Bert Ransomware Mapping the 185.100.157.74 Infrastructure
A new ransomware threat called Bert is targeting organizations across Asia, Europe, and the US, especially in healthcare, technology, and event services.

Bert Ransomware From IP to the whole infrastructure.
A new ransomware threat called Bert is targeting organizations across Asia, Europe, and the US, especially in healthcare, technology, and event services. This group uses both Windows and Linux variants, leveraging simple but effective code and fast, multi-threaded encryption to maximize damage and evade defenses.
Command and Control Server IP: 185.100.157.74
How Bert Operates:
Attackers use a PowerShell loader (start.ps1) to disable security tools, escalate privileges, and download the ransomware payload (payload.exe) directly from 185.100.157.74.
Staging Point:
This IP hosts open directories containing malware components, making it a central hub for Bert’s campaigns.
Russian Hosting:
The IP is registered in Russia, a common tactic to complicate attribution and takedown efforts.
Mapping with VirusTotal
Security teams use VirusTotal to:
Track Bert-related file hashes, PowerShell scripts, and payloads linked to 185.100.157.74
Uncover additional infrastructure, variants, and campaign overlaps
Block and monitor connections to this IP and associated domains
What to Do Now
Block IP 185.100.157.74 at your firewall and monitor for any related activity
Watch for suspicious PowerShell executions and unexpected downloads from external IPs
Update your threat intelligence feeds with Bert IOCs
Need Help?
Alpha Cyber provides:
Real-time monitoring for ransomware infrastructure
Proactive IOC blocking and threat hunting
Incident response and legal guidance for ransomware events
Don’t wait for Bert to strike, secure your network today!



