Rewterz Threat Alert – Iranian APT Uses Job Scams to Lure Targets
November 18, 2019Rewterz Threat Alert – New JavaScript Skimmer Found on Ecommerce Sites
November 18, 2019Rewterz Threat Alert – Iranian APT Uses Job Scams to Lure Targets
November 18, 2019Rewterz Threat Alert – New JavaScript Skimmer Found on Ecommerce Sites
November 18, 2019Severity
High
Analysis Summary
Active IoCs have been retrieved linked to the Azorult malware, that target and infect victims with the Azorult stealer.
AZORult is a Trojan stealer that collects various data on infected computers and sends it to the C&C server, including browser history, login credentials, cookies, files from folders as specified by the C&C server (for example, all TXT files from the Desktop folder), cryptowallet files, etc.
The malware can also be used as a loader to download other malware. Indicators of compromise are given below.
Impact
- Credential Theft
- Exposure of sensitive information
Indicators of Compromise
Domain Name
dark-team[.]pw
MD5
- 622e4013a109c98ba384b8ae94ad1c80
- 8a409f6268cb227a491ebb833233605b
- cf964e65a1be0be2335c69886108601e
SHA-256
- 1e880dce0c52262a8c7c2dc3ed5b5daf0391ba58f77e3a48ef5e3c915bbcb7ad
- 29e50b5023569b3456abfae6a9c217ebfe35d96539cea8b2e3bef63bc3fee326
- 253c3edecb73720d031f2bc91d032f8e2092fb239808e2c7070fc9bb82d31826
SHA1
- f7cf88068f3909f4459e98bbe2e66ecd89a86975
- f0592fc9980dc22f05d467801246cde6d81a5130
- fd672d3b705dc0515bb38f513581edcf9d3f0a74
Remediation
- Block the threat indicators at their respective controls.
- Do not download/execute untrusted files.
- Do not respond to untrusted emails.
- Do not visit links attached in untrusted emails.