Date: 08/05/2026
Severity: High
Summary
The Gentlemen ransomware affiliate used LOLBAS techniques, scheduled tasks, and MSI payloads to deploy EtherRAT across Windows networks for persistent access, credential theft, privilege escalation, and lateral movement. EtherRAT retrieves its command-and-control (C2) domains from an Ethereum smart contract, enabling dynamic infrastructure rotation and arbitrary JavaScript execution through a Node.js runtime. The operator’s toolkit also included Mimikatz, LSASS dumping, Sliver, Chisel, Ligolo-ng, and Potato-family privilege escalation tools, demonstrating capabilities to achieve domain-wide ransomware deployment.
Indicators of Compromise (IOC) List
Domains/URLs | itemrange.com wiselystarting.com simultaneouslypower.com resumeacceptable.com publisherresolution.com |
IP Address | 193.233.202.17 146.103.127.44 77.110.126.46 77.110.122.137 77.110.122.58 38.110.228.43 38.110.228.125 38.110.228.33 185.117.72.215 185.45.193.151 50.114.167.112 |
Hash | EE6807A8ABFABCED22EE026E178A28DA64D13CC3408E224394FF6E5782FB9E1D
F659681525DEBDA69FE0865B2B27A42F684B1FDA66AA7398E80B84CC765C73C7
7567994310A9576B1F98DC672ECFA038F1D65084315F59E3883F9B6F24000073
73955566338ADFFB423C3B7608792963080DA780E8B7B2C2CD6B6B0CEF6F217F
86881B8E9D197AC2F734792DE48D5DFAEBE7CAFB6E35D49C5DD7FE6EB697230E
F609621698EAAD8C4683750FE8BD0E242349BE3EEA408DA593151FF877ED8AB6
FB94688ED37DFCB985A8A4D720230E5150956E1788D579B0A54B53A153FD2F2E
C7A80576FBD25057435652788591D13998DA272EDF627FC29D296684CEFC50E5
BD61C2880920BBFB86C12DF439DD1CA0258A10E532433698FD029AEF2A5B33F2
F4C87A1DF04274B7497CBF9A4619B946C915CF5210B6E2EAA2FEE1629F4FF196
756C2096F54C5497110C9D854625C3ED592873E566D532077CD7ADB4D10D4ADD
|
Gurucul Threat Detection and Incident Response (TDIR) Queries for Detection
Detection Query 1 : | domainname like "publisherresolution.com" or url like "publisherresolution.com" or siteurl like "publisherresolution.com" or domainname like "itemrange.com" or url like "itemrange.com" or siteurl like "itemrange.com" or domainname like "wiselystarting.com" or url like "wiselystarting.com" or siteurl like "wiselystarting.com" or domainname like "simultaneouslypower.com" or url like "simultaneouslypower.com" or siteurl like "simultaneouslypower.com" or domainname like "resumeacceptable.com" or url like "resumeacceptable.com" or siteurl like "resumeacceptable.com" |
Detection Query 2 : | dstipaddress IN ("38.110.228.33","185.45.193.151","77.110.122.137","77.110.126.46","38.110.228.43","146.103.127.44","50.114.167.112","38.110.228.125","193.233.202.17","77.110.122.58","185.117.72.215") or srcipaddress IN ("38.110.228.33","185.45.193.151","77.110.122.137","77.110.126.46","38.110.228.43","146.103.127.44","50.114.167.112","38.110.228.125","193.233.202.17","77.110.122.58","185.117.72.215") |
Detection Query 3 : | sha256hash IN ("F4C87A1DF04274B7497CBF9A4619B946C915CF5210B6E2EAA2FEE1629F4FF196","BD61C2880920BBFB86C12DF439DD1CA0258A10E532433698FD029AEF2A5B33F2","FB94688ED37DFCB985A8A4D720230E5150956E1788D579B0A54B53A153FD2F2E","EE6807A8ABFABCED22EE026E178A28DA64D13CC3408E224394FF6E5782FB9E1D","F659681525DEBDA69FE0865B2B27A42F684B1FDA66AA7398E80B84CC765C73C7","7567994310A9576B1F98DC672ECFA038F1D65084315F59E3883F9B6F24000073","73955566338ADFFB423C3B7608792963080DA780E8B7B2C2CD6B6B0CEF6F217F","86881B8E9D197AC2F734792DE48D5DFAEBE7CAFB6E35D49C5DD7FE6EB697230E","F609621698EAAD8C4683750FE8BD0E242349BE3EEA408DA593151FF877ED8AB6","C7A80576FBD25057435652788591D13998DA272EDF627FC29D296684CEFC50E5","756C2096F54C5497110C9D854625C3ED592873E566D532077CD7ADB4D10D4ADD")
|
Reference:
https://hunt.io/blog/the-gentlemen-etherrat-ethereum-smart-contract-c2#IOCs_and_Observables