

Rewterz Threat Alert – SNAKE Ransomware – Active IOCs
November 11, 2021
Rewterz Threat Advisory – CVE-2021-23055 – F5 NGINX Ingress Controller
November 11, 2021
Rewterz Threat Alert – SNAKE Ransomware – Active IOCs
November 11, 2021
Rewterz Threat Advisory – CVE-2021-23055 – F5 NGINX Ingress Controller
November 11, 2021Severity
High
Analysis Summary
Following samples of Lazarus group aka Guardians of Peace, a state-sponsored North Korean threat actor group targeting financial organizations for their gains have been active again and actively targeting different organizations via phishing emails dropping malicious word documents which enables macro when downloaded and executed. The malicious file suspected of being used as an attachment has the name idahelper.dll. Previously these campaigns were specifically crafted to target Russian organizations but now they’ve shifted their tilt towards Asia pacific region


Impact
- Information theft and espionage
- Exposure of sensitive data
Indicators of Compromise
Filename
- idahelper[.]dll
MD5
- 9454715b9081323f525970dae9c37e9d
SHA-256
- fe80e890689b0911d2cd1c29196c1dad92183c40949fe6f8c39deec8e745de7f
SHA-1
- de0e23db04a7a780a640c656293336f80040f387
Remediation
- Always be suspicious about emails sent by unknown senders.
- Never click on links/attachments sent by unknown senders.
- Block all threat indicators at your respective controls.
- Search for IOCs in your environment.