Rewterz
Rewterz Threat Alert – Phishing URLs – Active
December 21, 2020
Rewterz
Rewterz Threat Advisory – CVE-2020-17526 – Apache Airflow security bypass
December 22, 2020

Rewterz Threat Alert – Active Emotet – IOCs

Severity

High

Analysis Summary

Emotet Malware is constantly being detected in the wild, targeting organizations from multiple sectors and countries. Emotetis a Trojan that is primarily spread through spam emails (malspam). The infection may arrive either via malicious script, macro-enabled document files, or malicious link. Emotet emails may contain familiar branding designed to look like a legitimate email. Emotet may try to persuade users to click the malicious files by using tempting language about “YourInvoice,” “Payment Details,” or possibly an upcoming shipment from well-known parcel companies. Emotet has gone through a few iterations. Early versions arrived as a malicious JavaScript file. Later versions evolved to use macro-enabled documents to retrieve the virus payload from command and control (C&C) servers run by the attackers. Lately, Emotet infections have been used to distribute other malware like Qakbot. So these can be multi-stage attacks that bundle other malware with emotet. Emotet has also been found stealing email attachments to attack contacts of compromised victims. 
Fresher IoCs are retrieved almost every week.

Impact

  • Financial loss 
  • Exposure of sensitive data

Indicators of Compromise

Filename

  • Documenten-6613623 5496[.]doc

MD5

  • 50cc9f248f8de988e6fc534fad65c6cf

SHA-256

  • b94ecdadfbd4659a82ecd02c0745508a5797f041025135a700a25695cd0992cc

SHA1

  • 97c86c67d91d7a354728ecdb932d784ec24334b4

URL

  • hxxp[:]//helionspharmaceutical[.]com/wp-admin/oXJB/
  • hxxp[:]//parakkunnathtemple[.]com/bckup/7SDAvi/[.]dll

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.