

Rewterz Threat Alert – Ursnif Banking Trojan aka Gozi – Active IOCs
January 20, 2023
Rewterz Threat Advisory – CVE-2022-47966 – Multiple Zoho ManageEngine products Vulnerability
January 20, 2023
Rewterz Threat Alert – Ursnif Banking Trojan aka Gozi – Active IOCs
January 20, 2023
Rewterz Threat Advisory – CVE-2022-47966 – Multiple Zoho ManageEngine products Vulnerability
January 20, 2023Severity
High
Analysis Summary
AP15 threat actor group – aka Ke3chang, Mirage, Vixen Panda, and Playful Dragon – has been active since at least 2010. The group is primarily known for targeting organizations in the Middle East, specifically in Saudi Arabia, with a focus on government and military entities. The group is believed to be based in China and has been associated with a variety of tools and techniques. The group is known for using sophisticated malware and targeted spear-phishing campaigns to gain initial access to targeted networks. Once inside a network, the group uses a variety of tools to move laterally and exfiltrate sensitive data. The group has been known to focus on a wide range of sectors, including government, defense, aerospace, telecommunications, and high-tech industries.
APT15 has been known for using various infrastructure and tools to evade detection, including using legitimate third-party tools and services, custom malware and backdoors, and the use of encrypted communication channels. The group has been also known for using a variety of tools to maintain persistence on compromised systems and to hide their activity.
Impact
- Information Theft and Espionage
Indicators of Compromise
IP
- 152.32.181.16
- 158.247.222.6
Domain Name
- vpnkerio.com
- update.delldrivers.in
- scm.oracleapps.org
- update.adboeonline.net
- mail.indiarailways.net
MD5
- 7b3f7c751a5c3b1823baac97ccb4d4c6
- c7802966e0ab20cee7e9028ba74129ea
- 912dddad1a02d4a0eb35bbe0e9c1f6e5
- 008a71c9a5167985ae6fedd63a50a902
- b54cbde68c020136ebd424fc3f33e4a7
SHA-256
- 67c911510e257b341be77bc2a88cedc99ace2af852f7825d9710016619875e80
- 8549c5bafbfad6c7127f9954d0e954f9550d9730ec2e06d6918c050bf3cb19c3
- 5bb99755924ccb6882fc0bdedb07a482313daeaaa449272dc291566cd1208ed5
- 6828b5ec8111e69a0174ec14a2563df151559c3e9247ef55aeaaf8c11ef88bfa
- ad22f4731ab228a8b63510a3ab6c1de5760182a7fe9ff98a8e9919b0cf100c58
SHA-1
- 615b5a92b6066fc992dae0d5f6abf29fe53cf2f9
- 91d0286080678fb1f87a2c3f277d072245900b7c
- 86f8c32d0110992c3a6ee9760b0733e7661ff8a1
- 540e50b57b648df5e91f7e09df4c2e0e0177c668
- 3a311e1143ae8eddc5e5c201a3c59051730c4050
Remediation
- Block all threat indicators at your respective controls.
- Search for Indicators of compromise (IOCs) in your environment utilizing your respective security controls
- Do not download documents attached in emails from unknown sources and strictly refrain from enabling macros when the source isn’t reliable.
- Enable antivirus and anti-malware software and update signature definitions in a timely manner. Using multi-layered protection is necessary to secure vulnerable assets
- Along with network and system hardening, code hardening should be implemented within the organization so that their websites and software are secure. Use testing tools to detect any vulnerabilities in the deployed codes.