Rewterz

Rewterz Threat Advisory – ICS: Multiple Delta Electronics DIAScreen Vulnerabilities

July 29, 2021
Rewterz

Rewterz Threat Advisory –PetitPotam NTLM Relay Attacks

July 29, 2021

Rewterz Threat Alert – Raccoon Infostealer – Active IOCs

Severity

Medium

Analysis Summary

Also known as “Racealer,” Racoon is used to steal sensitive and confidential information including login credentials, credit card information, cryptocurrency wallets and browser information (cookies, history, autofill) from almost 60 applications. Raccoon stealer is written in C++ and it has a wide range of methods and features for stealing data from popular browsers, email clients and cryptocurrency wallets. The malware is delivered via exploit kits that use browser-based vulnerabilities to redirect victims to landing pages injected with exploit codes. It’s also spread via phishing campaigns convincing targets to execute the malicious payload or macros. The malware gathers information about the machine like the OS arch and version, system language, hardware information and installed applications. In addition, it can take screenshots from the user’s machine if that was enabled by the attacker’s configuration. After fulfilling all its stealing capabilities, Raccoon gathers all the files that it wrote to the temp folder into one zip file named Log.zip. Now all it has to do is send the zip file back to the C&C server and delete all traces of itself.

Impact

  • Data exfiltration
  • Credential theft
  • Theft of financial information
  • Financial loss

Indicators of Compromise

MD5

  • 593a2cbdda331f0d7d4489b04a9128e7
  • f9667599e251af696f8a87776c66eca0
  • ad310ec6a6d2417e26107aad44da6a99
  • dfa8a3cee477e6dd764c28a8a3a78e4d
  • 15aaf947579e38300d042603547c866a
  • 801bf6606f63d831e26def8f5976dac8
  • 69b1bb4f5794eacb09e3ce7a8ad1f15f
  • be1766f3ec3060119007a54500fc64ff
  • d1df925bb71198bc73a8a6a3b2c9718a

SHA-256

  • 89200f68a4e1f756e7d3ce7616fe95a34586179e4029d541751a9645a6ac9582
  • d7b0af7c27ad1013e5edb42078590f6060a210ce48b460e6fd50616a4278295d
  • 925ec2c86ef50496d7400fa29a960b9547ad21ae2bb57907549368e4bd27cc43
  • 7fa8300652f1b8c48e6ac25203994e388acb14ffc29393da5175de05ec1614d8
  • d5b9b72950395ae3b512f96e87184429b9744c514ed14891cce9f5972764a296
  • aeeabbefb0ce4cc909ebc3c7d36d3272d55c09db77a162b7e607936e126d05c0
  • 56d389a215fd102eecb65009b5681642a66232e8b68aaa029b377554e1db7689
  • 0b138671b6b534306994daf163d36498a7b2dff3969931ac9b84d3eb6d1cc460
  • a6f0dc73e69c768ad702394dc9250700e54e3439a9adb609b119292f70200522

SHA-1

  • a4aead1f506af604706137d6b399efa4bb0f3d34
  • 308978e91169e5ec7899cb46b0fc172af88bb35a
  • 35bc6fc70796ba0f16e002241ea407202af479bb
  • 005e2358456d388a25e8e79d2585623f7ae5fda7
  • d7a23f5c93d03fd3c7d298277b20f5182e6ea8d2
  • f7be1ff5e020bb3322d822cc5bff77c23b370319
  • bb9de37bf233917f1ae04522f61213ef3ca6a488
  • 0a4ef4fedc18983021a5c5b7daa1de591bc8cf02
  • 52daaa5ef8e8df0d71c4d846ea243ac74c7c32e6

Remediation

  • Block the threat indicators at their respective controls.
  • Do not download software from random sources on the internet.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.