Rewterz
Rewterz Threat Alert – Cyberium Is Fanning Out Mirai Variants Through Its Malware Hosting Domain – Active IOCs
June 16, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-30641 – Apache HTTP Server Remote Code Execution
June 16, 2021

Rewterz Threat Alert – REvil Strikes Again – Active IOCs

Severity

Medium

Analysis Summary

The REvil ransomware group made headlines by targeting the US’s nuclear weapons contractors. Sol Oriens was targeted by the threat actors and their employees’ data was leaked online. Along with the employees’ information, business data was also stolen and leaked.

The company added that it is not aware that threat actors have stolen classified or critical security-related information belonging to its clients. However, the social security numbers of employees along with their payroll were leaked online.

“Sol Oriens, LLC did not take all necessary action to protect personal data of their employees and software developments for partner companies. We hereby keep a right to forward all of the relevant documentation and data to military agencies of our choice, including all personal data of employees.” reads the statement published by REvil on its leak site.

Impact

  • Credential Theft
  • Information Disclosure
  • Data Breach

Indicators of Compromise

URL

  • http[:]//aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd[.]onion/4DD2F2803EC112D7
  • https[:]//decoder[.]re/4DD2F2803EC112D7

Remediation

  • Block the threat indicators at their respective controls.
  • Search for IOCs in your environment.