

Rewterz Threat Advisory – CVE-2020-7710 – Node.js safe-eval module command execution
August 25, 2020
Rewterz Threat Alert – CobaltStrike Beacon Masquerades as VPN Client Installers
August 25, 2020
Rewterz Threat Advisory – CVE-2020-7710 – Node.js safe-eval module command execution
August 25, 2020
Rewterz Threat Alert – CobaltStrike Beacon Masquerades as VPN Client Installers
August 25, 2020Severity
Medium
Analysis Summary
A Royal Road RTF maldoc, created by the Royal Road RTF weaponizer, drops a new backdoor developed with Microsoft MFC C++. The dropped malware communicates with previously linked Goblin Panda infrastructure.

The backdoor is packed with a home made packer. The real entrypoint is call by a thread with the function AfxWinMain at FUN_00432cc8 and the entry of this thread is at 401740. the backdoor checks the windows version, environment user, it check the IP internal and mac address in the sub function.
Impact
- Information theft
- Exposure of sensitive data
Indicators of Compromise
IP
- 91[.]218[.]113[.]17
MD5
- b88b941590b8f4c40effb8503381d913
- ec607802d2de9bfdae9cf0a94af5d987
SHA-256
- b19d64d6ef5329b388d688157ebb9f4fa8cae2ccd18ec1fe7bb75b0fcc2350f9
- 74aa6fff407dee851f224329489232a8e7f2d6046aaff3c9cebfff81b7d5db22
SHA1
- 6510a4ecb20e98ec8fab7a5e72548e087ceb1cca
- 85004c1436b8be7c23ea0cf639ce70714c79107d
Remediation
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.