Rewterz Threat Alert – Variant of Adwind RAT Targets Petroleum Sector

Monday, November 11, 2019

Severity

High

Analysis Summary

Adwind is a remote access Trojan known to evade detection upon entry and to communicate with a command-and-control server once connected. The Trojan can steal sensitive information, such as credentials, as well as spy through a user’s webcam and log a user’s keystoke activity. The new addition to the modified remote access Trojan uses multi-layer obfuscation by containing various file extensions to avoid detection, with iDefense suspecting it to be tailored specifically to this industry. The malware originated from compromised Westnet accounts.

Impact

  • Information Theft
  • Credential Theft
  • Unauthorized Access

Indicators of Compromise

Hostname

members[.]westnet[.]com[.]au

Source IP

185[.]205.210[.]48

URL

hxxp[:]//members[.]westnet.com[.]au/~

Remediation

  • Block the threat indicators at their respective controls.
  • Do not download files/software from random sources on the internet.

Data Sheets

Corporate Brochure


Our Story


Services


Solutions


Managed Security


Upcoming Rewterz Trainings/Events

Rewterz News

  • 6, December 2019 Rewterz Threat Advisory – CVE-2019-14899 – New Linux Vulnerability Inferring and hijacking VPN-tunneled TCP connections
  • 6, December 2019 Rewterz Threat Advisory – CVE-2019-18232 – ICS: Thales DIS SafeNet Sentinel LDK License Manager Runtime Privilege Escalation Vulnerability
  • 5, December 2019 Rewterz Threat Alert – “ZeroCleare” Targets Energy Sector in the Middle East
  • 5, December 2019 Rewterz Threat Alert – CStealer Trojan Targeting Chrome Passwords

Copyright © Rewterz. All rights reserved.