Rewterz Threat Advisory – Multiple Oracle Vulnerabilities
January 20, 2022Rewterz Threat Alert – IcedID banking Trojan – Active IOCs
January 20, 2022Rewterz Threat Advisory – Multiple Oracle Vulnerabilities
January 20, 2022Rewterz Threat Alert – IcedID banking Trojan – Active IOCs
January 20, 2022Severity
High
Analysis Summary
Cyber espionage actors, aka APT32 (OceanLotus Group), are carrying out intrusions into private sector companies across multiple industries and have also targeted foreign governments, dissidents, and journalists. APT32 leverages a unique suite of fully-featured malware, in conjunction with commercially available tools, to conduct targeted operations that are aligned with Vietnamese state interests. In their current campaign, APT32 has leveraged files that employ social engineering methods to entice the victim into enabling macros. Upon execution, the initialized file downloads multiple malicious payloads from remote servers. APT32 actors continue to deliver malicious attachments via spear-phishing emails. APT32 actors designed multilingual lure documents which were tailored to specific victims. Although the files had “.DRV” file extensions, the recovered phishing lures were web page archives that contained text and images
Impact
- Information Theft and Espionage
- Data exfiltration
Indicators of Compromise
Filename
- HPScanUI[.]dll
MD5
- 53dcd2d08e115b907c95fcfeccb9d23f
SHA-256
- 9fb87b5d86639702329056bcffc740342477ff595d52adf1d6323d696d26b694
SHA-1
- 1dad1b833a769ebf0a3b7b2b626f871fe626b087
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.
- Always be suspicious about emails sent by unknown senders.
- Never click on links/ attachments sent by unknown senders.