<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Bad Rabbit in Threats</title>
    <link>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1600#M62</link>
    <description>Beware of the next Ransomware attack, Bad Rabbit is it's name. Read the article on &lt;A href="https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/Tibbar.A" target="_blank"&gt;https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/Tibbar.A&lt;/A&gt; to see how bit defender prevents te reboot and maybe the encryption process.</description>
    <pubDate>Thu, 26 Oct 2017 10:12:10 GMT</pubDate>
    <dc:creator>mattheer</dc:creator>
    <dc:date>2017-10-26T10:12:10Z</dc:date>
    <item>
      <title>Bad Rabbit</title>
      <link>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1600#M62</link>
      <description>Beware of the next Ransomware attack, Bad Rabbit is it's name. Read the article on &lt;A href="https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/Tibbar.A" target="_blank"&gt;https://www.microsoft.com/en-us/wdsi/threats/malware-encyclopedia-description?Name=Ransom:Win32/Tibbar.A&lt;/A&gt; to see how bit defender prevents te reboot and maybe the encryption process.</description>
      <pubDate>Thu, 26 Oct 2017 10:12:10 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1600#M62</guid>
      <dc:creator>mattheer</dc:creator>
      <dc:date>2017-10-26T10:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Bad Rabbit</title>
      <link>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1604#M63</link>
      <description>&lt;P&gt;A couple of Researchers&amp;nbsp;also pulling together some information:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://success.trendmicro.com/solution/1118637" target="_blank"&gt;https://success.trendmicro.com/solution/1118637&lt;/A&gt;&lt;BR /&gt;&lt;A href="https://blogs.forcepoint.com/insights/forcepoint-statement-bad-rabbit-cyber-attacks" target="_blank"&gt;https://blogs.forcepoint.com/insights/forcepoint-statement-bad-rabbit-cyber-attacks&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 10:18:43 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1604#M63</guid>
      <dc:creator>artfulbodger</dc:creator>
      <dc:date>2017-10-26T10:18:43Z</dc:date>
    </item>
    <item>
      <title>Re: Bad Rabbit</title>
      <link>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1609#M64</link>
      <description>&lt;P&gt;Some of the&amp;nbsp;domain name and&amp;nbsp;hash&amp;nbsp;values listed below. They need to blocked as much&amp;nbsp;as outer level&amp;nbsp;and hash-values need to be monitored.&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&amp;nbsp;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Domains:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;1dnscontrol.com&lt;/P&gt;&lt;P&gt;&lt;A href="http://diskcryptor.net/" target="_blank"&gt;http://diskcryptor.net/&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;File Hashes:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da&lt;/P&gt;&lt;P&gt;8ebc97e05c8e1073bda2efb6f4d00ad7e789260afa2c276f0c72740b838a0a93&lt;/P&gt;&lt;P&gt;afeee8b4acff87bc469a6f0364a81ae5d60a2add&lt;/P&gt;&lt;P&gt;b14d8faf7f0cbcfad051cefe5f39645f&lt;/P&gt;&lt;P&gt;de5c8d858e6e41da715dca1c019df0bfb92d32c0&lt;/P&gt;&lt;P&gt;fbbdc39af1139aebba4da004475e8839&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;1- File name:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;dispci.exe&lt;/P&gt;&lt;P&gt;Size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 140KiB (142848 bytes)&lt;/P&gt;&lt;P&gt;MD5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; b14d8faf7f0cbcfad051cefe5f39645f&lt;/P&gt;&lt;P&gt;SHA-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; afeee8b4acff87bc469a6f0364a81ae5d60a2add&lt;/P&gt;&lt;P&gt;SHA256&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 8ebc97e05c8e1073bda2efb6f4d00ad7e789260afa2c276f0c72740b838a0a93&lt;/P&gt;&lt;P&gt;File Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Win32 EXE&lt;/P&gt;&lt;P&gt;Other file names:&lt;/P&gt;&lt;P&gt;rabbit2.exe&lt;/P&gt;&lt;P&gt;ddd._exe&lt;/P&gt;&lt;P&gt;localfile~&lt;/P&gt;&lt;P&gt;payload_8ebc97e05c8e1073bda2efb6f4d00ad7e789260afa2c276f0c72740b838a0a93&lt;/P&gt;&lt;P&gt;8ebc97e05c8e1073bda2efb6f4d00ad7e789260afa2c276f0c72740b838a0a93.bin&lt;/P&gt;&lt;P&gt;dsc.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Imported files:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;ADVAPI32.dll&lt;/P&gt;&lt;P&gt;CRYPT32.dll&lt;/P&gt;&lt;P&gt;KERNEL32.dll&lt;/P&gt;&lt;P&gt;NETAPI32.dll&lt;/P&gt;&lt;P&gt;PSAPI.DLL&lt;/P&gt;&lt;P&gt;SHLWAPI.dll&lt;/P&gt;&lt;P&gt;USER32.dll&lt;/P&gt;&lt;P&gt;ole32.dll&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Runtime Process&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;8ebc97e05c8e1073bda2efb6f4d00ad7e789260afa2c276f0c72740b838a0a93.exe.bin&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;2- File Name&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;flash_install.php&lt;/P&gt;&lt;P&gt;FlashUtil.exe&lt;/P&gt;&lt;P&gt;File size&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 431.54 KB&lt;/P&gt;&lt;P&gt;MD5&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; fbbdc39af1139aebba4da004475e8839&lt;/P&gt;&lt;P&gt;SHA-1&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; de5c8d858e6e41da715dca1c019df0bfb92d32c0&lt;/P&gt;&lt;P&gt;SHA-256&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da&lt;/P&gt;&lt;P&gt;File Type&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Win32 EXE&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Other file names:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;BadRabbit.exe.virus&lt;/P&gt;&lt;P&gt;630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da.exe&lt;/P&gt;&lt;P&gt;630325cac09ac3fab908f903e3b00d0dadd5fdaa0875ed8496fcbb97a558d0da.bin&lt;/P&gt;&lt;P&gt;localfile~&lt;/P&gt;&lt;P&gt;Discoder BadRabbit RANSOMWARE&lt;/P&gt;&lt;P&gt;install_flash_player.exe&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Imported Files:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;KERNEL32.dll&lt;/P&gt;&lt;P&gt;SHELL32.dll&lt;/P&gt;&lt;P&gt;USER32.dll&lt;/P&gt;&lt;P&gt;msvcrt.dll&lt;/P&gt;</description>
      <pubDate>Thu, 26 Oct 2017 10:25:52 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1609#M64</guid>
      <dc:creator>Adeel</dc:creator>
      <dc:date>2017-10-26T10:25:52Z</dc:date>
    </item>
    <item>
      <title>Re: Bad Rabbit</title>
      <link>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1733#M65</link>
      <description>&lt;P&gt;Just a reminder to apply the latest signatures/definitions to your systems. Most products have already covered this threat in their latest update.&lt;/P&gt;</description>
      <pubDate>Sun, 29 Oct 2017 12:33:35 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Threats/Bad-Rabbit/m-p/1733#M65</guid>
      <dc:creator>Jason</dc:creator>
      <dc:date>2017-10-29T12:33:35Z</dc:date>
    </item>
  </channel>
</rss>

