Rewterz

Rewterz Threat Alert – Ryuk Ransomware – Active IOCs

September 9, 2022
Rewterz

Rewterz Threat Alert – APT Group Gamaredon – Active IOCs

September 9, 2022

Rewterz Threat Alert – Mirai Botnet – Active IOCs

Severity

High

Analysis Summary

A new Mirai variant is making the rounds called mirai_pteamirai. This botnet is one of the significant botnets targeting exposed networking devices running Linux. Mirai means ‘future’ in Japanese. This botnet is one of the active botnet and used to cause DDoS conditions. IP cameras, home routers, and other IoT devices are the common targets of this botnet.

Impact

  • Server Outage
  • Data Loss
  • Website Downtime

Indicators of Compromise

MD5

  • 89758623a0e5e11b6ed3e1b7c8ffb99e
  • 2b4ec58ba070122c5e73d59e7adc92b0
  • 120f55e7e86298725b7ac6b9c06e5a85

SHA-256

  • 10cae20574471a23f29815ee64cf513e64ac66af55c04ac81ea7b0e794cd2a31
  • ac9b5f32ca793b4cf9c33a586cf66167b9484f3fa00bc0c1641577ad69c4d0b9
  • 370d0a9c001d47b14219c76594c8aa7fa22a3d378e6242f4c2442440ad27404c

SHA-1

  • 9015cc733b439da00d5ee1f3651d9d38c8d44578
  • f5e4871f9f83255e192804f04251b3570394cd28
  • ae93a84f2d588336541c98bed65e16f58983178b

Remediation

  • Upgrade your operating system.
  • Don’t open files and links from unknown sources.
  • Install and run anti-virus scans.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.