Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
July 27, 2022Rewterz Threat Advisory – CVE-2022-36336 – Trend Micro Apex One and Worry-Free Business Security Vulnerability
July 28, 2022Rewterz Threat Alert – APT32 Ocean Lotus – Active IOCs
July 27, 2022Rewterz Threat Advisory – CVE-2022-36336 – Trend Micro Apex One and Worry-Free Business Security Vulnerability
July 28, 2022Severity
High
Analysis Summary
A new Mirai variant is making the rounds called mirai_pteamirai. This botnet is one of the significant botnets targeting exposed networking devices running Linux. Mirai means ‘future’ in Japanese. This botnet is one of the active botnet and used to cause DDoS conditions. IP cameras, home routers, and other IoT devices are the common targets of this botnet.
Impact
- Server Outage
- Data Loss
- Website Downtime
Indicators of Compromise
MD5
- 6c201d3a14777d60079c35d4726e2c6b
- 98cf05a6be9e9c30b26ed01a0794f422
- d8e00c04f65a8389a3644c11af97d239
- 79b7530bc29d2046d8a6983d8facd096
- 7609076ac9d3187f42e89e4114999dad
SHA-256
- e3a26188c0737228268df423a81169eab7417cb89e8cfed15b18a14c2bc6fe12
- 9c12186fd540075822b166350ab99c5372d25ab9fc98c4bf2094e1a246378ea9
- b84c1ce9ae5f44c366252f0157d4d877375e45b7750e2e27a57295873dc2bd2a
- 20cb3b881029790396bb48977187c7acb39d725ea885a6ac0408a0b471c3d5fc
- 92a7701f2286c3cdb9429117a14c32c49a9a3c6047aa24f90b772ed6b8585525
SHA-1
- 26c024c571e422a5834b3cd7007bf93bfc034a06
- 50e50aff10ac5b8ae009438988323f71b3ab5d8f
- ca8e5c86aca9e2e70652d4bf656191688578fb6f
- d483e6d13786af34554903dc5ed1c30605553fdb
- e64efabc2e4d10cbdca86c41a9c0fcc587e58807
Remediation
- Upgrade your operating system.
- Don’t open files and links from unknown sources.
- Install and run anti-virus scans.