Gootkit Italian Campaign Overview
- by nlqip
(We wanted to give an assessment of JS redirection content, but it was not reachable at the time of writing; we can assume by script name it had an output of a blank page response or other misleading action.)
Conclusion
Gootkit remains active by maintaining this campaign of redirection. We’ve noticed multiple configurations targeting the same region for the past year. Gootkit tries to protect itself even after infecting the system from legitimate AV product sites and even from additional known download mirrors. This type of attention to detail proves that this malware means business and is ready to disrupt the inner components of bank sites and other defense tools. Since this malware has declared Italy as part of its attack agenda, we recommend Italian users exercise caution when opening email links, as this is a primary infection vector. Since Gootkit blocks access to AV tools, we also recommend organizations prepare local copies of malware scanning and clean up tools so they can respond quickly in an emergency.
MD5:
6523766972839c645e20c24da11513db
f7d41fc527ffc5b5d5f70d3e42c9f7ff
7dfd903cb33663cf9024866d998a5470
C2:
37[.]10[.]71[.]157
176[.]10[.]118[.]118
194[.]76[.]225[.]28
Source link
lol
(We wanted to give an assessment of JS redirection content, but it was not reachable at the time of writing; we can assume by script name it had an output of a blank page response or other misleading action.) Conclusion Gootkit remains active by maintaining this campaign of redirection. We’ve noticed multiple configurations targeting the…
Recent Posts
- Windows 10 KB5046714 update fixes bug preventing app uninstalls
- Eight Key Takeaways From Kyndryl’s First Investor Day
- QNAP pulls buggy QTS firmware causing widespread NAS issues
- N-able Exec: ‘Cybersecurity And Compliance Are A Team Sport’
- Hackers breach US firm over Wi-Fi from Russia in ‘Nearest Neighbor Attack’