logo

Everest CTI Report

ID: ee1d7f3b-9004-4615-8473-6ccb779230db

STIX ID: report--ee1d7f3b-9004-4615-8473-6ccb779230db

Threat Score

78/100

Uploaded: 2026-06-10

Created by: dogesec

TLP:CLEAR
...
...
This technical CTI report analyzes a ConfuserEx-protected .NET ransomware sample named EVEREST, describing per-sample RSA-1024-wrapped seeds, AES-128-CBC file encryption, pre-encryption lateral spread (ARP parsing + Wake-on-LAN + SMB share mounting), strong anti-tamper measures (self-DACL), backup/restore deletion, and numerous stable and sample-specific IOCs and hunting queries for detection and response.