Rewterz Threat Advisory – CVE-2022-30190: Zero Day in (MSDT) – Active IOCs
June 8, 2022Rewterz Threat Alert – Pandora Ransomware – Active IOCs
June 8, 2022Rewterz Threat Advisory – CVE-2022-30190: Zero Day in (MSDT) – Active IOCs
June 8, 2022Rewterz Threat Alert – Pandora Ransomware – Active IOCs
June 8, 2022Severity
High
Analysis Summary
LockBit ransomware takes as little as five minutes to deploy the encryption routine on target systems once it lands on the victim network. LockBit attacks leave few traces for forensic analysis as the malware loads into the system memory, with logs and supporting files removed upon execution. In one case, they found that the attack began from a compromised Internet Information Server that launched a remote PowerShell script calling another script embedded in a remote Google Sheets document. This script connects to a command and control server to retrieve and install a PowerShell module for adding a backdoor and establish persistence. To evade monitoring and go unnoticed in the logs, the attacker renamed copies of PowerShell and the binary for running Microsoft HTML Applications (mshta.exe); this prompted Sophos to call this a “PS Rename“ attack. The backdoor is responsible for installing attack modules and executes a VBScript that downloads and executes a second backdoor on systems restart.
Impact
- Security Bypass
- Information Theft
- Files Encryption
Indicators of Compromise
MD5
- 6586ef47dc8d1450d5f4987e5542daa3
- cf1f0b2d0e400a54ee1c2d14a1e7323d
- b16e827ee8db29cb90c85570f41b9409
SHA-256
- 166aed80bc00d55893d777524235bc89680c8c8192762aff186eee89def0062e
- 17685fa128c7acff236a0587903405b58d8d664b04ebaa49d00e45fc958acc32
- 17c6f4e45d44bd4c06212139f521976b87ed5a6ddcd0e4e5e978e64dabb3883f
SHA-1
- 50ad9c5bcb88574f6e9624ce332d3aea762945cb
- 9d10f97c0ca276aa0b3cbcf331e2edc7c75135d3
- ae319c1b25eebe9b6256d9efce5da495e7483c77
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment