logo

Everest — Technical Analysis (Windows)

ID: 66ed655c-e319-4f97-a858-dbc8decc7d2c

STIX ID: report--66ed655c-e319-4f97-a858-dbc8decc7d2c

Threat Score

78/100

Uploaded: 2026-06-10

Created by: dogesec

TLP:CLEAR
...
...
Technical analysis of the EVEREST .NET ransomware sample (SHA-256 1df92b...) detailing deobfuscation, dynamic API resolution, execution flow, propagation (SMB enumeration, Wake‑On‑LAN, mount of unlettered volumes), anti-analysis (process kills, memory-heurstic, DACL self-protection), recovery inhibition (VSS/restore point/backups deletion), encryption mechanics (AES-128-CBC derived from a System.Random seed wrapped with embedded RSA‑1024), and extensive IOCs including hashes, onion blog, contact email, mutex, file extension (.everest) and behavior indicators to support detection and response.