SGI서울보증 Gunra 랜섬웨어 상세 분석

2025-08-25 78Research Lab Detailed Analysis of SGI Seoul Guarantee Gunra Ransomware

https://blog.78researchlab.com/253db461-3e5b-805c-b0c6-e91ae76d5cd6

Thumbnail for SGI서울보증 Gunra 랜섬웨어 상세 분석

78ResearchLab analyzed Gunra ransomware in connection with the July 2025 SGI Seoul Guarantee incident and describes it as Conti-derived ransomware that commonly reaches victim servers through VPN, SSH, and RDP brute force or vulnerabilities. The sample dynamically resolves Windows APIs by obtaining kernel32.dll through the PEB and walking the IAT, reducing exposed imports while also preventing duplicate execution with the mutex kjsidugiaadf99439. Gunra uses CPU-based multithreaded encryption, generates ChaCha20 keys with CryptGenRandom, protects them with RSA-2048, encrypts up to the first 5 MB of files, and changes encrypted files to the .ECRT extension. It drops R3ADM3.txt ransom notes, excludes selected system folders and executable file types, and removes Windows shadow copies to obstruct recovery. The report provides MD5 and SHA256 hashes for the analyzed Microsoft Visual C++ sample.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 854e5f77f788bbbe6e224195e115c74… 2025-07-29 2025-09-23

Related Reports

« Back