Rewterz Threat Alert – New Version of Stantinko Group Linux Proxy Trojan Masquerades as httpd
November 25, 2020Rewterz Threat Alert – TrickBot Employs Clever New Obfuscation Trick to evade detection
November 26, 2020Rewterz Threat Alert – New Version of Stantinko Group Linux Proxy Trojan Masquerades as httpd
November 25, 2020Rewterz Threat Alert – TrickBot Employs Clever New Obfuscation Trick to evade detection
November 26, 2020Severity
High
Analysis Summary
Gamaredon, the Russia-backed advanced persistent threat (APT) threat actor that has been active since at least 2013 has reinforced its cyber warfare activities a new surge of Gamaredon APT attacks targeting users with template injection of malicious documents exploiting Microsoft Word vulnerability CVE-2017-0199. Attacker main target is to get control of the target system using the malicious document.The exploit document employs the template injection technique to install additional malware on the victim’s machine. Upon opening the document, it connects back to the hacker’s server to download the payload file.
Impact
- Code Execution
- Data Manipulation
- Device take over
Indicators of Compromise
MD5
- b841990b6f15fa26bbbb11e217229bf7
SHA-256
- c6fe85f16ddb68f8244e8a6518f02b998e15cbd94a56ef756cf14c36c82a2e2b
SHA1
- 8cf958b088d5cb3b1695f303df6decbe23b03cf2
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment