Rewterz Threat Advisory –Multiple Linux Kernel Vulnerabilities
August 4, 2021Rewterz Threat Advisory –Multiple Vulnerabilities In Junos Space Log Collector
August 4, 2021Rewterz Threat Advisory –Multiple Linux Kernel Vulnerabilities
August 4, 2021Rewterz Threat Advisory –Multiple Vulnerabilities In Junos Space Log Collector
August 4, 2021Severity
Medium
Analysis Summary
Also known as “Racealer,” Racoon is used to steal sensitive and confidential information including login credentials, credit card information, cryptocurrency wallets and browser information (cookies, history, autofill) from almost 60 applications. Raccoon stealer is written in C++ and it has a wide range of methods and features for stealing data from popular browsers, email clients and cryptocurrency wallets. The malware is delivered via exploit kits that use browser-based vulnerabilities to redirect victims to landing pages injected with exploit codes. It’s also spread via phishing campaigns convincing targets to execute the malicious payload or macros. The malware gathers information about the machine like the OS arch and version, system language, hardware information and installed applications. In addition, it can take screenshots from the user’s machine if that was enabled by the attacker’s configuration. After fulfilling all its stealing capabilities, Raccoon gathers all the files that it wrote to the temp folder into one zip file named Log.zip. Now all it has to do is send the zip file back to the C&C server and delete all traces of itself.
Impact
- Data exfiltration
- Credential theft
- Theft of financial information
- Financial loss
Indicators of Compromise
MD5
- 49e7ffaf0602fb67ba7aa83b752024cc
- f0af15a2314afee90871fe75a1faa3a3
- 9fdc07eb09ef8721066b9e2f6b502d3f
- 2812dfa8b4046584e9809aee50ecbd4d
- 9a8c2ab3a3b48083e886ea9d3727ca20
- af330dc8f44e538e382b175398484068
- f94b1c83e0fdc0527f73a4219ed73125
- f739890443a157e89c1973e74db41ef7
- 3f78693234470a1a17d92dedbea1e8f6
SHA-256
- 55a37e33f6629f72348feb2e5152ac06f66f5fa9e50ae840aa1f37a8e57c4714
- 4ae2121a59907625840dfc680841abdd1cbb1646f0e46f3078b8f4e7d55f3d8e
- 799681dad39fec9ad2392e981960c35227bd6a7f225e4c83d4b8b71ab68afbfc
- d8ca0f951ce813217da5ba80013f3a2b3b78417a1ede6ca93925b91c39ca7425
- 862d67397e362a03338237b1c10d5d5f737f151fb3681bbddc08141add11247a
- 96705f492ccbba730a3745b9c27c836ff7b877c78f59d08b797a57faaebcd6ed
- 9eafc2a0a992162261c3da6ae7206ed2d1466d3280149469ff323402a7dc09f9
- 9f900d8fa07652fef51b583c5422ce011ce0940c59de8487d90ee0cabaeba530
- 6d0270e231953172e8198f15026e001fc0a16de639277d52bf7a6c5e160f6328
SHA-1
- 3c64cc911c7120a17e0c824bf49b5071b3cdc5c2
- 58a9d3200daf1b04a72c730b9a93b22b94bf5e25
- 89555c1f4629e9bc14472ab63d3dc5f917c6b5f8
- b27174217cb0bfed9b31b100509ca95655c1be87
- 1d5698610250e806e9994a444c7b149f24d358d5
- 79da00442b415855a6215e958d6069cfe526815f
- dce6202cbb00e6e50b0caced9da0ebe2884eb3a2
- 581fad349578ebcbf83fa306ee29c7716ded0643
- b035c72b90783b06538b960ed146330127682b35
Remediation
- Block the threat indicators at their respective controls.
- Do not download software from random sources on the internet.