Rewterz Threat Alert – FormBook Malware – Active IOCs
March 28, 2022Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
March 28, 2022Rewterz Threat Alert – FormBook Malware – Active IOCs
March 28, 2022Rewterz Threat Alert – Agent Tesla Malware – Active IOCs
March 28, 2022Severity
High
Analysis Summary
BlackMoon, aka KRBanker, is a banking trojan it can steal financial and banking account information as well as other sensitive data. Blackmoon was discovered in 2014 by Fortinet researchers, and it is back again with a new campaign. Blackmoon used to attack the host with URLs, advertisements, and other web content. Once the host has been compromised it can open multiple pop-ups.
Impact
- Credential Theft
- Financial Loss
- Data Exfiltration
Indicators of Compromise
MD5
- abd386bd13baa8922393cdc627e4f8e3
- e77bbf34e50a3573e1a1dee4b9c1f6d8
SHA-256
- cdc98e5891eeb209b04680f8c32981c3c4dd64240f01e98b35efaa1d43f15bc7
- e9c321d5987986c891aee1d2e0aa5f06f406b7994a62cee0820c70b4f2e265c4
SHA-1
- 088694457cc5727bd1aaf61ad65405f3cbbce7d5
- 0b86d2a2feeaa384493ede9ed568a144cd4af16f
Remediation
- Block all the threat indicators at your respective controls.
- Search for IOCs in your environment.