Rewterz Threat Advisory – CVE-2019-5847 – Google Chrome V8 Denial of service Vulnerability
July 17, 2019Rewterz Threat Alert – EvilGnome Rare Malware Spying on Linux Desktop Users
July 18, 2019Rewterz Threat Advisory – CVE-2019-5847 – Google Chrome V8 Denial of service Vulnerability
July 17, 2019Rewterz Threat Alert – EvilGnome Rare Malware Spying on Linux Desktop Users
July 18, 2019Severity
High
Analysis Summary
A campaign recently identified and attribute to the Buhtrap Group. These threat actors have been linked to campaigns against Russian financial institutions but recently have expanded their operations to conduct espionage campaigns in Central Asian and Eastern European countries. They were observed utilizing several zero day vulnerabilities (CVE-2019-1132 and CVE-2015-2387) to attack their victims, most recently a government institution. Since being discovered in 2015, the group has added numerous tool sets to their arsenal, but their tactics, such as the use of decoy documents, remain relatively the same. This was the first known instance where the group exploited zero day vulnerabilities to attack their victims. The infection process begins when a user opens a Microsoft Word document, enables macros, and then ultimately downloads the malicious payload.
Impact
Privilege escalation
Indicators of Compromise
URLs
- https[:]//hdfilm-seyret[.]com/help/index[.]php
- https[:]//redmond[.]corp-microsoft[.]com/help/index[.]php
- https[:]//win10[.]ipv6-microsoft[.]org
- https[:]//services-glbdns2[.]com/FIGm6uJx0MhjJ2ImOVurJQTs0rRv5Ef2UGoSc
- https[:]//secure-telemetry[.]net/wp-login[.]php
Malware Hash (MD5/SHA1/SH256)
- 2f2640720cce2f83ca2f0633330f13651384dd6a
- e0f3557ea9f2ba4f7074caa0d0cf3b187c4472ff
- c17c335b7ddb5c8979444ec36ab668ae8e4e0a72
- 9c3434ebdf29e5a4762afb610ea59714d8be2392
Remediation
- Search for the existing IOC’s in your environment.
- Block all threat indicators at your respective controls.