Rewterz Threat Advisory – CVE-2022-22931 – Apache James directory traversal Vulnerability
February 8, 2022Rewterz Threat Alert – Vidar Malware – Active IOCs
February 8, 2022Rewterz Threat Advisory – CVE-2022-22931 – Apache James directory traversal Vulnerability
February 8, 2022Rewterz Threat Alert – Vidar Malware – Active IOCs
February 8, 2022Severity
High
Analysis Summary
NetWire is a remote access tool and a malicious program (RAT). RATs are often used to remotely access and manipulate computers. These programs can be used for lawful purposes by system administrators to get access to client systems, but they can also be used for malicious purposes. NetWire is a keylogger used by cybercriminals to collect data from USB card readers and other peripheral devices. This sends emails containing potentially dangerous files. The malware gets downloaded into the victim’s machine after the victim clicks on it. Crooks frequently use PDF, Word, and IMG files as shared files for their malware payloads.
Impact
- Sensitive Data Exposure
- Information Theft
- Keylogging
Indicators of Compromise
Filename
- sy4Xc[.]exe
- keqaikxf[.]dll
- sqlclient[.]exe
MD5
- afb7b1b29f82dd547cd5bd02788cee09
- dcbf37b8eaee657ed77795753e65ae39
- 31555a4c2e03324d43105121aec58155
SHA-256
- 979006b7422b4d2be9876c85263dabfe9d15e52dbf63bdff41bff04be2475d01
- 4beb785c349edcd431c027e3f05ee4fbdda6f5cb640a8a85ab38bcb0caa13644
- f74fe2e268460819040182e30bc54b5b787e0fb819cc8bc54b37ec43f5eb354a
SHA-1
- b3e881066fc10fc7921dd0382ffb7a3c296c6cdf
- fafd15eda45803d10c98edf271f79410f81a9f39
- fd54235feca6e2ec63d28fd148af74d546446ce2
Remediation
- Block all the threat indicators at your respective controls.
- Search for IOCs in your environment.
- Always be suspicious about emails sent by unknown senders.
- Never click on the links/attachments sent by unknown senders