

Rewterz Threat Advisory – CVE-2021-34979 – NETGEAR routers Vulnerability
November 9, 2021
Rewterz Threat Alert – RedLine Stealer – Active IOCs
November 9, 2021
Rewterz Threat Advisory – CVE-2021-34979 – NETGEAR routers Vulnerability
November 9, 2021
Rewterz Threat Alert – RedLine Stealer – Active IOCs
November 9, 2021Severity
Medium
Analysis Summary
A new info-stealing malware called Anubis was first observed in the cybercriminal underground. The malware uses forked code from Loki to steal vast amounts of data including system info, credentials, credit card details, and cryptocurrency wallets such as Bitcoin and Electrum. This malware should not be confused with the Android banking malware also named Anubis. At present, the new Anubis is being deployed in limited campaigns and contains only a handful of download URLs and C2 servers. This malware uses a text file to exfiltrate data from the victim.
Impact
- Information Theft
- Credential Theft
- Theft of Financial Information
Indicators of Compromise
SHA-256
- 3fec7dce03c7b76c204f310d93ae59762082625eed5896e47902886d26a4358b
- 5b6fbfa053667e0f2d19a13e95053da99638e552981dc994386a073188804236
- d61d410670cf556d816a57a5d511cae6231ba8c0a966d0659f6034609edb0356
- d6450cf2ee02aafc2db4d15e0a9dd27d76ba9431c400b2af61312db847b321f1
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.