High
Adwind is a remote access Trojan known to evade detection upon entry and to communicate with a command-and-control server once connected. The Trojan can steal sensitive information, such as credentials, as well as spy through a user’s webcam and log a user’s keystoke activity. The new addition to the modified remote access Trojan uses multi-layer obfuscation by containing various file extensions to avoid detection, with iDefense suspecting it to be tailored specifically to this industry. The malware originated from compromised Westnet accounts.
Hostname
members[.]westnet[.]com[.]au
Source IP
185[.]205.210[.]48
URL
hxxp[:]//members[.]westnet.com[.]au/~