Rewterz
Rewterz Threat Alert – Shamoon 2: Disttrack Wiper Returns
December 5, 2019
Rewterz
Rewterz Threat Alert – “ZeroCleare” Targets Energy Sector in the Middle East
December 5, 2019

Rewterz Threat Alert – CStealer Trojan Targeting Chrome Passwords

Severity

Medium

Analysis Summary

A new CStealer trojan is found that targets Chrome passwords and exfiltrates them via mongoDB database at 18.220.85[.]117:27000, along with target system’s information.

EKjKP1ZUcAIVlwf.png

Impact

Credential Theft

Indicators of Compromise

MD5

181482ec53907fdba47e83b76795b196

SHA-256

00a1237e8faa646219744517b24cb4c8ebdbaa10d62e2b56fc25dffca832583c

SHA1

24cb0b03442d6b3f934031e06d60f5226a5dccda

Source IP

18.220.85[.]117

URL

http[:]//18.220.85[.]117:27000

Remediation

  • Block the threat indicators at their respective controls.
  • Keep web browsers patched against known vulnerabilities.