

Rewterz Threat Alert – Mirai Botnet aka Katana – Active IOCs
January 15, 2024
Rewterz Threat Advisory – CVE-2023-7028 – GitLab Vulnerability
January 15, 2024
Rewterz Threat Alert – Mirai Botnet aka Katana – Active IOCs
January 15, 2024
Rewterz Threat Advisory – CVE-2023-7028 – GitLab Vulnerability
January 15, 2024Severity
High
Analysis Summary
GootLoader, a multi-staged JavaScript malware package, has been active in the wild since late 2020. It initially gained popularity as a sophisticated multi-staged downloader of GootKit malware. This dropper’s payload delivery has progressed, and its payload capabilities have expanded beyond only distributing its namesake malware. Previously, this threat has delivered the information-stealing malware “GootKit,” from which it derives its name.
GootLoader leverages SEO poisoning tactics to prominently promote links to its malware in internet search results, drawing in as many unknowing victims as possible. The group also utilized overlays to show a fake forum page over blog articles with highly targeted material related to government, finances, legal, healthcare, and education.
Impact
- Information Theft
- Unauthorized Access
- SEO Poisoning
Indicators of Compromise
MD5
- 28db34b58419a23ac39e1e7da5cfccf3
- 310a81390f89ef0da4c4313d6d552766
- 1a6481c0ba09fc0f7ce35936982ddd92
SHA-256
- c853d91501111a873a027bd3b9b4dab9dd940e89fcfec51efbb6f0db0ba6687b
- aacc1a4f82a7e62a89860cd7ae0472f61265ed509dd35b3df74e36ad3b3668cf
- 6f30d32889faed3d0f6e1d27ec3b19fee1be80c8c31562f6188fdd03f365d5ef
SHA-1
- 947539769b8a818530e9790c27084b2850333c29
- 8b6fd0e7a0214c042706616d543f9561a9b10178
- a226ebb9c23e14fbf69f23f9b2ea34944f1e2fdc
Remediation
- Block all threat indicators at your respective controls.
- Search for Indicators of compromise (IOCs) in your environment utilizing your respective security controls.
- Never trust or open ” links and attachments received from unknown sources/senders.
- Do not download documents attached to emails from unknown sources and strictly refrain from enabling macros when the source isn’t reliable.