Rewterz
Rewterz Threat Alert – Titanium Malware: the Platinum group strikes again
November 11, 2019
Rewterz
Rewterz Threat Alert – Scammers Abusing a New Firefox Browser Lock Bug
November 12, 2019

Rewterz Threat Alert – Variant of Adwind RAT Targets Petroleum Sector

Severity

High

Analysis Summary

Adwind is a remote access Trojan known to evade detection upon entry and to communicate with a command-and-control server once connected. The Trojan can steal sensitive information, such as credentials, as well as spy through a user’s webcam and log a user’s keystoke activity. The new addition to the modified remote access Trojan uses multi-layer obfuscation by containing various file extensions to avoid detection, with iDefense suspecting it to be tailored specifically to this industry. The malware originated from compromised Westnet accounts.

Impact

  • Information Theft
  • Credential Theft
  • Unauthorized Access

Indicators of Compromise

Hostname

members[.]westnet[.]com[.]au

Source IP

185[.]205.210[.]48

URL

hxxp[:]//members[.]westnet.com[.]au/~

Remediation

  • Block the threat indicators at their respective controls.
  • Do not download files/software from random sources on the internet.