Rewterz Threat Alert – Donot APT Group – IOCs
June 28, 2021Rewterz Threat Alert – DanaBot Trojan – Active IOCs
June 28, 2021Rewterz Threat Alert – Donot APT Group – IOCs
June 28, 2021Rewterz Threat Alert – DanaBot Trojan – Active IOCs
June 28, 2021Severity
High
Analysis Summary
A new malware “Crackonosh” in part because of some possible indications that the malware author may be Czech. Crackonosh is distributed along with illegal, cracked copies of popular software and searches for and disables many popular antivirus programs as part of its anti-detection and anti-forensics tactics.
The main target of Crackonosh was the installation of the coin miner XMRig, from all the wallets, there was one where we were able to find statistics. The pool sites showed payments of 9000 XMR in total, that is with today prices over $2,000,000 USD.
Impact
- Credential Theft
- Data Exfiltration
Indicators of Compromise
SHA-256
- E497EE189E16CAEF7C881C1C311D994AE75695C5087D09051BE59B0F0051A6CF
- 65F39206FE7B706DED5D7A2DB74E900D4FAE539421C3167233139B5B5E125B8A
- 4B01A9C1C7F0AF74AA1DA11F8BB3FC8ECC3719C2C6F4AD820B31108923AC7B71
- 7F836B445D979870172FA108A47BA953B0C02D2076CAC22A5953EB05A683EDD4
- 93A3B50069C463B1158A9BB3A8E3EDF9767E8F412C1140903B9FE674D81E32F0
- 9EC3DE9BB9462821B5D034D43A9A5DE0715FF741E0C171ADFD7697134B936FA3
- D8C092DE1BF9B355E9799105B146BAAB8C77C4449EAD2BDC4A5875769BB3FB8A
- 6A3C8A3CA0376E295A2A9005DFBA0EB55D37D5B7BF8FCF108F4FFF7778F47584
- D7A9BF98ACA2913699B234219FF8FDAA0F635E5DD3754B23D03D5C3441D94BFB
- 8C52E5CC07710BF7F8B51B075D9F25CD2ECE58FD11D2944C6AB9BF62B7FBFA05
- C6817D6AFECDB89485887C0EE2B7AC84E4180323284E53994EF70B89C77768E1
Remediation
- Block the threat indicators at their respective controls.
- Do not download files attached in untrusted emails.
- Keep all systems and software updated to the latest patched versions.
- Enable multi-factor authentication.