Rewterz Threat Alert – Adwind Bypasses Microsoft ATP to Attack Utilities Industry

Thursday, August 22, 2019



Analysis Summary

A phishing campaign delivering Adwind (also known as JRAT or SockRat) to the utilities industry. The email attachment spoofs a PDF file but is actually the delivery mechanism for the notorious Adwind malware. The national grid utilities infrastructure is the primary target of the campaign. Adwind is designated as a MaaS (malware-as-a-service) and is available for use for a subscription fee. Its functions include taking screenshots, acquiring credentials from browsers (Chrome, IE, and Edge), webcam access, audio recording, file transfer, collecting system and user information, stealing VPN certificates, and a keylogger. The email is sent from a compromised account at Friary Shoes and requests the potential victim to open the PDF, sign it, and return the signed copy. The “attachment” looks like a PDF icon, but is actually a linked JPG that points to the initial payload. The payload is a JAR file, requiring Java to run. Clicking on the “attachment” begins the download and execution process. Once running, Adwind connects to its command and control server. Information harvested from the infected system is sent back to the CnC servers. Popular anti-virus software and analysis tools are disabled by using taskkill.exe.


Credential theft

Indicators of Compromise

IP(s) / Hostname(s)

  • 109[.]203[.]124[.]231
  • 194[.]5[.]97[.]28

Malware Hash (MD5/SHA1/SH256)

  • 0b7b52302c8c5df59d960dd97e3abdaf
  • 6b94046ac3ade886488881521bfce90f
  • 781fb531354d6f291f1ccab48da6d39f
  • 7f97f5f336944d427c03cc730c636b8f
  • a4e510d903f05892d77741c5f4d95b5d
  • c17b03d5a1f0dc6581344fd3d67d7be1


  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the link/attachments sent by unknown senders.

Data Sheets

Corporate Brochure

Our Story



Managed Security

Upcoming Rewterz Trainings/Events

Rewterz News

  • 23, February 2020 Rewterz Threat Advisory – CVE-2019-16028 – Cisco Firepower Management Center
  • 17, February 2020 Rewterz Threat Alert – Satan ransomware rebrands as 5ss5c ransomware
  • 3, February 2020 Rewterz Threat Alert – Iranian Campaign Tailored to US Companies Introduces TONEDEAF 2.0
  • 3, February 2020 Rewterz Threat Alert – Spamhaus Phishing Scam Delivers Ursnif Malware

Copyright © Rewterz. All rights reserved.