Resource Library
Security BulletinsIncident ResponseRiskVisibilityFebruary 13, 2024

Conti Ransomware

CONTI RANSOMWARE — PROTECTING HEALTHCARE CUSTOMERS © 2021 ORDR, INC.

Detecting Conti Ransomware with ORDR

Introduction

The FBI Cyber Division on 20th May 2021 identified at least 16 Conti ransomware attacks over the past year.

Targets included:

• U.S. healthcare and first responder networks,

• law enforcement agencies,

• emergency medical services,

• 9-1-1 dispatch centers, and municipalities.

The FBI also stated that the Conti ransomware gang targeted close to 400 first responder networks worldwide; close to 290 of these organizations are located in the U.S. The average payment for Conti ransomware was $782,636, and systems were taken offline for an average of 14 days. This ransomware gang has recently breached Ireland’s Health Service Executive (HSE) networks and Department of Health (DoH), asking the former to pay a $20 million ransom after successfully encrypting its systems.

See the documentation at the following references:

https://www.coveware.com/conti-ransomware

https://www.bleepingcomputer.com/news/security/irelands-health-services-hit-with-20-million-ransomware-demand/

What Is the Conti Ransomware Gang?

Conti ransomware is a private Ransomware-as-a-Service (RaaS) controlled by a cyber gang, Wizard Spider. Conti shares some of its code with Ryuk ransomware and uses the same TrickBot distribution channels and Cobalt Strike beacons after Ryuk activity decreased around July 2020.

Timeline of Conti Ransomware

The Conti Ransomware infection will follow the timeline shown below:

1. Initial Access: IcedID execution

2. Discovery of Network: using IcedID

3. Privilege Escalation: Cobalt Strike named pipe impersonation

4. Lateral Movement: of Cobalt Strike Beacon.dll to Domain Controller

5. Recon: port scan from Domain Controller

6. Second Lateral Movement: transfer of Cobalt Strike beacon

7. Execution: Cobalt Strike beacon executed using PsExec

8. Impact: Group Policy updated / Windows Defender disabled / devices encrypted

Detection of Conti Using ORDR

ORDR SCE (Systems Control Engine) uses multi-faceted data to calculate the risk and security posture of every individual device in the protected network. The ORDR platform uses deep packet inspection to capture device data, including:

• Static attributes such as O.S. information of the device,

• Hotfixes deployed,

• Applications deployed,

• And the behavioral patterns of the device.

ORDR security capabilities includes an integrated Threat Detection Engine to detect exploits and lateral movement, and industry-leading threat intelligence to detect more than 1000 critical event types that point to vulnerable devices in the network. In addition, ORDR uses AI to map and baseline every device communications flow, complete with risk scores, to detect anomalous traffic.

The ORDR SCE solution includes the SCE Analytics Engine, and the ORDR SCE Sensors. The SCE Analytics Engine collects information in the ORDR Data Lake and processes it with machine learning and continuous analytics. The ORDR SCE Sensors inspects network traffic and sends metadata to SCE.

The following sections describe how ORDR SCE detects Conti Ransomware in its various phases.

Detection of Initial Access

ORDR SCE updates threat intelligence in real-time, and all communications with the IcedID IoC list* are marked risky.

vaclicinn.xyz
thulleultinn.club
oxythuler.cyou
dictorecovery.cyou
expertulthima.club
68.183.20.194:80
159.89.140.116:443
83.97.20.160:443

*IoCs obtained from:

https://thedfirreport.com/2021/05/12/conti-ransomware/

https://otx.alienvault.com/pulse/5f0781369d8978954c40d9f1

Detection of Lateral Movement

ORDR sensors deployed across the network include an integrated Threat Detection Engine that monitors all ingress-egress and east-west traffic and alerts on malicious activity and anomalous communication behavior. In the case of Conti, ORDR can detect the “Cobalt Strike” lateral movement.

ORDR SCE analyzes and baselines the traffic based on expected behavior, and any deviation from this normal traffic is marked as anomalous on the system.

Detection of Exfil

ORDR sensors deployed across the network include an integrated Threat Detection Engine that monitors all ingress-egress and east-west traffic, including detection of a complete suite of reconnaissance attacks like port scanning used to detect vulnerable devices in the network. Conti ransomware uses recon from domain controllers to detect vulnerable devices. The secondary transfer is based on the reconnaissance attack.

ORDR threat Intelligence can detect all I.P./URLs** marked for Conti domains as risky communications and increase the risk score of the device accordingly.

tapavi.com
ontirecovery.best
us/ky/louisville/312-s-fourth-st.html
23.106.160.174
23.82.140.137

**IoCs obtained from:

https://thedfirreport.com/2021/05/12/conti-ransomware/

https://otx.alienvault.com/pulse/5f0781369d8978954c40d9f1

Preventing Ransomware Attacks

ORDR SCE is a tool that provides complete visibility into all the connected assets in the enterprise. All assets are assigned a risk score, which is a measure of the riskiness of the device. In ransomware, all the devices that exhibited the above patterns will have a risky score level of critical and high. This will allow users to easily track and remediate these devices.

ORDR has the most comprehensive integrations in the industry, including deep integration with the firewalls and NAC vendors for immediate, automated response. Users will have an option to quarantine the devices based on the risky level or detection of any security event or behavior anomaly that point to a possibility of an attack in the enterprise.

Frequently asked questions
What are the primary initial access vectors used by Conti ransomware?
Conti typically gains initial access through exposed RDP services, phishing campaigns, and compromised credentials targeting internet-facing systems. ORDR's security bulletins document these specific vectors so organizations can deploy targeted detection controls and network segmentation to block compromise at the entry point.
How does Conti move laterally through healthcare networks?
Conti leverages legitimate administrative tools, credential harvesting, and network reconnaissance to move across segmented systems once inside the perimeter. Understanding these lateral movement techniques allows security teams to identify gaps in network monitoring and implement micro-segmentation controls aligned with ORDR's visibility and risk assessment methodology.
What indicators should security teams monitor to detect Conti data exfiltration?
Key indicators include unusual outbound traffic to unknown destinations, bulk data transfers to cloud storage, and reconnaissance activities before encryption deployment. ORDR's approach emphasizes real-time visibility into connected assets to catch exfiltration attempts before the final encryption stage maximizes damage to healthcare operations.

This resource is published by ORDR, the connected asset security company. ORDR delivers AI-powered visibility, risk assessment, and automated protection for IoT, OT, and IoMT devices across healthcare, manufacturing, government, and financial environments. Browse all resources →