Rewterz Threat Alert – Phishing Campaign Regarding Emergency Financial Aid For Covid-19
December 4, 2020Rewterz Threat Alert – FormBook Malware – Active IOCs
December 4, 2020Rewterz Threat Alert – Phishing Campaign Regarding Emergency Financial Aid For Covid-19
December 4, 2020Rewterz Threat Alert – FormBook Malware – Active IOCs
December 4, 2020Severity
High
Analysis Summary
TrickBot is a banking Trojan which targets sensitive information and acts as a dropper for other malware. Trickbot is usually spread via malicious malspam campaigns. These campaigns send unsolicited emails that direct users to download malware from malicious websites or trick the user into opening malware through an attachment. Trickbot has a new functionality of called TrickBoot makes use of tools to check devices for well-known vulnerabilities that allow attackers to inject malicious code in the UEFI/BIOS firmware of a device. TrickBot performing reconnaissance for firmware vulnerabilities. This activity sets the stage for TrickBot operators to perform more active measures such as the installation of firmware implants and backdoors or the destruction (bricking) of a targeted device. It is quite possible that threat actors are already exploiting these vulnerabilities against high-value targets.
Impact
- Privilege escalation
- Financial data loss
- Credential theft
- Exposure of sensitive data
Indicators of Compromise
MD5
- 491115422a6b94dc952982e6914adc39
- cef670f443d2335f44a1838463ea44ed
- 257483d5d8b268d0d679956c7acdf02d
SHA-256
- c1f1bc58456cff7413d7234e348d47a8acfdc9d019ae7a4aba1afc1b3ed55ffa
- c065e39ce4e90a5a966f76d9798cb5b962d51a3f35e3890f91047acfefa8c58e
- ea0b9eecf4ad5ec8c14aec13de7d661e7615018b1a3c65464bf5eca9bbf6ded3
SHA1
- 55803cb9fd62f69293f6de21f18fd82f3e3d1d68
- 30aa28e6df66fe7b4ec643635df8187ede31db06
- fbf8b0613a2f7039aeb9fa09bd3b40c8ff49ded2
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.