Rewterz Threat Advisory – CVE-2022-43402 – Jenkins Pipeline: Groovy Plugin Vulnerability
November 15, 2022Rewterz Threat Alert – BumbleBee Malware – Active IOCs
November 15, 2022Rewterz Threat Advisory – CVE-2022-43402 – Jenkins Pipeline: Groovy Plugin Vulnerability
November 15, 2022Rewterz Threat Alert – BumbleBee Malware – Active IOCs
November 15, 2022Severity
High
Analysis Summary
The AZORULT malware is an information stealer which was discovered in 2016. This malware steals IDs, browsing history, cookies, passwords, and other information. AZORult serves as a malware downloader and it was advertised on Russian underground forums as a way to extract sensitive data from compromised computers. Browser history, bitcoin, ID, cookies, and passwords can be stolen by this malware. Phishing emails and the Fallout Exploit Kit (EK), in combination with social engineering tactics, are the primary infection vectors for the AZORult virus. The virus can also act as a loader, allowing more malware to be downloaded
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 3600712041a90a57210ad5a348bd3e8b
- a60a4483b3d8eb2986dab873006b30fe
- 83bb70ad1fd458a7a1620a8fcb31feec
SHA-256
- 719bbac50a8e3fc4629004bd0be2b13fd06a03c14d5fefa7f5008362e5790f20
- c70985c46887e272e3cec4fc92570ae761461bc97f40382b2b7d2fa0a32e031f
- 0db7901cac4a2ef3a9335ea4ef7dddbb2a145b8cae7cc681b4a7dc2458da8dc4
SHA-1
- 2f6d24093e7ef5d040c5d8bc693c3021ba9de14d
- 7a0e788a65b9d6f69c543622539ea91f7d77dc41
- 1375d7e06c958103ae0578e2daf152809ecadb48
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.