Rewterz
Rewterz Threat Advisory – CVE-2022-22931 – Apache James directory traversal Vulnerability
February 8, 2022
Rewterz
Rewterz Threat Alert – Vidar Malware – Active IOCs
February 8, 2022

Rewterz Threat Alert – NetWire RAT Malware – Active IOCs

Severity

High

Analysis Summary

NetWire is a remote access tool and a malicious program (RAT). RATs are often used to remotely access and manipulate computers. These programs can be used for lawful purposes by system administrators to get access to client systems, but they can also be used for malicious purposes. NetWire is a keylogger used by cybercriminals to collect data from USB card readers and other peripheral devices. This sends emails containing potentially dangerous files. The malware gets downloaded into the victim’s machine after the victim clicks on it. Crooks frequently use PDF, Word, and IMG files as shared files for their malware payloads.

Impact

  • Sensitive Data Exposure
  • Information Theft
  • Keylogging

Indicators of Compromise

Filename

  • sy4Xc[.]exe
  • keqaikxf[.]dll
  • sqlclient[.]exe

MD5

  • afb7b1b29f82dd547cd5bd02788cee09
  • dcbf37b8eaee657ed77795753e65ae39
  • 31555a4c2e03324d43105121aec58155

SHA-256

  • 979006b7422b4d2be9876c85263dabfe9d15e52dbf63bdff41bff04be2475d01
  • 4beb785c349edcd431c027e3f05ee4fbdda6f5cb640a8a85ab38bcb0caa13644
  • f74fe2e268460819040182e30bc54b5b787e0fb819cc8bc54b37ec43f5eb354a

SHA-1

  • b3e881066fc10fc7921dd0382ffb7a3c296c6cdf
  • fafd15eda45803d10c98edf271f79410f81a9f39
  • fd54235feca6e2ec63d28fd148af74d546446ce2

Remediation

  • Block all the threat indicators at your respective controls.
  • Search for IOCs in your environment.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders