Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
High
Nanobot Backdoor updates their folder names and include the files to exfiltrate inside the folder: “F**theworld” to avoid detection. The first stage contacts a Russian domain to find out the public IP and geolocation. The second stage exfiltrates collected data. Earlier samples used to go through HTTP, but since the release of PTSecurity rules, they moved to HTTPS and to a different domain.
Exposure of sensitive information
Domain Name
hokage.ru
MD5
eed75304df013248b41bbea0cb2688c8
SHA-256
068ebfd30d5bb614f2922b093742e672b959c9480849fa3fb5cf720cb619bd26
SHA1
ee893d2e6ec91dd51428d7bb17047547816b3a68
URL
http[:]//hokage[.]ru/antivirus[.]php