{"id":3579,"date":"2019-10-03T07:46:16","date_gmt":"2019-10-03T06:46:16","guid":{"rendered":"https:\/\/werle.pro\/?p=3579"},"modified":"2019-10-04T08:02:00","modified_gmt":"2019-10-04T07:02:00","slug":"ssi-atr-grandcrab-mcafee-analyzes-sodinokibi","status":"publish","type":"post","link":"https:\/\/werle.pro\/index.php\/2019\/10\/03\/ssi-atr-grandcrab-mcafee-analyzes-sodinokibi\/","title":{"rendered":"SSI ATR &#8211; GrandCrab &#8211; McAfee analyzes Sodinokibi"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-3578 alignnone size-full\" src=\"https:\/\/i0.wp.com\/werle.pro\/wp-content\/uploads\/2019\/10\/gandcrab-raas-model5112212314321597958.png?resize=1200%2C676&#038;ssl=1\" width=\"1200\" height=\"676\" srcset=\"https:\/\/i0.wp.com\/werle.pro\/wp-content\/uploads\/2019\/10\/gandcrab-raas-model5112212314321597958.png?w=1376&amp;ssl=1 1376w, https:\/\/i0.wp.com\/werle.pro\/wp-content\/uploads\/2019\/10\/gandcrab-raas-model5112212314321597958.png?resize=200%2C113&amp;ssl=1 200w, https:\/\/i0.wp.com\/werle.pro\/wp-content\/uploads\/2019\/10\/gandcrab-raas-model5112212314321597958.png?resize=768%2C433&amp;ssl=1 768w, https:\/\/i0.wp.com\/werle.pro\/wp-content\/uploads\/2019\/10\/gandcrab-raas-model5112212314321597958.png?resize=512%2C288&amp;ssl=1 512w\" sizes=\"(max-width: 1200px) 100vw, 1200px\" data-recalc-dims=\"1\" \/><\/p>\n<div class=\"entry-content\" id=\"atricle-content\">\n<h3><\/h3>\n<p>McAfee\u2019s Advanced Threat Research team (ATR) observed a new ransomware family in the wild, dubbed Sodinokibi (or REvil), at the end of April 2019.<\/p>\n<p>Around this same time, the GandCrab ransomware crew announced they would shut down their operations.<\/p>\n<p>Coincidence ? Or is there more to the story ?<\/p>\n<p>In this series of blogs, we share fresh analysis of Sodinokibi and<br \/>\nits connections to GandCrab, with new insights gleaned exclusively from McAfee ATR\u2019s in-depth and extensive research.<\/p>\n<ul>\n<li>Episode 1: What the Code Tells Us<\/li>\n<li>Episode 2: The All-Stars<\/li>\n<li>Episode 3: Follow the Money<\/li>\n<li>Episode 4: Crescendo<\/li>\n<li><\/li>\n<\/ul>\n<\/div>\n<p><a href=\"https:\/\/securingtomorrow.mcafee.com\/other-blogs\/mcafee-labs\/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us\/\">https:\/\/securingtomorrow.mcafee.com\/other-blogs\/mcafee-labs\/mcafee-atr-analyzes-sodinokibi-aka-revil-ransomware-as-a-service-what-the-code-tells-us\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>McAfee\u2019s Advanced Threat Research team (ATR) observed a new ransomware family in the wild, dubbed Sodinokibi (or REvil), at the end of April 2019. Around this same time, the GandCrab ransomware crew announced they would shut down their operations. Coincidence ? Or is there more to the story ? In this series of blogs, we &#8230; <a title=\"SSI ATR &#8211; GrandCrab &#8211; McAfee analyzes Sodinokibi\" class=\"read-more\" href=\"https:\/\/werle.pro\/index.php\/2019\/10\/03\/ssi-atr-grandcrab-mcafee-analyzes-sodinokibi\/\" aria-label=\"Read more about SSI ATR &#8211; GrandCrab &#8211; McAfee analyzes Sodinokibi\">Lire la suite<\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","enabled":false}}},"categories":[10],"tags":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p7ALXt-VJ","jetpack-related-posts":[],"_links":{"self":[{"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/posts\/3579"}],"collection":[{"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/comments?post=3579"}],"version-history":[{"count":2,"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/posts\/3579\/revisions"}],"predecessor-version":[{"id":3583,"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/posts\/3579\/revisions\/3583"}],"wp:attachment":[{"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/media?parent=3579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/categories?post=3579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/werle.pro\/index.php\/wp-json\/wp\/v2\/tags?post=3579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}