

Rewterz Threat Advisory – Multiple Microsoft .NET Core, Visual Studio, Dynamics 365
October 13, 2021
Rewterz Threat Advisory – Multiple SAP BusinessObjects, NetWeaver Application and SuccessFactors Vulnerabilities
October 13, 2021
Rewterz Threat Advisory – Multiple Microsoft .NET Core, Visual Studio, Dynamics 365
October 13, 2021
Rewterz Threat Advisory – Multiple SAP BusinessObjects, NetWeaver Application and SuccessFactors Vulnerabilities
October 13, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name Profit and Loss Statement. zip and Profit and Loss Statement.xlsx.lnk. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region
Impact
- Exposure of Sensitive Data
- Information Theft and Espionage
Indicators of Compromise
Filename
- New Profits Distributions_MATT[.]zip
MD5
- bed99a09a68eb8f8b53d2a9d0ccc085a
- c44d866adf8c6845b7dda742c59c6b59
- 22827467f52cc5cf4f6461ea008bcd54
SHA-256
- 3979b2d47cec119a9a22a80b1e5cdda7c59e97f9fc144918c20eeec5e27a6549
- a042bfeee49345d514c274e5f44da374eb0875da4a5671e8bf67005078c076fd
- fe0a9261e6dc402ebd92706d6f5126e00057b478084a3bcede17a0f049adbe91
SHA-1
- 5d93026501eb6f6fd844eaa5f0db3d7cc9c96986
- b19e3b0ea216eea3c3cdfae490b0929b8d0ca40d
- c614831d3ba85ca296ba8a69e3117a3c138c1ea7
URL
- https[:]//onlinedocpage[.]org/1
- https[:]//onlinedocpage[.]org/2
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.