Rewterz
Rewterz Threat Advisory – CVE-2021-1528 – Cisco SD-WAN Software Privilege Escalation Vulnerability
June 3, 2021
Rewterz
Rewterz Threat Advisory – CVE-2021-26092 – FortiGate SSL VPN Portal Vulnerability
June 3, 2021

Rewterz Threat Alert – Unknown Threat Actors Targeting different Pakistani Sectors – Active IOCs

Severity

Medium

Analysis Summary

An unknown threat actor has started a new campaign that is potentially targeting the Government sector and is targeting users with a phishing campaign and in that is a list of Afghan refugees that Pakistan have given refuge as part of the peace process in war-torn Afghanistan. This campaign is likely to be expanded to different sectors because of the nature of the sensitivity of the issue. Previously, these type of campaigns has been ignored in the past and users were carelessly clicking on the emails sent by threat actors and were robbed of with their credentials and other information. 

Image

Impact

  • Information theft and espionage
  • Data exfiltration

Indicators of Compromise

Filename

  • List of Afg Refugees Hi School inside Qta[.]rtf

MD5

  • 085e0260b49ef900f74aa69cc22c0ac2

SHA-256

  • 9e0734e4fd3bbaa34e8717f8de8cbe441352ce590b319cb2e0450e909948f2f5


SHA1

  • 18620ff4f38cc73fb7592867e00ed538a3a9b52c

URL

  • hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/running[.]php
  • hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/verison[.]php
  • hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/Update/winservice_{num}[.]exe
  • hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/Update/s_{num}[.]ps1
  • hxxp[:]//windowsupdateserver[.]cf/main/alpha/admin/php/%20/api[.]php

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.
  • Users are advised to look out for any emails with this subject.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on links/ attachments sent by unknown senders.