Rewterz Threat Alert – Cobalt Strike Malware- Active IOCs
December 27, 2022Rewterz Threat Alert – AveMaria RAT – Active IOCs
December 27, 2022Rewterz Threat Alert – Cobalt Strike Malware- Active IOCs
December 27, 2022Rewterz Threat Alert – AveMaria RAT – Active IOCs
December 27, 2022Severity
High
Analysis Summary
Panda stealer is a malicious program, a new variant of CollectorStealer, designed to collect and exfiltrate sensitive and personal data from infected computers. It primarily targets cryptocurrency to steal Bytecoin, Dash, Litecoin, and other crypto wallets. Panda can steal log-in credentials from VPN software (NordVPN), messaging platforms, and digital distribution services for video games. It can also take screenshots of the infected machine and steal information from browsers such as cookies, passwords, and credit cards. It places files in the %Temp% folder, which keeps stolen data under randomized file names before sending it to a command-and-control (C&C) server.
Spam campaigns have been used to propagate Panda stealer. It is also known to propagate through malicious Microsoft Office Excel files.
Impact
- Credential Theft
- Unauthorized Access
Indicators of Compromise
MD5
- d8893957a19642f899cc472fc705c7f4
SHA-256
- 39d3801ccfbeb255a58b591edb846b38e5efef1cd36e0aba54fec3d164e8d795
SHA-1
- 2050dd79819480e54dfb2203488b95492f620773
Remediation
- Block all threat indicators at your respective controls.
- Search for Indicators of compromise (IOCs) in your environment utilizing your respective security controls
- Patch and upgrade any platforms and software timely and make it into a standard security policy. Prioritize patching known exploited vulnerabilities and zero-days.
- Along with network and system hardening, code hardening should be implemented within the organization so that their websites and software are secure. Use testing tools to detect any vulnerabilities in the deployed codes.
- Enable two-factor authentication.
- Enable antivirus and anti-malware software and update signature definitions in a timely manner. Using multi-layered protection is necessary to secure vulnerable assets