Rewterz
Rewterz Threat Alert – SNAKE Ransomware – Active IOCs
January 24, 2022
Rewterz
Rewterz Threat Alert – Dark Crystal RAT – Active IOCs
January 24, 2022

Rewterz Threat Alert – Gamaredon APT – Active IOCs

Severity

High

Analysis Summary

Gamaredon, the Russia-backed advanced persistent threat (APT) threat actor that has been active since at least 2013 has reinforced its cyber warfare activities a new surge of Gamaredon APT attacks targeting users with template injection of malicious documents. The attacker main target is to get control of the target system using the malicious document. The exploit document employs the template injection technique to install additional malware on the victim’s machine. Upon opening the document, it connects back to the hacker’s server to download the payload file

update-1639132978.png

Impact

  • Template Injection 
  • Exposure of Sensitive Data

Indicators of Compromise

Domain Name

  • normandia[.]fun

MD5

  • 97d3d3fe312514f33a44dcd9d5887b54

SHA-256

  • 4ddf00bc7bf2ec628389c503e0ccbb90b8f5ade1d9ad1c6ee10b9d3b33bdce68

SHA-1

  • 827b5543a83eff2c10e80b32366b25613ff190da

URL

  • http[:]//normandia[.]fun/DESKTOP-JGLLJLD_26B799FA/office[.]txt

Remediation

  • Block the threat indicators at their respective controls.
  • Search for IOCs in your environment.