Rewterz
Rewterz Threat Advisory – CVE-2021-26094 – FortiWLC – Multiple Buffer Overflow Vulnerabilities
June 3, 2021
Rewterz
Rewterz Threat Alert – Oski Data Stealer Malware – Active IOCs
June 3, 2021

Rewterz Threat Alert – LockBit Ransomware targeting Network – Active IOCs

Severity

High

Analysis Summary

LockBit ransomware takes as little as five minutes to deploy the encryption routine on target systems once it lands on the victim network. LockBit attacks leave few traces for forensic analysis as the malware loads into the system memory, with logs and supporting files removed upon execution. In one case, they found that the attack began from a compromised Internet Information Server that launched a remote PowerShell script calling another script embedded in a remote Google Sheets document. This script connects to a command and control server to retrieve and install a PowerShell module for adding a backdoor and establish persistence. To evade monitoring and go unnoticed in the logs, the attacker renamed copies of PowerShell and the binary for running Microsoft HTML Applications (mshta.exe); this prompted Sophos to call this a “PS Rename“ attack. The backdoor is responsible for installing attack modules and executes a VBScript that downloads and executes a second backdoor on systems restart.

advisory-1622619020.jpg

Impact

  • Security Bypass
  • Information Theft
  • Files Encryption

Indicators of Compromise

MD5

  • 80424ca2bfaa8bb703fa81169fcb69d3
  • 6d594b75cf111f1f2107f325e70b824d
  • 60bd83912cee84cba0c1c174e9766f47

SHA-256

  • 7a60cd13e6caea997275fae437a841f7bdbbd8e97a2feb93ec02d71ecdc30e1d
  • b90c5aabda7ad52cb0616d14730e6d698137c44cc585937e20943821aacfc089
  • 8e73f308b4a2f79a25a333fc31a3d81f424064fc27c1d2638c377a5deee1b419
  • faaa06208acdf230496128dfd656984d3f0f99a9b5be4f2cbaaec0bb830bdcf9

SHA1

  • c32c648cfd185b95f6793712fe498703a011c026
  • 8bed224530344f35ea4899c3d243fdae3ee37941
  • c4a0098f5ebe495c12e69ef5d3877d73dcd96e7c

Remediation

  • Block the threat indicators at their respective controls.
  • Do not respond to emails coming from untrusted sources.
  • Do not open untrusted files received by any means.