Rewterz
Rewterz Threat Advisory – CVE-2019-5847 – Google Chrome V8 Denial of service Vulnerability
July 17, 2019
Rewterz
Rewterz Threat Alert – EvilGnome Rare Malware Spying on Linux Desktop Users
July 18, 2019

Rewterz Threat Alert – Buhtrap Group Recent Activity

Severity

High

Analysis Summary

A campaign recently identified and attribute to the Buhtrap Group. These threat actors have been linked to campaigns against Russian financial institutions but recently have expanded their operations to conduct espionage campaigns in Central Asian and Eastern European countries. They were observed utilizing several zero day vulnerabilities (CVE-2019-1132 and CVE-2015-2387) to attack their victims, most recently a government institution. Since being discovered in 2015, the group has added numerous tool sets to their arsenal, but their tactics, such as the use of decoy documents, remain relatively the same. This was the first known instance where the group exploited zero day vulnerabilities to attack their victims. The infection process begins when a user opens a Microsoft Word document, enables macros, and then ultimately downloads the malicious payload.

Impact

Privilege escalation

Indicators of Compromise

URLs

  • https[:]//hdfilm-seyret[.]com/help/index[.]php
  • https[:]//redmond[.]corp-microsoft[.]com/help/index[.]php
  • https[:]//win10[.]ipv6-microsoft[.]org
  • https[:]//services-glbdns2[.]com/FIGm6uJx0MhjJ2ImOVurJQTs0rRv5Ef2UGoSc
  • https[:]//secure-telemetry[.]net/wp-login[.]php


Malware Hash (MD5/SHA1/SH256)

  • 2f2640720cce2f83ca2f0633330f13651384dd6a
  • e0f3557ea9f2ba4f7074caa0d0cf3b187c4472ff
  • c17c335b7ddb5c8979444ec36ab668ae8e4e0a72
  • 9c3434ebdf29e5a4762afb610ea59714d8be2392

Remediation

  • Search for the existing IOC’s in your environment.
  • Block all threat indicators at your respective controls.