A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #29113  by CloneRanger
 Sat Aug 27, 2016 4:19 am
Re - fairware@sigaint.org in the ransom.

As soon as i saw sigaint.org it immediately rang a bell ! Here's where i remember seeing it listed - https://citizenlab.org/2016/08/million- ... -group-uae

Of course it "could" just be a concidence that the same @ is being used ? Hopefully others can look deeper into it, and post their findings, on here and/or elsewhere ;)
 #29116  by hx1997
 Sat Aug 27, 2016 9:26 am
CloneRanger wrote:Re - fairware@sigaint.org in the ransom.
A quick Google search revealed that sigiant.org is a darknet email service capable of sending mails to .onion addresses. Thus they could be just unrelated. Still, thanks for the info!
 #29120  by CloneRanger
 Sat Aug 27, 2016 9:45 pm
darknet email service, so it is just a coincidence then, Thanx, & for the link. Good catch !