Rewterz Threat Advisory – CVE-2021-34947 – NETGEAR R7800 Vulnerability
September 30, 2021Rewterz Threat Alert – SNAKE Ransomware – Active IOCs
September 30, 2021Rewterz Threat Advisory – CVE-2021-34947 – NETGEAR R7800 Vulnerability
September 30, 2021Rewterz Threat Alert – SNAKE Ransomware – Active IOCs
September 30, 2021Severity
High
Analysis Summary
On the Fourth of July weekend, around 200 organizations all over the world were hit with a ransomware attack. Investigators are calling this the “largest ransomware attack in history.” The REvil ransomware group exploited the Kaseya VSA tool used to perform client monitoring and patch management by MSPs. The gang initially compromised the VSA software, and then deployed their ransomware on the on-premise servers of enterprise networks. This is an ongoing attack and more than1500 organizations have been compromised as of yet. FBI is helping the company investigate this incident and organizations and vendors affected by the attack have also released advisories on patches and remediations for the attack. They are demanding $70 million
Impact
- Data Encryption
Indicators of Compromise
MD5
- 0dbae50a9ce32ca0c1dc37fe570b9381
- f0491be2ce02d018ee252d9eddc9944a
- b22b36ab1052d958ee6974cd2b4564a6
- 6b71048c123158f7ec3d2f06510bf1b7
SHA-256
- b70f49143b16037b761f22a310d79ce2d9e4e8481f546fe6e4722161a432c487
- 39da75a73e0be40ec37aa1d31f9755b6897e797262ab608bd1849710f218c13d
- c1188be02bfec96e946612d7b920abab3d10d3a9c098bef654823ae7bfa13c2b
- 4ceafc0a0b1f1a5f3615e7f293dc8728c0b679452081e59dccb734c8cbb907c8
SHA-1
- 6d0c3155078e5cf8b3605f0c98e2f580565aed24
- 28140abe6d74eb5a62027bb67a352144a285651f
- a9a150c4623fab3319b83b89034dc04037a404f4
- c3954e2788006386ffcf7d7d7faadaadfc19adbb
Remediation
- Block all threat indicators all your respective controls.
- Search for IOCs in your environment