Rewterz Threat Advisory – CVE-2021-1528 – Cisco SD-WAN Software Privilege Escalation Vulnerability
June 3, 2021Rewterz Threat Advisory – CVE-2021-26092 – FortiGate SSL VPN Portal Vulnerability
June 3, 2021Rewterz Threat Advisory – CVE-2021-1528 – Cisco SD-WAN Software Privilege Escalation Vulnerability
June 3, 2021Rewterz Threat Advisory – CVE-2021-26092 – FortiGate SSL VPN Portal Vulnerability
June 3, 2021Severity
Medium
Analysis Summary
An unknown threat actor has started a new campaign that is potentially targeting the Government sector and is targeting users with a phishing campaign and in that is a list of Afghan refugees that Pakistan have given refuge as part of the peace process in war-torn Afghanistan. This campaign is likely to be expanded to different sectors because of the nature of the sensitivity of the issue. Previously, these type of campaigns has been ignored in the past and users were carelessly clicking on the emails sent by threat actors and were robbed of with their credentials and other information.
Impact
- Information theft and espionage
- Data exfiltration
Indicators of Compromise
Filename
- List of Afg Refugees Hi School inside Qta[.]rtf
MD5
- 085e0260b49ef900f74aa69cc22c0ac2
SHA-256
- 9e0734e4fd3bbaa34e8717f8de8cbe441352ce590b319cb2e0450e909948f2f5
SHA1
- 18620ff4f38cc73fb7592867e00ed538a3a9b52c
URL
- hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/running[.]php
- hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/verison[.]php
- hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/Update/winservice_{num}[.]exe
- hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/Update/s_{num}[.]ps1
- hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/%20/api[.]php
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.
- Users are advised to look out for any emails with this subject.
- Always be suspicious about emails sent by unknown senders.
- Never click on links/ attachments sent by unknown senders.