PULSE NAME
Targeted Crimeware in the Midst of Indiscriminate Activity
WHITE AlienVault 2015-05-06 Modified: 2017-08-24
29
IOCs
MEDIUM VOLUME
Although we have observed low volume spam campaigns by some cybercriminals who have purchased MWI, we recently discovered spearphishing emails by one group using MWI to direct an attack against point-of-sale (POS) service providers. Despite the targeted nature of the spearphishing emails, the payload was the widely distributed Vawktrak banking Trojan. In addition, we found that the infrastructure used in this case overlaps with FindPOS/PoSeidon as well as Chanitor and sits amidst a cluster of largely indiscriminate malicious activity.
Indicators of Compromise (7 / 29 total)
All domain URL FileHash-MD5 email
TYPEINDICATORDESCRIPTIONCREATED
domain othersforrep.com 2017-08-24
domain cakedhisjohn.com 2017-08-24
domain xablopefgr.com 2017-08-24
domain idthentehed.com 2017-08-24
domain pickleweb.net 2017-08-24
domain rebteugrigh.com 2017-08-24
domain winfertrow.com 2017-08-24