot;][\/et_pb_image][et_pb_text _builder_version=&quot;3.26.5&quot;]<\/p>\n<p style=\"text-align: center;\"><span style=\"color: #808080;\"><em>The second time visiting the webpage<\/em><\/span><\/p>\n<p>Going back and refreshing the webpage, the fake forum page disappears and only a post shows to visitors. However, <strong>how come that the page disappears?<\/strong> The redirection system resulted because of a<strong> JavaScript element<\/strong> that we recovered from the website:<\/p>\n<p>[\/et_pb_text][et_pb_image src=&quot;https:\/\/www.intrinsec.com\/wp-content\/uploads\/2019\/07\/JS.png&quot; align=&quot;center&quot; _builder_version=&quot;3.26.5&quot; width=&quot;85%&quot;][\/et_pb_image][et_pb_text _builder_version=&quot;3.26.6&quot;]<\/p>\n<p>Threat actors were inviting the users to download the document from this URL, which seemed, after a quick investigation, that it is another<strong> compromised WordPress website<\/strong>.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=\u00a0\u00bb3.26.5&Prime; border_width_all=\u00a0\u00bb2px\u00a0\u00bb custom_padding=\u00a0\u00bb10px||10px|15px|false|false\u00a0\u00bb]<\/p>\n<p style=\"text-align: left;\"><strong>hxxp:\/\/www[.]zwoelfistei-haexe[.]ch\/file[.]php bqkytcptqvmkl=476b7051524b43796e2f5063335a704d65496857545477462b7451384b6e3168754a56676e386a384b495842763763396938427933436e30<\/strong><\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=\u00a0\u00bb3.26.5&Prime;]<\/p>\n<h2><strong><\/strong><\/h2>\n<h2><strong><\/strong><\/h2>\n<h2><strong><\/strong><\/h2>\n<h2><strong>Pivoting<\/strong><\/h2>\n<p>Pivoting using the <strong>same technique (Google dorks)<\/strong>, we found hundreds of many other compromised websites pointing to each other or hosting the fake forum webpage. Here are two screenshots taken from random compromised WordPress websites:<\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&quot;1&quot; _builder_version=&quot;3.26.5&quot;][et_pb_row column_structure=&quot;1_2,1_2&quot; _builder_version=&quot;3.26.5&quot; custom_margin=&quot;-1px|auto||auto||&quot;][et_pb_column type=&quot;1_2&quot; _builder_version=&quot;3.26.5&quot;][et_pb_image src=&quot;https:\/\/www.intrinsec.com\/wp-content\/uploads\/2019\/07\/5-1.png&quot; _builder_version=&quot;3.26.5&quot;][\/et_pb_image][\/et_pb_column][et_pb_column type=&quot;1_2&quot; _builder_version=&quot;3.26.5&quot;][et_pb_image src=&quot;https:\/\/www.intrinsec.com\/wp-content\/uploads\/2019\/07\/6.png&quot; _builder_version=&quot;3.26.5&quot;][\/et_pb_image][\/et_pb_column][\/et_pb_row][\/et_pb_section][et_pb_section fb_built=&quot;1&quot; _builder_version=&quot;3.26.5&quot;][et_pb_row _builder_version=&quot;3.26.5&quot;][et_pb_column type=&quot;4_4&quot; _builder_version=&quot;3.26.5&quot;][et_pb_text _builder_version=&quot;3.26.5&quot;]<\/p>\n<p>As discussed above,<strong> threat actors are using the same template<\/strong> (JavaScript displayed above) and are <strong>just changing documents\u2019 names and URLs pointing to the content<\/strong> (or payload) download links that are hosted on other compromised WordPress websites.<\/p>\n<p>The downloaded content or the distributed payload was<strong> a zip file including a multi-technology malware<\/strong> (JS launching a PowerShell dropper which decompress, load and execute a .NET DLL in memory). We will not dig into that payload since the main subject of this post aims to explain the distribution method and the attackers\u2019 infrastructure.<\/p>\n<p>Although we didn\u2019t find any posts explaining or describing this distribution ecosystem, we think that we are not the only ones that have faced this threat.<strong> The <em>Virus Total<\/em> <a href=\"https:\/\/www.virustotal.com\/graph\/g99aea3bd0748489fbfa776feed9bbeb85eece989b03e4abba0fe218ebd9d7ac8\">Graph <\/a>bellow was found while investigating on some compromised URLs<\/strong>, the owner of this graph is unknown, but content distributed by this compromised WordPress (rickrockwell[.]net) is, as you can see, <strong>GandCrab Ransowmare.<\/strong><\/p>\n<p>[\/et_pb_text][et_pb_image src=&quot;https:\/\/www.intrinsec.com\/wp-content\/uploads\/2019\/07\/7.png&quot; align=&quot;center&quot; _builder_version=&quot;3.26.5&quot;][\/et_pb_image][et_pb_text _builder_version=&quot;3.26.5&quot;]<\/p>\n<h2><strong><\/strong><\/h2>\n<p><strong><\/strong><\/p>\n<h2><strong><\/strong><\/h2>\n<h2><strong>Final thoughts <\/strong><\/h2>\n<p>Content analyzed during OSINT makes us believe that this campaign is <strong>targeting French speakers only<\/strong>. This technique of distribution, even if it is not advanced, <strong>works perfectly and may contaminates both enterprise environments<\/strong> (HR, Finance, etc.) and individuals who are often looking for documents\u2019 models and templates.<\/p>\n<p><strong>Tracking this type of campaigns is hard to automate<\/strong>, since Google dorks would be limited with captchas and since scanning every single page of a WordPress is not feasible. If you have any ideas that you would like to share, do not hesitate to get in touch with us.<\/p>\n<p><strong>Securing and monitoring your websites nowadays is necessary<\/strong>; threat actors are actively seeking vulnerable and unsecured websites to use them as part of their ransomware delivery infrastructure.<\/p>\n<p><strong>If you think that your employees could be potential victims of this threat, you should also start thinking of and implementing awareness training and sessions (phishing simulations, awareness campaigns, etc.).<\/strong><\/p>\n<p>Here is <strong>a Yara rue to add to your security tools or to use to scan your WordPress<\/strong> instances if you are running threat hunting programs or compromise assessments engagements.<\/p>\n<p>[\/et_pb_text][et_pb_text _builder_version=\u00a0\u00bb3.26.5&Prime; border_width_all=\u00a0\u00bb2px\u00a0\u00bb width=\u00a0\u00bb75%\u00a0\u00bb custom_margin=\u00a0\u00bb|480px|||false|false\u00a0\u00bb custom_padding=\u00a0\u00bb10px||10px|21px|false|false\u00a0\u00bb]<\/p>\n<p><strong>rule Compromised_WP {<\/strong><strong>\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0 meta:<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 author = \u00ab\u00a0CERT Intrinsec\u00a0\u00bb<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 description = \u00ab\u00a0Detect malicious fake forum pages used for ransomware distribution\u00a0\u00bb<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 date = \u00ab\u00a02019-07-26\u00a0\u00bb<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 reference = \u00ab\u00a0https:\/\/www.intrinsec.com\/blog\/ransomware-wordpress\u00a0\u00bb<\/strong><strong>\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0 strings:<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 $s1 = \u00ab\u00a0document.all[i].tagName\u00a0\u00bb<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 $s2 = \u00ab\u00a0Super Moderateur\u00a0\u00bb<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 $s3 = \u00ab\u00a0removeChild(elem);\u00a0\u00bb<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 $s4 = \u00ab\u00a0remove(elem) \u00ab\u00a0<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 $s5 = \u00ab\u00a0Voici un lien de\u00a0\u00bb<\/strong><strong>\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0 condition:<\/strong><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 <\/strong><\/p>\n<p><strong>\u00a0\u00a0\u00a0\u00a0\u00a0 all of them<\/strong><\/p>\n<p><strong>}<\/strong><\/p>\n<p>[\/et_pb_text][\/et_pb_column][\/et_pb_row][\/et_pb_section]<\/p>\n","protected":false},"excerpt":{"rendered":"<p>[et_pb_section fb_built=\u00a0\u00bb1&Prime; _builder_version=\u00a0\u00bb3.26.5&Prime;][et_pb_row _builder_version=\u00a0\u00bb3.26.5&Prime;][et_pb_column type=\u00a0\u00bb4_4&Prime; _builder_version=\u00a0\u00bb3.26.5&Prime;][et_pb_text _builder_version=\u00a0\u00bb3.26.5&Prime;] CERT Intrinsec have faced many ransomware attacks this [&hellip;]<\/p>\n","protected":false},"author":20,"featured_media":219767,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6,9],"tags":[],"class_list":["post-219798","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cert","category-cyber-threat-intelligence"],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v28.0 (Yoast SEO v28.1) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>An (almost) perfect ransomware - INTRINSEC<\/title>\n<meta name=\"description\" content=\"CERT Intrinsec have faced many ransomware attacks this year, many interesting techniques were spotted when responding to these attacks on wordpress...\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.intrinsec.com\/en\/ransomware-wordpress\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"An (almost) perfect ransomware distribution ecosystem\" \/>\n<meta property=\"og:description\" content=\"CERT Intrinsec have faced many ransomware attacks this year, many interesting techniques were spotted when responding to these attacks on wordpress...\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.intrinsec.com\/en\/ransomware-wordpress\/\" \/>\n<meta property=\"og:site_name\" content=\"INTRINSEC\" \/>\n<meta property=\"article:published_time\" content=\"2019-08-01T09:07:04+00:00\" \/>\n<meta name=\"author\" content=\"Omar Jbari\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:site\" content=\"@Intrinsec\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Omar Jbari\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"8 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/\"},\"author\":{\"name\":\"Omar Jbari\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/6c61b81e246cbf5d425243a65af1c5c5\"},\"headline\":\"An (almost) perfect ransomware distribution ecosystem\",\"datePublished\":\"2019-08-01T09:07:04+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/\"},\"wordCount\":1526,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"articleSection\":[\"CERT\",\"Cyber Threat Intelligence\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/\",\"name\":\"An (almost) perfect ransomware - INTRINSEC\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2019-08-01T09:07:04+00:00\",\"description\":\"CERT Intrinsec have faced many ransomware attacks this year, many interesting techniques were spotted when responding to these attacks on wordpress...\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/ransomware-wordpress\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\\\/\\\/www.intrinsec.com\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"An (almost) perfect ransomware distribution ecosystem\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#website\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"name\":\"INTRINSEC\",\"description\":\"Notre m\u00e9tier , Prot\u00e9ger le v\u00f4tre\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.intrinsec.com\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#organization\",\"name\":\"INTRINSEC\",\"alternateName\":\"ISEC\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"contentUrl\":\"https:\\\/\\\/www.intrinsec.com\\\/wp-content\\\/uploads\\\/2025\\\/02\\\/libellule.png\",\"width\":1322,\"height\":1322,\"caption\":\"INTRINSEC\"},\"image\":{\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/Intrinsec\",\"https:\\\/\\\/fr.linkedin.com\\\/company\\\/intrinsec\",\"https:\\\/\\\/www.youtube.com\\\/channel\\\/UC0trUZAHNZOUbxYnNdecM4A\"],\"description\":\"soci\u00e9t\u00e9 de consulting, pure player cybers\u00e9curit\u00e9 fran\u00e7ais et europ\u00e9en depuis plus de 30ans, sp\u00e9cialiste dans la s\u00e9curit\u00e9 offensive & audit (pentest\\\/red team), GRC, et services IMSS comme le SOC, CTI et CERT Intrinsec est qualifi\u00e9 PASSI Elev\u00e9, PRIS Elev\u00e9 et PACS par l'ANSSI\",\"email\":\"contact@intrinsec.com\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.intrinsec.com\\\/#\\\/schema\\\/person\\\/6c61b81e246cbf5d425243a65af1c5c5\",\"name\":\"Omar Jbari\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/?s=96&d=retro&r=g\",\"caption\":\"Omar Jbari\"},\"url\":\"https:\\\/\\\/www.intrinsec.com\\\/en\\\/author\\\/omar-jbari\\\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"An (almost) perfect ransomware - INTRINSEC","description":"CERT Intrinsec have faced many ransomware attacks this year, many interesting techniques were spotted when responding to these attacks on wordpress...","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.intrinsec.com\/en\/ransomware-wordpress\/","og_locale":"en_US","og_type":"article","og_title":"An (almost) perfect ransomware distribution ecosystem","og_description":"CERT Intrinsec have faced many ransomware attacks this year, many interesting techniques were spotted when responding to these attacks on wordpress...","og_url":"https:\/\/www.intrinsec.com\/en\/ransomware-wordpress\/","og_site_name":"INTRINSEC","article_published_time":"2019-08-01T09:07:04+00:00","author":"Omar Jbari","twitter_card":"summary_large_image","twitter_creator":"@Intrinsec","twitter_site":"@Intrinsec","twitter_misc":{"Written by":"Omar Jbari","Est. reading time":"8 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/#article","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/"},"author":{"name":"Omar Jbari","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/6c61b81e246cbf5d425243a65af1c5c5"},"headline":"An (almost) perfect ransomware distribution ecosystem","datePublished":"2019-08-01T09:07:04+00:00","mainEntityOfPage":{"@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/"},"wordCount":1526,"commentCount":0,"publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"image":{"@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/#primaryimage"},"thumbnailUrl":"","articleSection":["CERT","Cyber Threat Intelligence"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.intrinsec.com\/ransomware-wordpress\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/","url":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/","name":"An (almost) perfect ransomware - INTRINSEC","isPartOf":{"@id":"https:\/\/www.intrinsec.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/#primaryimage"},"image":{"@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/#primaryimage"},"thumbnailUrl":"","datePublished":"2019-08-01T09:07:04+00:00","description":"CERT Intrinsec have faced many ransomware attacks this year, many interesting techniques were spotted when responding to these attacks on wordpress...","breadcrumb":{"@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.intrinsec.com\/ransomware-wordpress\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/www.intrinsec.com\/ransomware-wordpress\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.intrinsec.com\/"},{"@type":"ListItem","position":2,"name":"An (almost) perfect ransomware distribution ecosystem"}]},{"@type":"WebSite","@id":"https:\/\/www.intrinsec.com\/#website","url":"https:\/\/www.intrinsec.com\/","name":"INTRINSEC","description":"Our job is to protect yours.","publisher":{"@id":"https:\/\/www.intrinsec.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.intrinsec.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.intrinsec.com\/#organization","name":"INTRINSEC","alternateName":"ISEC","url":"https:\/\/www.intrinsec.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","contentUrl":"https:\/\/www.intrinsec.com\/wp-content\/uploads\/2025\/02\/libellule.png","width":1322,"height":1322,"caption":"INTRINSEC"},"image":{"@id":"https:\/\/www.intrinsec.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/Intrinsec","https:\/\/fr.linkedin.com\/company\/intrinsec","https:\/\/www.youtube.com\/channel\/UC0trUZAHNZOUbxYnNdecM4A"],"description":"Intrinsec, a consulting firm and pure-play French and European cybersecurity provider for over 30 years, specializes in offensive security and auditing (penetration testing\/red teams), GRC, and IMSS services such as SOC, CTI, and CERT. Intrinsec is qualified at PASSI High, PRIS High, and PACS levels by ANSSI.","email":"contact@intrinsec.com"},{"@type":"Person","@id":"https:\/\/www.intrinsec.com\/#\/schema\/person\/6c61b81e246cbf5d425243a65af1c5c5","name":"Omar Jbari","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/?s=96&d=retro&r=g","caption":"Omar Jbari"},"url":"https:\/\/www.intrinsec.com\/en\/author\/omar-jbari\/"}]}},"_links":{"self":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/219798","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/users\/20"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/comments?post=219798"}],"version-history":[{"count":0,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/posts\/219798\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/media?parent=219798"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/categories?post=219798"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intrinsec.com\/en\/wp-json\/wp\/v2\/tags?post=219798"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}