Clear, practical technology insights BSOD Code Lookup · Windows Error Code Lookup · Wi-Fi Troubleshooting · PC Troubleshooting Checklist

GIBON Extortion Code Spread Through Spam

Learn about GIBON extortion code spread through spam, who may be affected, and which practical steps users or administrators can take to reduce exposure.

Table of Contents

Learn about GIBON extortion code spread through spam, who may be affected, and which practical steps users or administrators can take to reduce exposure.

GIBON Extortion Code Spread Through Spam Overview

A new ransomware called GIBON, once again malspam (malware spread via email) attaches a malicious file and contains the download macro, installs the malicious code to blackmail the victim's computer.

Although there is not much information about this malspam, at least you know how to operate it and fortunately it can be decoded. So if you are a victim of this ransomware, download the file decryption tool here. https://download. bleepingcomputer. com/demonslay335/GibonDecrypter. zip

Why Is It Called GIBON Ransomware?

When a new malicious code appears, researchers often name the string found in the executable file or malware itself, suggesting a naming scheme.

When a new malicious code appears, researchers often name the string found in the executable file or malware itself Gibon Ransomware communicates with C2 server

GIBON's name comes from 2 locations. The first is the identification string (user agent) of GIBON used when communicating with C&C server. The second is the Admin panel. In the image below, you also see it calling itself 'GIBON coding machine'.

GIBON's name comes from 2 locations Admin control panel of GIBON

See also: 10 typical malware types

How Does GIBON Encrypt Computers?

Although detailed information on how to invade GIBON is not available, this is how it encrypts victim computer data. On startup, GIBON connects to the C&C server and registers the new victim by sending base64 encoded string containing timestamp, Windows version and 'register' string. It will tell C2 that this is a new victim.

C2 then sends a response containing the base64 encoded string used for extortion notice. Using the C2 server to create a blackmail notification instead of being made available to the executable file, the attacker can update it easily without having to run a new executable file.

When registering with C2, there will be a key code that encodes XOR sent to C2 based on base64 string, which is used to encrypt all files on the computer. The extension extension is. encrypt. In the process, GIBON periodically sends a ping to C2 to indicate that it is still encrypted.

When registering with C2, there will be a key code that encodes XOR sent to C2 based on base64 string, which is used Encrypted files have additional. encrypt extensions

Each encrypted folder will also have a separate extortion notice READ_ME_NOW. txt that provides paid information and instructions.

Each encrypted folder will also have a separate extortion notice READ_ME_NOW GIBON extortion notice

When completed, ransomware sends a message to C2 with a 'finish' string with a timestamp, a Windows version, and the number of encrypted files.

See also: Enable ransomware Controlled Folder Access on Windows 10

IOC Information About GIBON Ransomware

Hash SHA256: 30b5c4609eadafc1b4f97b906a4928a47231b525d6d5c9028c873c4421bf6f98 Related files READ_ME_NOW. txt

Email related bomboms123@mail. ru subsidiary: yourfood20@mail. ru

Notice of extortion

Attention! ?ã có t?p tin ???c t?p tin ?ã ???c xác th?c! ?? ph?c h?i t?p tin, ghi vào th?: bomboms123@mail. ru N?u b?n không nh?n ra câu tr? l?i t? th? này trong 24 gi?, r?i ghi vào tên chính c?a: b?nfood20@mail. ru

Security note: Threat conditions and vendor guidance can change. Install current updates and verify any advisory with the official vendor before taking action.

FAQ

Why does GIBON Extortion Code Spread Through Spam matter?

Learn about GIBON extortion code spread through spam, who may be affected, and which practical steps users or administrators can take to reduce exposure.

Who may be affected by this issue?

The impact depends on the affected product, version, account, device, or network. Review the article details and the vendor's current advisory to confirm whether your environment is exposed.

How can users reduce the risk?

Install current security updates, use official downloads, enable strong account protection, maintain tested backups, and follow the latest guidance from the relevant vendor.

Discussion

Reader Comments 0

Sign in with email or Google to join the discussion.