Rewterz
‘Sitting Ducks’ Domain Hijacking Technique Threatens Over 1 Million Domains
August 2, 2024
Rewterz
CVE-2024-41183 – Trend Micro VPN Proxy One Pro Zero-Day Vulnerability
August 2, 2024

CryptBot Trojan – Active IOCs

Severity

High

Analysis Summary

CryptBot - a Windows malware - is capable of stealing credentials for browsers, cryptocurrency wallets, browser cookies, and credit cards, and creates screenshots of the infected system. Cryptbot hides within legitimate software to be installed by its victims. CryptBot threat actors spread malware via websites purportedly offering software cracks, key generators, or other tools. To gain widespread visibility, threat actors utilize search engine optimization to position malware distribution sites toward the top of Google search results, resulting in a steady stream of potential victims. It can also spread through a fake VPN client which is called Inter VPN, when executed, it infects the system with Cryptbot and Vidar which then runs an AutoHotKey script leading to download executables from malicious websites.

Impact

  • Credential Theft
  • Information Theft
  • Exposure of Sensitive Data

Indicators of Compromise

Domain Name

  • twex12ht.top

MD5

  • 06996bb69b5978d822b228766c4b44c0
  • 4de2056db3a3b39bee9d833d403091d4

SHA-256

  • dd9c9e05161c28e9a5da6113d0da80ecae0c58591ea311f0243195f625335623
  • 341d0acb07c501d964a5cee3a1fb057e8ac38c958c43cafc7c38eb0fca3e7023

SHA1

  • e830fd6e5d9d8e48841556a4315189683f2a50e7
  • 1eae771651e8a1468ec2b4af74715260a240cf8b

URL

  • http://gg.gg/1b9jyb

Remediation

  • Block all threat indicators at your respective controls.
  • Search for indicators of compromise (IOCs) in your environment utilizing your respective security controls.
  • Enable antivirus and anti-malware software and update signature definitions promptly. Using multi-layered protection is necessary to secure vulnerable assets.
  • Do not download documents attached in emails from unknown sources and strictly refrain from enabling macros when the source isn’t reliable.