Rewterz
Rewterz Threat Alert – Panda Continues to Target Cryptocurrency Miners
September 23, 2019
Rewterz
Rewterz Threat Alert – Tofsee Malware Resurfaces with Fresh IoCs
September 23, 2019

Rewterz Threat Alert – Turla NetTrans Malware

Severity

Medium

Analysis Summary

Turla, also known as Snake or Uroburos is one of the most sophisticated ongoing cyber-espionage campaigns. Targets of “Epic” belong to the following categories: government entities (Ministry of Interior, Ministry of Trade and Commerce, Ministry of Foreign/External affairs, intelligence agencies), embassies, military, research and education organizations and pharmaceutical companies.

The attackers use both direct spear-phishing e-mails and watering hole attacks to infect victims. Watering holes are websites commonly visited by potential victims. These websites are compromised in advance by the attackers and injected to serve malicious code. Depending on the visitor’s IP address (for instance, a government organization’s IP), the attackers serve Java or browser exploits, signed fake Adobe Flash Player software or a fake version of Microsoft Security Essentials.

Impact

Exposure of sensitive information

Indicators of Compromise

Malware Hash (MD5/SHA1/SH256)

  • 4dc26b3b144826569bc2601fb20dcef124abf9fe63944c029a52eda48
  • 6874b387a1c07d85bbedbd196cae3f06539cbcc724395723034196a3ad016724

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the link/attachments sent by unknown senders.