Rewterz Threat Advisory – CVE-2020-3143 – Cisco TelePresence Collaboration Endpoint
January 23, 2020Rewterz Threat Alert – GoMiner spreads via public cloud storage providers
January 24, 2020Rewterz Threat Advisory – CVE-2020-3143 – Cisco TelePresence Collaboration Endpoint
January 23, 2020Rewterz Threat Alert – GoMiner spreads via public cloud storage providers
January 24, 2020Severity
High
Analysis Summary
Nodera is a ransomware family that uses the Node.js framework and was discovered by researchers. The infection chain starts with a VBS script embedded with multiple JavaScript files. Upon execution, a directory is created and both the main node.exe program and several required NodeJS files are downloaded into the directory. Additionally, a malicious JavaScript payload that performs the encryption process is saved in this directory. After checking that it has admin privileges and setting applicable variables, the malicious JavaScript file enumerates the drives to create a list of targets. Processes associated with common user file types are stopped and volume shadow copies are deleted. Finally, all user-specific files on the C: drive and all files on other drives are encrypted and are appended with a “.encrypted” extension. The ransom note containing instructions on paying the Bitcoin ransom are provided along with a batch script to be used for decryption after obtaining the private key.
Impact
File encryption
Indicators of Compromise
MD5
- 976b17845289d9f8a5ee1c8a9e9c4173
- e8cfee97467d4006257afdaabf945565
SHA-256
- 7265c1fb74eb9ea3cd98358475620ce54b9033421ba042957135bdefd078b366
- 53a95c9126be8262afb0821da4d7137e6c8a4d9b363f91298249ca134d394bf4
SHA1
- c458e4c32e3ebb1fca331ef235fe3f96e505e066
- 7879bbaf9bd6de58a7b318d013cd479d4a24ffae
Remediation
- Block all threat indicators at your respective controls.
- Always be suspicious about emails sent by unknown senders.
- Never click on the links/attachments sent by unknown senders.