Rewterz
Rewterz Threat Alert – Ordinypt Malware Hitting Germany in New Spam Campaign
September 16, 2019
Rewterz
Rewterz Threat Alert – Phishing Attack Targets The Guardian’s Whistleblowing Site
September 17, 2019

Rewterz Threat Alert – InnfiRAT Malware Steals Litecoin And Bitcoin Wallet Information

Severity

Medium

Analysis Summary

As with just about every piece of malware, InnfiRAT is designed to access and steal personal information on a user’s computer. Among other things, InnfiRAT is written to look for cryptocurrency wallet information, such as Bitcoin and Litecoin. InnfiRAT also grabs browser cookies to steal stored usernames and passwords, as well as session data. In addition, this RAT has ScreenShot functionality so it can grab information from open windows. For example, if the user is reading email, the malware takes a screenshot. It also checks for other applications running on the system, such as an active antivirus program.

Impact

  • Exposure of sensitive information
  • Financial loss
  • Credential theft

Indicators of Compromise

IP(s) / Hostname(s)

62[.]210[.]142[.]219

Malware Hash (MD5/SHA1/SH256)

f992dd6dbe1e065dff73a20e3d7b1eef

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the link/attachments sent by unknown senders.