Rewterz Threat Advisory – Fortinet FortiClientEMS And FortiAnalyzer Vulnerabilities
October 7, 2021Rewterz Threat Alert – Oski Data Stealer Malware – Active IOCs
October 7, 2021Rewterz Threat Advisory – Fortinet FortiClientEMS And FortiAnalyzer Vulnerabilities
October 7, 2021Rewterz Threat Alert – Oski Data Stealer Malware – Active IOCs
October 7, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name wesco_781138102_20211005_11414007_781138102.xls, and Manulife_policy.xls. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region
Impact
- Information Theft and Espionage
- Exposure of Sensitive Data
Indicators of Compromise
Filename
- wesco_781138102_20211005_11414007_781138102[.]xls
- Manulife_policy[.]xls
IP
- 185[.]202[.]93[.]201
MD5
- 97c8a4a020e91a415d49f77293db32b2
- 128a2d6105360896238515c941c67f88
SHA-256
- d6c487b1fb3d31851921b343f3d131f7cb4c0469a60484037a6fa8cfbdc29dea
- 4648edc370e61a52c95d3f525391e0154406fd661d01d091f2d9dba9f8a485f2
SHA-1
- 22d67ef270e69fdddd2a4a7a8986d575922fc14b
- b602a512b58a089d5b2df45cd43f778e811a9b83
URL
- http[:]//185[.]10[.]68[.]235/
- http[:]//185[.]183[.]96[.]147/?data=
- http[:]//194[.]180[.]174[.]6/
- http[:]//185[.]202[.]93[.]201/mlp[.]php?data=
- http[:]//185[.]225[.]19[.]156/
- http[:]//fidufagios[.]com/r?x=
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.