Rewterz Threat Alert – Emotet – Active IOCs
December 8, 2021Rewterz Threat Alert – Remcos RAT – Active IOCs
December 8, 2021Rewterz Threat Alert – Emotet – Active IOCs
December 8, 2021Rewterz Threat Alert – Remcos RAT – Active IOCs
December 8, 2021Severity
Medium
Analysis Summary
A new info-stealing malware called Anubis was first observed in the cybercriminal underground. The malware uses forked code from Loki to steal vast amounts of data including system info, credentials, credit card details, and cryptocurrency wallets such as Bitcoin and Electrum. This malware should not be confused with the Android banking malware also named Anubis. At present, the new Anubis is being deployed in limited campaigns and contains only a handful of download URLs and C2 servers. This malware uses a text file to exfiltrate data from the victim.
Impact
- Information Theft
- Credential Theft
- Theft of Financial Information
Indicators of Compromise
SHA-256
- e7b65381c26dc596ecb6ebe077316a50a117a73281175be2e0d3781d66ad6951
- 49a737c094086e84c8edf6bda0ee5407ef28c8eb08a5e89516f3329aff1a3d45
- 8345ceec78b9c6f4c3a6589bf8f1e096a356e4be2c1c9cab2ef4aae0f8e76e74
- 82004d68c90f03287999315a5e8d3226b50331cb2a2dd1f390b8650139539c05
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.