Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Severity
Medium
Analysis Summary
Recently, some threat actors distributed their malware by abusing Yandex.Direct and hosted it on GitHub. The group used two well-known backdoors — Buhtrap and RTM — as well as ransomware and cryptocurrency stealers. Malicious ads were posted through Yandex.Direct, aimed at redirecting a potential target to a website offering malicious downloads disguised as document templates.
The user must run the executable in order for it to work. Moreover, the cryptocurrency addresses associated with the ransom payment of this campaign are encrypted using RC4.
Impact
Indicators of Compromise
IP(s) / Hostname(s)
URLs
Filename
Malware Hash (MD5/SHA1/SH256)
Remediation