Rewterz

Rewterz Threat Advisory – CVE-2022-44590 – WordPress Simple Video Embedder Plugin Vulnerability

November 16, 2022
Rewterz

Rewterz Threat Advisory – CVE-2022-45378 – Apache SOAP Vulnerability

November 16, 2022

Rewterz Threat Alert – Conti Ransomware – Active IOCs

Severity

High

Analysis Summary

Conti ransomware was discovered in December 2019 and is delivered via TrickBot. It’s been utilized against large companies and government institutions across the world, especially in North America. Conti steals important files and information from targeted networks and threatens to disseminate it unless the ransom is paid. Conti ransomware enhances performance by utilizing “up to 32 simultaneous encryption operations,” and is very likely directly controlled by its controllers. This ransomware can target network-based resources while ignoring local files. This feature has the noticeable impact of being able to create targeted harm in an environment in a way that might hinder incident response actions.

Impact

  • Sensitive File Theft
  • File Encryption

Indicators of Compromise

MD5

  • ce3b141aa84f121127b37adecc908db8

SHA-256

  • 05bbf1c653825b757ee73b59df45410070a28841819362462162d9547adb3d5a

SHA-1

  • c761ca6f202558b752efa76058264f01065d8171

Remediation

  • Search for IOCs in your environment.
  • Block all threat indicators at your respective controls

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.