Rewterz Threat Alert – Qakbot (Qbot) Malware – Active IOCs
April 26, 2022Rewterz Threat Alert – Nanocore Rat – Active IOCs
April 26, 2022Rewterz Threat Alert – Qakbot (Qbot) Malware – Active IOCs
April 26, 2022Rewterz Threat Alert – Nanocore Rat – Active IOCs
April 26, 2022Severity
High
Analysis Summary
On the Fourth of July weekend, around 200 organizations all over the world were hit with a ransomware attack. Investigators are calling this the “largest ransomware attack in history.” The REvil ransomware group exploited the Kaseya VSA tool used to perform client monitoring and patch management by MSPs. The gang initially compromised the VSA software, and then deployed their ransomware on the on-premise servers of enterprise networks. This is an ongoing attack and more than1500 organizations have been compromised as of yet. FBI is helping the company investigate this incident and organizations and vendors affected by the attack have also released advisories on patches and remediations for the attack. They are demanding $70 million.
Impact
- Data Encryption
Indicators of Compromise
MD5
- e051009b12b37c7ee16e810c135f1fef
- 4a6ceabb2ce1b486398c254a5503b792
- adf0907a6114c2b55349c08251efdf50
SHA-256
- 5bc00ad792d4ddac7d8568f98a717caff9d5ef389ed355a15b892cc10ab2887b
- 4a76a28498b7f391cdc2be73124b4225497232540247ca3662abd9ab2210be36
- 3bb2f8c2d2d1c8da2a2051bd9621099689c5cd0a6b12aa8cb5739759e843e5e6
SHA-1
- 415b27cd03d3d701a202924c26d25410ea0974d7
- 08a1c43bd1c63bbea864133d2923755aa2f74440
- aa25ae2f9dbe514169f4526ef4a61c1feeb1386a
Remediation
- Block all threat indicators at your respective controls
- Search for IOCs in your environment.