Rewterz Threat Alert – Adwind Bypasses Microsoft ATP to Attack Utilities Industry

Thursday, August 22, 2019

Severity

Medium

Analysis Summary

A phishing campaign delivering Adwind (also known as JRAT or SockRat) to the utilities industry. The email attachment spoofs a PDF file but is actually the delivery mechanism for the notorious Adwind malware. The national grid utilities infrastructure is the primary target of the campaign. Adwind is designated as a MaaS (malware-as-a-service) and is available for use for a subscription fee. Its functions include taking screenshots, acquiring credentials from browsers (Chrome, IE, and Edge), webcam access, audio recording, file transfer, collecting system and user information, stealing VPN certificates, and a keylogger. The email is sent from a compromised account at Friary Shoes and requests the potential victim to open the PDF, sign it, and return the signed copy. The “attachment” looks like a PDF icon, but is actually a linked JPG that points to the initial payload. The payload is a JAR file, requiring Java to run. Clicking on the “attachment” begins the download and execution process. Once running, Adwind connects to its command and control server. Information harvested from the infected system is sent back to the CnC servers. Popular anti-virus software and analysis tools are disabled by using taskkill.exe.

Impact

Credential theft

Indicators of Compromise

IP(s) / Hostname(s)

  • 109[.]203[.]124[.]231
  • 194[.]5[.]97[.]28

Malware Hash (MD5/SHA1/SH256)

  • 0b7b52302c8c5df59d960dd97e3abdaf
  • 6b94046ac3ade886488881521bfce90f
  • 781fb531354d6f291f1ccab48da6d39f
  • 7f97f5f336944d427c03cc730c636b8f
  • a4e510d903f05892d77741c5f4d95b5d
  • c17b03d5a1f0dc6581344fd3d67d7be1

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the link/attachments sent by unknown senders.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 17, September 2019 Rewterz Threat Alert – Emotet Revival with Spam Emails Around the World
  • 17, September 2019 Rewterz Threat Advisory – CVE-2016-1409 – Cisco Products IPv6 Neighbor Discovery Crafted Packet Vulnerability
  • 17, September 2019 Rewterz Threat Alert – Phishing Attack Targets The Guardian’s Whistleblowing Site
  • 16, September 2019 Rewterz Threat Alert – InnfiRAT Malware Steals Litecoin And Bitcoin Wallet Information

Copyright © Rewterz. All rights reserved.