Rewterz
Rewterz Threat Alert – FormBook Malware – Fresh IOCs
July 28, 2021
Rewterz
Rewterz Threat Alert – Nanocore Rat – Fresh IOCs
July 28, 2021

Rewterz Threat Alert – Oski Data Stealer Malware – Fresh IOCs

Severity

High

Analysis Summary

An emergent and effective data-harvesting tool dubbed Oski is proliferating in North America and China, stealing online account credentials, credit card numbers, crypto wallet accounts, and more. The malware is still in its developing phase but packs a punch with its capabilities. Oski C2’s dashboard revealed that Oski’s theft tactics involve extracting credentials using man-in-the-browser (MitB) attacks by hooking the browser processes using DLL injection, It also extracts credentials from the registry, passwords from the browser SQLite database, and stored session cookies of all stripes, including crypto-wallet cookies from Bitcoin Core, Ethereum, Monero, Litecoin, and others.

Impact

  • Credential theft
  • Unauthorized access

Indicators of Compromise

MD5

  • e2e01c7a8e323e117cfc9c4cdf0ad1c2

SHA-256

  • c40bf8fd1a3bc472287536b81fd9fdde8fa2046ace7dcb787f464e6b547a4f1b
  • af66b7e1963f8faeb154343e2936681f06107203a20fbdfbd0263d9d5b09eced
  • 926b147d9e72e70db67c73e8f43d77c6fa8a30a223502a93838ac7ce16af2205
  • e8b4e90cb7a9233231088d027c2c090aafc143c77e1f46d34d6b206c2c797419

SHA-1

  • ea718bc482d968f9db9577b8d9edb08e4f24abbd

Remediation

  • Block all threat indicators at your respective controls.
  • Always be suspicious about emails sent by unknown senders.
  • Never click on the links/attachments sent by unknown senders.