Rewterz
Rewterz Threat Alert – Donot APT Group – IOCs
June 28, 2021
Rewterz
Rewterz Threat Alert – DanaBot Trojan – Active IOCs
June 28, 2021

Rewterz Threat Alert – New Malware Crackonosh Making Rounds – IOCs

Severity

High

Analysis Summary

A new malware “Crackonosh” in part because of some possible indications that the malware author may be Czech. Crackonosh is distributed along with illegal, cracked copies of popular software and searches for and disables many popular antivirus programs as part of its anti-detection and anti-forensics tactics.

The main target of Crackonosh was the installation of the coin miner XMRig, from all the wallets, there was one where we were able to find statistics. The pool sites showed payments of 9000 XMR in total, that is with today prices over $2,000,000 USD.

advisory-1624877979.png

Impact

  • Credential Theft
  • Data Exfiltration

Indicators of Compromise

SHA-256

  • E497EE189E16CAEF7C881C1C311D994AE75695C5087D09051BE59B0F0051A6CF
  • 65F39206FE7B706DED5D7A2DB74E900D4FAE539421C3167233139B5B5E125B8A
  • 4B01A9C1C7F0AF74AA1DA11F8BB3FC8ECC3719C2C6F4AD820B31108923AC7B71
  • 7F836B445D979870172FA108A47BA953B0C02D2076CAC22A5953EB05A683EDD4
  • 93A3B50069C463B1158A9BB3A8E3EDF9767E8F412C1140903B9FE674D81E32F0
  • 9EC3DE9BB9462821B5D034D43A9A5DE0715FF741E0C171ADFD7697134B936FA3
  • D8C092DE1BF9B355E9799105B146BAAB8C77C4449EAD2BDC4A5875769BB3FB8A
  • 6A3C8A3CA0376E295A2A9005DFBA0EB55D37D5B7BF8FCF108F4FFF7778F47584
  • D7A9BF98ACA2913699B234219FF8FDAA0F635E5DD3754B23D03D5C3441D94BFB
  • 8C52E5CC07710BF7F8B51B075D9F25CD2ECE58FD11D2944C6AB9BF62B7FBFA05
  • C6817D6AFECDB89485887C0EE2B7AC84E4180323284E53994EF70B89C77768E1

Remediation

  • Block the threat indicators at their respective controls.
  • Do not download files attached in untrusted emails.
  • Keep all systems and software updated to the latest patched versions.
  • Enable multi-factor authentication.