• Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Press Release
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert – STOP (DJVU) Ransomware – Active IOCs
November 30, 2022
Rewterz Threat Alert – ZLoader Banking Trojan – Active IOCs
November 30, 2022

Rewterz Threat Alert – Heodo Malware – Active IOCs

November 30, 2022

Severity

High

Analysis Summary

Heodo is a malicious program that is a variant of Emotet. Emotet was first identified in 2014. This malware is mostly disseminated through spam emails (malspam). Malicious scripts, document files with built-in macros, or malicious links can all deliver the infection. Emotet has undergone a few alterations.”

Heodo malware can be used to download and execute other malware, steal personal or sensitive information, and so on. Heodo attack victims may incur a monetary loss, data loss, computer infection with additional viruses, identity theft, problems with online privacy, and other concerns. Threat actors use spam campaigns to deceive consumers into installing Heodo on their PCs. They send emails with a malicious Microsoft Word document that, when opened, requests access to information and modification or macros commands.

Impact

  • Credential Theft 
  • Information Theft 
  • Financial Loss

Indicators of Compromise

MD5

276d2ef178f1d319a7ab74aee99917bf
cdda16daa0aa2ead514cdfd1c0d912a7
67a284d0a8a8886aa50679f297c828b3
0b1ca8eb44d80598332d0ff9bc303925

SHA-256

09819925fdc296619617875dc4a026ed5657b455c0520c53729430e951e752f2
bfdc3d72a69f8b5d91dcd726788840e6aa5d3c748f71ef0cd047de44f85e2798
00dce1e20b8469aecc0938f2ddec66b813c12dedb50b0b67c3e6a3032c3ca0b0
a33353b8af41a2c8c526cf73db3a091e48056c4b5e4e0c1ec13f416bde627754

SHA-1

1d703d84368e0c53f6706276da6858bdd7df55e6
2f430c35f7f0e817aaddee94059f9bf235135d5f
2def3bde2c9a1b4b14b797727be214570ddd8bc1
2cae1ab2e5ed9e0700c01b3a1f825aa2e92dc05c

Remediation

  • Block all threat indicators at your respective controls. 
  • Search for IOCs in your environment.
  • Passwords – Ensure that general security policies are employed including: implementing strong passwords, correct configurations, and proper administration security policies.
  • Admin Access – limit access to administrative accounts and portals to only relevant personnel and make sure they are not publicly accessible.
  • WAF – Web defacement must be stopped at the web application level. Therefore, set up a Web Application Firewall with rules to block suspicious and malicious requests.
  • Patch – Patch and upgrade any platforms and software timely and make it into a standard security policy. Prioritize patching known exploited vulnerabilities and zero-days.
  • Secure Coding – Along with network and system hardening, code hardening should be implemented within the organization so that their websites and software are secure. Use testing tools to detect any vulnerabilities in the deployed codes.
  • 2FA – Enable two-factor authentication.
  • Antivirus – Enable antivirus and anti-malware software and update signature definitions in a timely manner. Using a multi-layered protection is necessary to secure vulnerable assets
  • Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.