Keep your eyes on these

VERY IMPORTANT

Security Articles

RSS

Zeppelin Ransomware Threat Assessment

released on 2021-04-06 @ 05:56:22 PM
Zeppelin is highly configurable, but maintains common methods for distribution and deployment found with many ransomware families today. Additionally, Zeppelin is often distributed via compromised websites or temporary command and control (C2) infrastructures that are active only during distribution. Further complicating things, recent Zeppelin variants include a sleep function that lasts for 26 seconds in an attempt to bypass dynamic analysis engines and sandboxes. Zeppelin also notably includes functionality that checks the victim’s country code to make sure it’s not running in Russia, Ukraine, Belarus or Kazakhstan.