Rewterz Threat Alert – ServHelper (aka HuadhServHelper) Malware Indicators of Compromise
June 24, 2019Rewterz Threat Alert – Waterbug Resurfaces with New Tool Kit
June 25, 2019Rewterz Threat Alert – ServHelper (aka HuadhServHelper) Malware Indicators of Compromise
June 24, 2019Rewterz Threat Alert – Waterbug Resurfaces with New Tool Kit
June 25, 2019Severity
High
Analysis Summary
The output of command, there is a service (Spiservice) which running on port 8043. The SpiService.exe is associated with XFS, the Extension for Financial Services DLL library (MSXFS.dll) that is specifically used by ATMs. The library provides a special API for the communication with the ATM’s PIN pad and the cash dispenser. The ATM tested by the expert is running Aglis XFS for Opteva version 4.1.61.1. Attempting to connect to the service via a web browser, experts noticed it calls many libraries, including a library called VDMXFS.dll.
Impact
Remote code execution
Affected Vendors
Diebold Nixdorf
Affected Products
Opteva version 4.x
Remediation
The attack can be mitigated by utilizing a properly configured, terminal-based firewall.