• Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Transform
      • SOC Consultancy
      •     SOC Maturity Assessment
      •     SOC Model Evaluation
      •     SOC Gap Analysis
      •     SIEM Gap Analysis
      •     SIEM Optimization
      •     SOC Content Pack
    • Train
      • Security Awareness and Training
      • Tabletop Exercise
      • Simulated Cyber Attack Exercises
    • Respond
      • Incident Response
      • Incident Analysis
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
Rewterz Threat Alert – Tofsee Malware Resurfaces with Fresh IoCs
September 23, 2019
Rewterz Threat Advisory – CVE-2019-1367 – Internet Explorer Scripting Engine Memory Corruption Vulnerability
September 24, 2019

Rewterz Threat Alert – ATM’s Targeted via North Korean Malware ATMDtrack

September 24, 2019

Severity

High

Analysis Summary

North Korean hackers have developed and have been observed using a new malware strain that can be planted on ATM systems and used to record and steal data from payment cards inserted into a machine. Named ATMDtrack, this new malware has been spotted on the networks of Indian banks since late summer 2018. Newer attacks have also targeted Indian research centers with a more potent and expanded version of the same malware, named DTrack, which focuses on spying and data theft, rather than financial crime, and comes with features normally found in remote access trojan (RAT).

Recent DTrack samples can perform the following operations:

  • Keylogging,
  • Retrieve browser history,
  • Gather host IP addresses, information about available networks and active connections,
  • List running processes,
  • List files on all available disk volumes.

Impact

  • Financial loss
  • Exposure of sensitive information

Indicators of Compromise

Malware Hash (MD5/SHA1/SH256)

  • 774b530f996d783cf9564d88840f36bbb9748fbd9356b86a08360926ca293ec8
  • 1850fcb50168c4f61230cca40ee869bff038aff1bbcd4310c18b9effe3edaa2e
  • 16db0063e4aa666d94752414549fa09fb33142481d894b01a0fae45b339a09fb
  • e983e86e12a57e80a22368626f99123dd0cb6f4664f7991b691f9d2f9a50d2c6
  • 5f71d7511bdd0b236d05b35396eddc20eae57ab2561f09ff62f212f32ef310cc
  • 3a3bad366916aa3198fd1f76f3c29f24
  • 8f360227e7ee415ff509c2e443370e56
  • f84de0a584ae7e02fb0ffe679f96db8d
  • 9d9571b93218f9a635cfeb67b3b31e211be062fd0593c0756eb06a1f58e187fd
  • 58fef66f346fe3ed320e22640ab997055e54c8704fc272392d71e367e2d1c2bb
  • fe51590db6f835a3a210eba178d78d5eeafe8a47bf4ca44b3a6b3dfb599f1702

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the link/attachments sent by unknown senders.
  • Services
    • Asses
      • Compromise Assessment
      • APT Assessment
      • Penetration Testing
      • Secure Architecture Design & Review
      • Red Team Assessment
      • Purple Team Assessment
      • Social Engineering
      • Source Code Review
    • Respond
      • Incident Response
      • Incident Analysis
  • Transform
    • SOC Consultancy
    •     SOC Maturity Assessment
    •     SOC Model Evaluation
    •     SOC Gap Analysis
    •     SIEM Gap Analysis
    •     SIEM Optimization
    •     SOC Content Pack
  • Train
    • Security Awareness and Training
    • Tabletop Exercise
    • Simulated Cyber Attack Exercises
  • Managed Security
    • Managed Security Monitoring
      • Remote SOC
      • Onsite SOC
      • Hybrid SOC
    • Managed Security Services
      • Managed Detection and Response
      • Managed Endpoint Detection and Response
      • Managed Threat Intelligence
      • Managed Threat Hunting
      • Managed Risk-Based SOAR
      • Managed Penetration Testing
  • Solutions
  • Resources
    • Blog
    • Threat Advisory
  • Company
    • About Us
    • Careers
    • Contact
COPYRIGHT © REWTERZ. ALL RIGHTS RESERVED.