Rewterz Threat Alert – REvil Ransomware – Active IOCs
August 10, 2022Rewterz Threat Alert – Ramnit Malware – Active IOCs
August 10, 2022Rewterz Threat Alert – REvil Ransomware – Active IOCs
August 10, 2022Rewterz Threat Alert – Ramnit Malware – Active IOCs
August 10, 2022Severity
High
Analysis Summary
APT29 aka Nobelium and Cozy Bear are the group which were behind the infamous Solar Wind attacks in 2020. APT29 threat group has previously targeted commercial entities and government organizations in Germany, Uzbekistan, South Korea and the US, including the US State Department and the White House in 2014. They have also targeted several vaccine manufacturers in attempt to sabotage the process to combat the Coronavirus pandemic. This time they’ve come up with a current campaign to target government organizations in attempt to steal sensitive information.
Impact
- Information Theft and Espionage
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 6e651190979252ba4cfaf8aaf4bf2b32
- 5bc3b701819a4f2004b000d7db4b1b63
- 3b67048cadcbbd89c0ed05cc1a4c34be
- 6e651190979252ba4cfaf8aaf4bf2b32
- 72d4146e6c92013e4bb6776f0d87851e
SHA-256
- 280c6da5e9b3962be6bdc34aab1ab19cf64a92970a60e227a37a8d46c8decf7e
- dd29a6b5c62d8726a3073b6f7d20e6f34d00616de61fc55d04bda9e7824cd598
- f1e36937ed970fb185cb8d2b1fe99b1ffd781245d298f28cdce8812f6536a7a1
- 280c6da5e9b3962be6bdc34aab1ab19cf64a92970a60e227a37a8d46c8decf7e
- 80591e810f1cb94cead1cff9dff96ab0d004cbb063c6f9fc3ca55c1b5da2fe2e
SHA-1
- 6b0155a1e01894cb5e9b06ff102355df8bd8eb1f
- e7720ab728cb18ea329c7dd7c9b7408e266c986b
- cbc760225e2cb591c5478f756d535439a7e4bc8e
- 6b0155a1e01894cb5e9b06ff102355df8bd8eb1f
- 925753d36c590da4fe2d08ee684c4b3a60337130
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment