Rewterz Threat Advisory – Multiple F5 BIG-IP Vulnerabilities
August 5, 2022Rewterz Threat Alert – APT Group Gamaredon – Active IOCs
August 5, 2022Rewterz Threat Advisory – Multiple F5 BIG-IP Vulnerabilities
August 5, 2022Rewterz Threat Alert – APT Group Gamaredon – Active IOCs
August 5, 2022Severity
High
Analysis Summary
The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded.
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 085b7c931de2158749766e0739a029f6
- 5ebd9c6dad66fedf677a043d9af0b504
- 53b6e86dceab78b1fd41076b86be6cc4
- 8bd13a7858764b487ae00b5394d59c75
SHA-256
- eaba8851c1f322461a569ff7b7cd06959eaf767d674c0958eec5e56f341b2054
- c5f1d36f5b7f70ffab8b430c730ff5b4a20d21cef6218e751ebd4feadb896b87
- a6bb4031f4f28bafd8e88002bdd2d7690f92019a67e19ffb4348e1b055f1e835
- 51440f5a52c3bea327dff5f79b0e875455719bcdf1d963af7637f26bddc90591
SHA-1
- 25bee38e68a72f1a41a232a0943d83c8c1584215
- 0184f7abe79a218311da4c39c553bda321f2f5da
- 855524589dac86f1a6e9eff45f5b08f3e5195034
- 9fbd31d4f97ca4405a9b7abbb4e22e2554fceeaa
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.