PULSE NAME
Fidelis Threat Advisory #1017: Phishing in Plain Sight
WHITE AlienVault 2015-06-09 Modified: 2015-06-09
34
IOCs
MEDIUM VOLUME
Fidelis Cybersecurity analysis has identified unrelated cyber criminal activity leveraging the vulnerability cited in CVE-2014-4114, which was initially exploited by advanced persistent threat (APT) actors in October 2014. Notably, some of this recent activity demonstrated actors implementing a technique that bypassed antivirus detection by saving a PowerPoint document in which malware executed once the document was opened in Slide Show presentation format. The identification of cyber crime actors, particularly Nigerian 419 scam operators, attempting to exploit CVE-2014-4114 demonstrates how quickly cyber criminals are trying to exploit a vulnerability previously associated with espionage actors, using similar tactics, techniques, and procedures (TTP) to maximize their chances of success, with additional innovation as seen with these samples.
Indicators of Compromise (11 / 34 total)
All FileHash-SHA256 hostname FileHash-MD5 FileHash-SHA1 CVE domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 a2601a0ef3bb2e817c8f3bcd3083edd0 2015-06-09
FileHash-MD5 c1cee41ef83a62d0b78a9f0cd6891072 2015-06-09
FileHash-MD5 cd102ef39bab23b1c17fa3ec7f6c39ee 2015-06-09
FileHash-MD5 f90ad27e8d2345b84361189dbc9c9f3d 2015-06-09
FileHash-MD5 5300a967825b13d8873f0f01d1e21849 2015-06-09
FileHash-MD5 ad9c15b11075bc9c99c547fbffc43b3f 2015-06-09
FileHash-MD5 2303c3ad273d518cbf11824ec5d2a88e 2015-06-09
FileHash-MD5 fd5a753347416484ab01712786c407c4 2015-06-09
FileHash-MD5 1e479d02dde72b7bb9dd1335c587986b 2015-06-09
FileHash-MD5 94576ca20488d444802b874c324867ac 2015-06-09
FileHash-MD5 f2f45d410533ee38750fc24035a89b32 2015-06-09