Rewterz Threat Advisory – CVE-2022-35845 – Fortinet FortiTester Vulnerability
January 5, 2023Rewterz Threat Alert – NJRAT – Active IOCs
January 5, 2023Rewterz Threat Advisory – CVE-2022-35845 – Fortinet FortiTester Vulnerability
January 5, 2023Rewterz Threat Alert – NJRAT – Active IOCs
January 5, 2023Severity
Medium
Analysis Summary
GCleaner is a tool that acts as a fake PC cleaner and is also known as Fake Garbage Cleaner. This tool was observed at the beginning of 2019 when executed it drops a Azorult Password straler. Moreover, the website implements a Traffic Direction System(TDS) using IPLogger which drops different malware including Azorult, PredatorTheThieff, and Miners depending on the location of the victim. To avoid the detection by Anti-virus they changed their technique by distributing these malware through crack websites. When these cracks are executed, it emits various payloads. Depending on the country it emits various malware which includes STOP/DJVU ransomware, SmokeLoader, Redline, Amadey, Flicker, and Racoon Stealer. The countries that were mostly targeted were the US, EU, and CA.
Impact
- Information Theft
- Credential Theft
- Exposure of Sensitive Data
Indicators of Compromise
MD5
- 2631d1325f059487e736d8e40e9423c4
- 22caece1ce176ba51df3fede79203a28
- 14704a15758e82823cdc16ccb7fe69a2
- 00c85a38b379b37fe9cb38a0d7347f50
- 2991a27c8444236494cdf8c33f7b6057
- 40acaaad0f773f548a1f80aedcbd9e2f
SHA-256
- 10b1f8687ca7a02f11e0cba327253959a703c45e3f8cfd1cf16759f65a5e14da
- aa2aa5f565c57b53c56a898fe0ed6377aa0e631259491f3d2dd2057657fae9bf
- 8d9f6c573e9d1bc84adc379249d4aec84c49ff2eecdae48f31b34512b5b41867
- f7cc9f5bf4906481594e64f2a5d32796e358771130eaadaac6b9f69101637c45
- 30e97b6220e26448ad73cdbac0eda95f694f2b929025704f587d54d23d961240
- dc0d0569cf2ef8b1b90457c0371d8f517be928a8cead021a72ca78cc3bbd4824
SHA-1
- 2ca6e85188bf0b7fe285f2fa8af0565ae42bd1ad
- 73c7c3b03e4d96802ef2867b0dfc7acf6d5cf70e
- 4e4759b8cab98b0e344161951556643995607bf7
- ab77fa7153d9f8de2b2486c27e4c583f543948be
- dc90f9cd3ad62c78eb2ea9b76996a6f65c477118
- 0f1a47bcda08b20d01b85c8469896261e60586f4
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.