PULSE NAME
Another InfoStealer Discovered
WHITE eric.ford 2023-04-04 Modified: 2023-05-04
12
IOCs
MEDIUM VOLUME
On 29 March 2023, Cyble reported that they discovered a new InfoStealer titled Creal whose source code and builder are publicly accessible. Cyble observed the stealer delivered via phishing websites and collects login credentials and cookies from various browsers with data exfiltration occurring via Discord or through various file hosting and sharing services. This threat is highly likely operating now, with a roughly even chance of targeting customers. Currently, the threat is reported as limited, but reporting of the public availability will likely cause the threat to become widespread. Customers will likely fit an adversary’s interest and make the likelihood of compromise consistent or higher than normal. ATI recommends mitigative action occur within the normal business cycle, which includes blocking certain websites or attachment types (such as Telegram, Discord, .lnk, and .iso.) if they are not necessary for business operations.
Indicators of Compromise (12)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 929e6f2c8896059c72368915abcaefa2 MD5 of 7122f0b88607061806fd62282e8b175ae28b7e29 2023-04-04
FileHash-MD5 bb2ca78ffff72d58599d66bf9b2f0ae6 MD5 of 20dcb84660e5f79a98c190d3d455fce368d96f35 2023-04-04
FileHash-SHA1 20dcb84660e5f79a98c190d3d455fce368d96f35 2023-04-04
FileHash-SHA1 7122f0b88607061806fd62282e8b175ae28b7e29 2023-04-04
FileHash-SHA256 4ee417cbefa1673d088a32df48b8182bdad244541e8dc02faf540b9aa483fdcb SHA256 of 20dcb84660e5f79a98c190d3d455fce368d96f35 2023-04-04
FileHash-SHA256 f3197e998822bc45cb9f42c8b153c59573aad409da01ac139b7edd8877600511 SHA256 of 7122f0b88607061806fd62282e8b175ae28b7e29 2023-04-04
URL https://sellix.io 2023-04-04
URL https://steam.com 2023-04-04
domain geolocation-db.com 2023-04-04
domain kryptex.software 2023-04-04
domain sellix.io 2023-04-04
domain steam.com 2023-04-04