Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs
June 15, 2021Rewterz Threat Advisory – CVE-2021-28814 – QNAP Releases Improper Access Control Vulnerability
June 15, 2021Rewterz Threat Alert – GuLoader Malspam Campaign – Active IOCs
June 15, 2021Rewterz Threat Advisory – CVE-2021-28814 – QNAP Releases Improper Access Control Vulnerability
June 15, 2021Severity
Medium
Analysis Summary
FormBook is an information-stealer malware that has been active since 2016. The info-stealer malware’s capabilities include stealing credentials, capturing screenshots of victim’s desktop, monitoring clipboard, keystroke logging, clearing browser cookies, downloading and executing files, uploading and removing bots, launching commands via ShellExecute, downloading and unpacking ZIP archive, rebooting and shutting down the system. The attackers behind these email campaigns used a variety of distribution techniques to deliver the FormBook info-stealer, including PDFs, Office Documents, ZIP, RAR, etc. Some of these files are related to quotation requests.
Impact
- Credential theft
- Keystroke logging
- System reboot
- Exposure of sensitive data
Indicators of Compromise
MD5
- 6cf088d03d07c5a47124fc64dc8be788
- 4c2e1efad8fd68181030911b131dce98
- 6e8cd3559c5dff28ec2650cc61158522
- 2cb81b073019a04a475626ad28126660
- 7700f7e6a086fba3c9518b57a13dc151
- 285cc0e41ca87f5eb2a6d08680a0f94b
- f0400b8eeaaf66d4baae0c682d3a16a3
SHA-256
- 634466056f4a9fc0952561871ed744d45ae535644f1a10252aeff5850d7048b7
- 40a2c949e7545544f4eea971311400c1aa7ea20524a9b2036346ea475407f95c
- a27f16e998de4089e6b263faca4025cd8271b35fe16cc97019140d09dd928463
- b8ede92590d43efb1edb31a19e4c28dc4fe4ecaf52be4bdd4ceae0a6caf26368
- d2a0fa2a17083c7a4f744218d0394f88610c34245bf1532efbf2153de97d1c62
- e6ee5b04ebf048d04e5e3c987a953b6f95a8eac0d741645796a3ee0aa948bd2c
- 7fe8fc25255d0fbe221579b985327bb67bb1226f39dfc71b8b59e6a2b15fff11
- 36f34d118ee0769d818d0cdb9b7562262e23233f97fd78c9280e8d5a7c390636
SHA1
- 29b3266053e4ee04e215d9a0f92d66e8e1c61627
- b1373058efc3fc46b68a576b18a68e24e937ceb8
- 6dccf254cb797072921d5c6e450fcac762d8c0cd
- de57413e7b4c0cae15131fa74b5575e1d9ba7e59
- 46984c29552c16135161154f51c9a0f4a9e6f3a1
- cb194a9597068cf2614a25e5df9881cb22fdbed6
- db9e8fc6765e44c47a3a693a1d52c853e5ac5c19
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.
- Do not download files attached in untrusted emails