Rewterz Threat Alert – Multiple Malspam Campaigns Dropping Different Malware – IoCs
March 19, 2019Rewterz Threat Alert – Multiple Phishing Campaigns – Indicators of Compromise
March 19, 2019Rewterz Threat Alert – Multiple Malspam Campaigns Dropping Different Malware – IoCs
March 19, 2019Rewterz Threat Alert – Multiple Phishing Campaigns – Indicators of Compromise
March 19, 2019Severity
Medium
Analysis Summary
Following threat indicators have been retrieved from multiple malware and phishing campaigns. These malicious IPs and domains are involved in dropping various Trojans and malware.
Impact
Andromeda
Generic Trojan
RETADUP
DarkGate
VBS.Unk
Chthonic
IcedID
Worm
Infostealer
Banking Trojan
Indicators of Compromise
IP(s) / Hostname(s) | 75.183.130[.]158 69.89.31[.]139 192.185.5[.]208 162.241.218[.]118 173.50.48[.]59 169.207.67[.]14 |
URLs | disorderstatus[.]ru differentia[.]ru changetheworld[.]bit newage[.]newminersage[.]com newage[.]radnewage[.]com utorrentsp2p[.]nz top[.]theandroidstore[.]tv atomary[.]bit centechnya[.]pw enversial[.]com jq[.]syrusdesign[.]com melbourg[.]ooo rogersbvrly0123.ddns[.]net |
Email Address | mmswholesaleltd[@]homdpot[.]com |
Malware Hash (MD5/SHA1/SH256) | 36ace63e783dd0ca36cb1e441c8ff249 132b9d25754543036c8913c35bea1c47 |
Remediation
Block the threat indicators at their respective controls.