Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
June 30, 2021Rewterz Threat Alert – Donot APT Group – IOCs
June 30, 2021Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
June 30, 2021Rewterz Threat Alert – Donot APT Group – IOCs
June 30, 2021Severity
High
Analysis Summary
An emergent and effective data-harvesting tool dubbed Oski is proliferating in North America and China, stealing online account credentials, credit card numbers, crypto wallet accounts, and more. The malware is still in its developing phase but packs a punch with its capabilities. Oski C2’s dashboard revealed that Oski’s theft tactics involve extracting credentials using man-in-the-browser (MitB) attacks by hooking the browser processes using DLL injection, It also extracts credentials from the registry, passwords from the browser SQLite database, and stored session cookies of all stripes, including crypto-wallet cookies from Bitcoin Core, Ethereum, Monero, Litecoin, and others.
Impact
- Credential Theft
- Unauthorized access
Indicators of Compromise
MD5
- 8b044cbf9b624f6e661b20909a7ae5b2
- 1c1b93412ab9925460ee78ebf5c76a15
- 8d1a835aec4a08b9f3bd3be40c3de3e4
SHA-256
- f8a3701ae1544e20c1c05352b41e29d92af9a015670a7cf0830ed9cfa92d2638
- 89eb1caa50dfc398890c3490fef1d34527dd8505de3d770bb6ae7032ae22fd1f
- 6ab28a843d5ad26feee60448dfbbb5ddba73da6d5dc5a6a6fb9c0129bc7e3bf6
SHA-1
- cda7ae6c577616abeaedc22a7778df2c531286a7
- 0004689b4953642eddc67235f8ce294c2dfd7d1f
- c225f31c999580ba3d0bdbf2f2510eb43d583bc1
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the links/attachments sent by unknown senders.