Rewterz Threat Alert – CStealer Trojan Targeting Chrome Passwords

Thursday, December 5, 2019

Severity

Medium

Analysis Summary

A new CStealer trojan is found that targets Chrome passwords and exfiltrates them via mongoDB database at 18.220.85[.]117:27000, along with target system’s information.

EKjKP1ZUcAIVlwf.png

Impact

Credential Theft

Indicators of Compromise

MD5

181482ec53907fdba47e83b76795b196

SHA-256

00a1237e8faa646219744517b24cb4c8ebdbaa10d62e2b56fc25dffca832583c

SHA1

24cb0b03442d6b3f934031e06d60f5226a5dccda

Source IP

18.220.85[.]117

URL

http[:]//18.220.85[.]117:27000

Remediation

  • Block the threat indicators at their respective controls.
  • Keep web browsers patched against known vulnerabilities.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 10, January 2020 Rewterz Threat Advisory – CVE-2020-1600 – Juniper Networks Junos OS Denial of Service in the RPD daemon
  • 10, January 2020 Rewterz Threat Alert – Bank of America Phishing Campaign
  • 10, January 2020 Rewterz Threat Alert – LiquorBot Botnet
  • 10, January 2020 Rewterz Threat Advisory – CVE-2019-16005 – Cisco Webex Video Mesh Node Command Injection Vulnerability

Copyright © Rewterz. All rights reserved.