Rewterz
Rewterz Threat Alert – Remcos RAT – Active IOCs
June 15, 2022
Rewterz
Rewterz Threat Advisory – CVE-2022-29143 – Microsoft SQL Vulnerability
June 15, 2022

Rewterz Threat Alert – Shodi Malware – Active IOCs

Severity

Medium

Analysis Summary

W32/Shodi-F – a virus targeting Windows platform – seeks to infect all files with the EXE extension, except for specific Windows system files. W32/Shodi-F specifically targets Scandskw.exe, Winmine.exe, Sol.exe, Pbrush.exe, and Notepad.exe files in the Windows folder. After targeting, it creates a thread to look for additional exe files on the system, including any open network shares to the infected host. W32/Shodi-F drops Troj/Remadm-C, a remote administration Trojan, and also drops JPG file to the Windows system folder with the USR_Shohdi_Photo_USR.jpg filename.

Impact

  • Information Theft
  • Credential Theft

Indicators of Compromise

MD5

  • ce882b664f279278da3b3b592581799f

SHA-256

  • e5548e43506b0e47875100dc52a87a16c1bede9dad838e5fee1d61ca71ce04e3

SHA-1

  • 12162f4eff152cfc640e8ae70891da100d8fff8e

Remediation

  • Block the threat indicators at their respective controls.
  • Search for IOCs in your environment.