

Rewterz Threat Alert – Shamoon 2: Disttrack Wiper Returns
December 5, 2019
Rewterz Threat Alert – “ZeroCleare” Targets Energy Sector in the Middle East
December 5, 2019
Rewterz Threat Alert – Shamoon 2: Disttrack Wiper Returns
December 5, 2019
Rewterz Threat Alert – “ZeroCleare” Targets Energy Sector in the Middle East
December 5, 2019Severity
Medium
Analysis Summary
A new CStealer trojan is found that targets Chrome passwords and exfiltrates them via mongoDB database at 18.220.85[.]117:27000, along with target system’s information.

Impact
Credential Theft
Indicators of Compromise
MD5
181482ec53907fdba47e83b76795b196
SHA-256
00a1237e8faa646219744517b24cb4c8ebdbaa10d62e2b56fc25dffca832583c
SHA1
24cb0b03442d6b3f934031e06d60f5226a5dccda
Source IP
18.220.85[.]117
URL
http[:]//18.220.85[.]117:27000
Remediation
- Block the threat indicators at their respective controls.
- Keep web browsers patched against known vulnerabilities.