Rewterz
Rewterz Threat Alert – SmokeLoader Malware – Active IOCs
December 9, 2021
Rewterz
Rewterz Threat Advisory – Multiple SonicWall SMA 100 Series Devices Vulnerabilities
December 9, 2021

Rewterz Threat Alert – Raccoon Infostealer – Active IOCs

Severity

High

Analysis Summary

Also known as “Racealer,” Racoon is used to steal sensitive and confidential information including login credentials, credit card information, cryptocurrency wallets and browser information (cookies, history, autofill) from almost 60 applications. Raccoon stealer is written in C++ and it has a wide range of methods and features for stealing data from popular browsers, email clients and cryptocurrency wallets. The malware is delivered via exploit kits that use browser-based vulnerabilities to redirect victims to landing pages injected with exploit codes. It’s also spread via phishing campaigns convincing targets to execute the malicious payload or macros. The malware gathers information about the machine like the OS arch and version, system language, hardware information and installed applications. In addition, it can take screenshots from the user’s machine if that was enabled by the attacker’s configuration. After fulfilling all its stealing capabilities, Raccoon gathers all the files that it wrote to the temp folder into one zip file named Log.zip. Now all it has to do is send the zip file back to the C&C server and delete all traces of itself.

Impact

  • Data Exfiltration
  • Credential Theft
  • Financial Loss

Indicators of Compromise

MD5

  • 4a7e711416f01ea6ea7dd33c3e4fe16b
  • 90b477d2d26f07e17a71d0e17dbb706b
  • a251ed6c078614e663e4ada306429782
  • 82647c7fd8bfcebe57a46f009285e030
  • 0a8277b8be308e4f03f2e76127900519
  • 945f150ec87c4201ae97f452b2d07640

SHA-256

  • 7c4a95d3b713f29745a28c55000e03fa3255c1b49f607cfd8c0a018256e83d73
  • eebb0bc908c35371455035b1bfdf3e1b89abd056deaece5b295f0863f0c5aeed
  • 0850e7daf8a13b13aeb3d48bf41303856735c01e2b4d97819222c9b8c700aebe
  • eefc11d7652518188e5cec696e4e45f774acc45b4d158cba71eb5a8cfe392736
  • 2f1035b3e20ba563758a7f6c09cbfb929120ee39a3461096ddcb5ec1af844c1c
  • 7bfd5e39d9f727940ade736f2b32a6b53e0f2bf622a1b69c0235e562f037fc45

SHA-256

  • 31915ec26545fa6552f7c1e44c81eaab7e69ac33
  • 5d2a4046cf3aad360ada50ab052e4cd702592722
  • 3cf498e32d901ab24b9ba927c0c92c80c9377687
  • d602af33f0bb33493b0d3530ee9369b5cfe2df0a
  • e99da3a92789f5db44fe6ec52067a6d2a5ecdf1a
  • c484911fa39334c63ae1b27a9206c6b89e67b074

Remediation

  • Block all threat indicators at your respective controls.
  • Search for IOCs in your environment.