Rewterz Threat Advisory – Multiple vulnerabilities fixed in VLC media player
August 21, 2019Rewterz Threat Alert – Banks All over the World Attacked by Silence Advanced Hackers
August 22, 2019Rewterz Threat Advisory – Multiple vulnerabilities fixed in VLC media player
August 21, 2019Rewterz Threat Alert – Banks All over the World Attacked by Silence Advanced Hackers
August 22, 2019Severity
Medium
Analysis Summary
A phishing campaign delivering Adwind (also known as JRAT or SockRat) to the utilities industry. The email attachment spoofs a PDF file but is actually the delivery mechanism for the notorious Adwind malware. The national grid utilities infrastructure is the primary target of the campaign. Adwind is designated as a MaaS (malware-as-a-service) and is available for use for a subscription fee. Its functions include taking screenshots, acquiring credentials from browsers (Chrome, IE, and Edge), webcam access, audio recording, file transfer, collecting system and user information, stealing VPN certificates, and a keylogger. The email is sent from a compromised account at Friary Shoes and requests the potential victim to open the PDF, sign it, and return the signed copy. The “attachment” looks like a PDF icon, but is actually a linked JPG that points to the initial payload. The payload is a JAR file, requiring Java to run. Clicking on the “attachment” begins the download and execution process. Once running, Adwind connects to its command and control server. Information harvested from the infected system is sent back to the CnC servers. Popular anti-virus software and analysis tools are disabled by using taskkill.exe.
Impact
Credential theft
Indicators of Compromise
IP(s) / Hostname(s)
- 109[.]203[.]124[.]231
- 194[.]5[.]97[.]28
Malware Hash (MD5/SHA1/SH256)
- 0b7b52302c8c5df59d960dd97e3abdaf
- 6b94046ac3ade886488881521bfce90f
- 781fb531354d6f291f1ccab48da6d39f
- 7f97f5f336944d427c03cc730c636b8f
- a4e510d903f05892d77741c5f4d95b5d
- c17b03d5a1f0dc6581344fd3d67d7be1
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the link/attachments sent by unknown senders.