• Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Press Release
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert –Sodinokibi Ransomware – Active IOCs
August 12, 2021
Rewterz Threat Advisory –CVE-2021-30591 – Google Chrome Security Vulnerability
August 12, 2021

Rewterz Threat Alert –Raccoon Infostealer – Active IOCs

August 12, 2021

Severity

Medium

Analysis Summary

Also known as “Racealer,” Racoon is used to steal sensitive and confidential information including login credentials, credit card information, cryptocurrency wallets and browser information (cookies, history, autofill) from almost 60 applications. Raccoon stealer is written in C++ and it has a wide range of methods and features for stealing data from popular browsers, email clients and cryptocurrency wallets. The malware is delivered via exploit kits that use browser-based vulnerabilities to redirect victims to landing pages injected with exploit codes. It’s also spread via phishing campaigns convincing targets to execute the malicious payload or macros. The malware gathers information about the machine like the OS arch and version, system language, hardware information and installed applications. In addition, it can take screenshots from the user’s machine if that was enabled by the attacker’s configuration. After fulfilling all its stealing capabilities, Raccoon gathers all the files that it wrote to the temp folder into one zip file named Log.zip. Now all it has to do is send the zip file back to the C&C server and delete all traces of itself.

Impact

  • Data exfiltration
  • Credential theft
  • Theft of financial information
  • Financial loss

Indicators of Compromise

Domain Name

  • bbhmnn778[.]fun

MD5

  • 130e84f3410d8e798f4b98b8bd405ef8
  • 70d8341039b9cd0f26aa5adb2b9ff8cb
  • b7a3c17bab848b5ba2d1611040f70a91
  • 65af851236e69cb0cd15753d9c1317bf
  • 55c7ec11b9c80cf6ca17642f2ef18e80
  • 996ba35165bb62473d2a6743a5200d45
  • ee6186b0cd25ac5ca7ae401293d8552b
  • 5b4bd24d6240f467bfbc74803c9f15b0
  • b05cb04751b14de3a1c8c0bf50fc1b8b

SHA-256

  • f15ec4e938667248ae7ec3f0c754bafa8b1978cd5ee043755854783d78d06ab9
  • ea50f0afe88df5256b2f596b8ecde1f12779f496cd9a7d482d2182d6f789a57f
  • e950dd74f002df712925abe0c8ed18cc0cf38c53e5cb57eb68610e00da14c0f3
  • e10a97b02915dc3b2962603b9d173043906c4ecb865c7a8a64c6dcee66d30967
  • d9bb8e2ccfb5f98ca1097224493dc4f166291ee7b11fd13eaf9d0ef3cd379807
  • 5caffdc76a562e098c471feaede5693f9ead92d5c6c10fb3951dd1fa6c12d21d
  • 38b605f9fac77ac0bf9b13067a13fe02ac76ebee5fbd11a0e0ca869f268a6b3c
  • 14c7bec7369d4175c6d92554b033862b3847ff98a04dfebdf9f5bb30180ed13e
  • 1935d92f1fbc8a6ef85e72c7b25d80dabe8ea7db42c42446a3c01076c3aad750

SHA-1

  • 024ba07af6594fd80456059a6577830fea2ea3fc
  • 7aa293ae2e2f8145848d946684c19bf093b2af7a
  • d597cc5636221134990bee45e30fc0293850ac56
  • 0813f4dec9d2d5a3fdb68f6a56eb931481c973c0
  • 2478919a6e82d147bd146885133e0732b64bc87a
  • 52169b0b5cce95c6905873b8d12a759c234bd2e0
  • 82ee489d3988ba03240f9ac40f31789f15ad9fd2
  • c17f98c182d299845c54069872e8137645768a1a
  • cb24d65bad747c8ebc34e7160f524b227b6babbe

URL

  • http[:]//telete[.]in/jbitchsucks

Remediation

  • Block all threat indicators at their respective controls.
  • Do not download software from random sources on the internet.
  • Search for IOCs in your environment..
  • Services
    • Assess
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.