Rewterz Threat Advisory – CVE-2021-2189 – Oracle E-Business Suite Sales Offline Denial of Service
August 24, 2021Rewterz Threat Alert – Sodinokibi Ransomware – Active IOCs
August 24, 2021Rewterz Threat Advisory – CVE-2021-2189 – Oracle E-Business Suite Sales Offline Denial of Service
August 24, 2021Rewterz Threat Alert – Sodinokibi Ransomware – Active IOCs
August 24, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region.
Impact
- Exposure of Sensitive Data
- Credential Theft
- Information Theft and Espionage
Indicators of Compromise
Filename
- NvContainer[.]exe
MD5
- 7703fd3c5cf5d61e38755c2abc75f354
SHA-256
- 3b7e2f7a2169c20b1cae57d5616538cc7634ec6401c710c20f9e06366df0b1cd
SHA1
- 12800c9cccbdb92ebf783200b94984d2d4a5979c
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.