

Rewterz Threat Alert – Ordinypt Malware Hitting Germany in New Spam Campaign
September 16, 2019
Rewterz Threat Alert – Phishing Attack Targets The Guardian’s Whistleblowing Site
September 17, 2019
Rewterz Threat Alert – Ordinypt Malware Hitting Germany in New Spam Campaign
September 16, 2019
Rewterz Threat Alert – Phishing Attack Targets The Guardian’s Whistleblowing Site
September 17, 2019Severity
Medium
Analysis Summary
As with just about every piece of malware, InnfiRAT is designed to access and steal personal information on a user’s computer. Among other things, InnfiRAT is written to look for cryptocurrency wallet information, such as Bitcoin and Litecoin. InnfiRAT also grabs browser cookies to steal stored usernames and passwords, as well as session data. In addition, this RAT has ScreenShot functionality so it can grab information from open windows. For example, if the user is reading email, the malware takes a screenshot. It also checks for other applications running on the system, such as an active antivirus program.
Impact
- Exposure of sensitive information
- Financial loss
- Credential theft
Indicators of Compromise
IP(s) / Hostname(s)
62[.]210[.]142[.]219
Malware Hash (MD5/SHA1/SH256)
f992dd6dbe1e065dff73a20e3d7b1eef
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the link/attachments sent by unknown senders.