PULSE NAME
Carbanak gang is back and packing new guns
WHITE Anunak AlienVault 2015-09-08 Modified: 2017-08-30
82
IOCs
HIGH VOLUME
The Carbanak financial APT group made the headlines when Group-IB and Fox-IT broke the news in December 2014, followed by the Kaspersky report in February 2015. The two reports describe the same cybercriminal gang which stole up to several hundreds of millions of dollars from various financial institutions. However, the story is interesting not only because of the large amount of money stolen but also from a technical point of view. The Carbanak team does not just blindly compromise large numbers of computers and try to ‘milk the cow’ as other actors do, instead they act like a mature APT-group. They only compromise specific high-value targets and once inside the company networks, move laterally to hosts that can be monetized.
Indicators of Compromise (82)
All domain hostname FileHash-SHA1 CVE YARA FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
domain seven-sky.org 2017-08-23
domain adobe-dns-3-adobe.com 2017-08-23
domain clients4-google.com 2017-08-23
domain comixed.org 2017-08-23
hostname img.in-travelusa.com 2017-08-23
FileHash-SHA1 e838004a216e58c44553a168760100b497e514e8 2017-08-23
FileHash-SHA1 5943abcf662dc9634b714b1358164b65e5651d15 2017-08-23
FileHash-SHA1 3552338d471b7a406d8f7e264e93b848075235c0 2017-08-23
FileHash-SHA1 e8514bf4c4e1f35fb1737c2f28a4a4ced07aa649 2017-08-23
FileHash-SHA1 833a8d88be11807bae966d56b28af7b3cc34dbcd 2017-08-23
FileHash-SHA1 6090853934833d0814f9239e6746161491cccb44 2017-08-23
FileHash-SHA1 dd01331abff03525506cdcbac4d76cb4efd602a4 2017-08-23
FileHash-SHA1 170142c042bf32ff86af680ead86cd1af075b0cb 2017-08-23
FileHash-SHA1 3927835c620058efcadf76642489fc13aace305b 2017-08-23
FileHash-SHA1 ac95f01487b4f179a1f10684b1e0a5656940a005 2017-08-23
FileHash-SHA1 ec5dadaacae763d0e55ce6a78c9a5f57b01a5135 2017-08-23
FileHash-SHA1 5b6aba51215a9662987f59aef6cae0a9e3a720b8 2017-08-23
FileHash-SHA1 b79e6a21d8c2813ec2279727746bdb685180751a 2017-08-23
FileHash-SHA1 850e9a10e6d20d33c8d2c765e22771e8919fc3ee 2017-08-23
FileHash-SHA1 68ea12cdccee01d50c23ebc29caa96bf40925dc6 2017-08-23
FileHash-SHA1 af7564ee7959142c3b0d9eb8129605c2ae582cb7 2017-08-23
FileHash-SHA1 bcf9e4dce910e94739728158c98578a8d145be56 2017-08-23
FileHash-SHA1 ac68ad2e5f5802a6ab9e7e1c1ec7fab3c6bdbaa4 2017-08-23
FileHash-SHA1 5e8b566095fd6a98949ef5c479ce290f520dd9e2 2017-08-23
FileHash-SHA1 6f452c76f7ac00fe1463314f5aa0a80ec4f7360c 2017-08-23
FileHash-SHA1 d71e310adf183f02e36b06d166f8e3ad54fdbcc9 2017-08-23
FileHash-SHA1 84cc02b3c10306bfcece8bf274b57475b056c6d6 2017-08-23
FileHash-SHA1 f8cbf647a64028cae835a750ef3f8d1aa216e46c 2017-08-23
FileHash-SHA1 ded83a1e3b6630d69077976cc01321fbc946dce2 2017-08-23
FileHash-SHA1 1ad84a244b7d4fbb4d89d023b21715b346027e49 2017-08-23
FileHash-SHA1 4e8ee08ff4f8dc06aff8de2e476afafba58bdc11 2017-08-23
FileHash-SHA1 3cef1ca36a78cba308fb29a46b20e5ca22d03289 2017-08-23
FileHash-SHA1 cf1f97879a6eb26fedc7207d6679dfa221dd2d45 2017-08-23
FileHash-SHA1 8c2c08111f76c84c7573cf07c3d319a43180e734 2017-08-23
FileHash-SHA1 32aa4911bc6ab8098e496cd88790ff7147ec6ac3 2017-08-23
FileHash-SHA1 0b0884992f28a3c1439dba60007076b22831ce51 2017-08-23
FileHash-SHA1 d678bd90257cf859c055a82b4a082f9182eb3437 2017-08-23
FileHash-SHA1 207ff65543dac6d1d9f86dffd891c507ad24018b 2017-08-23
FileHash-SHA1 d627dd4e3850cbd571afc4799a331054c7080b0d 2017-08-23
FileHash-SHA1 5e31db305a97736c0f419a3f2f8f093ff6a1f56f 2017-08-23
FileHash-SHA1 0b8605d0293d04bbf610103039768cbe62e2faae 2017-08-23
FileHash-SHA1 2dd485729e0402fd652cf613e172ea834b5c9077 2017-08-23
FileHash-SHA1 567749b4f2330f02dd181c6c0840191cee2186d9 2017-08-23
FileHash-SHA1 7a9be31078bc9b5fece94bc1a9f45b7dbf0fce12 2017-08-23
FileHash-SHA1 33870482ba7de041587d4b809574b458c0673e94 2017-08-23
FileHash-SHA1 a09f520dded0d5292a5fa48e80de02f9af718d06 2017-08-23
FileHash-SHA1 905d0842cc246a772c595b8cf4a4e9e517683eb7 2017-08-23
FileHash-SHA1 7162bb61cd36ed8b7ee98cbd0bffec33d34dd3e7 2017-08-23
FileHash-SHA1 36093a6004a9502079b054041badc43c69a0bdeb 2017-08-23
FileHash-SHA1 7267791340204020727923cc7c8d65afc18f6f5b 2017-08-23
FileHash-SHA1 a40bdf005b4b469d2c7bed1766c9da9823e1cfb7 2017-08-23
FileHash-SHA1 3672c9f4e7f647f2af9ae6d5ea8d9c7ff16faf40 2017-08-23
FileHash-SHA1 dcc932b878b374d47540d43a2dee97f37d68267f 2017-08-23
FileHash-SHA1 28d514fe46d8b5720fe27c40c3889f3b45967cc7 2017-08-23
FileHash-SHA1 3acea9477b219fc6b8c0a734e67339ae2eb2aa5b 2017-08-23
FileHash-SHA1 a77336620df96642691c1e5b6c91511bfa76a5be 2017-08-23
FileHash-SHA1 8330bc5a3dcc52a22e50187080a60d6dbf23e7e6 2017-08-23
FileHash-SHA1 efc0555418a6ed641047d29178d0da3aefa7adeb 2017-08-23
FileHash-SHA1 2896814e5f8860e620ac633af53a55d9aa21f8c0 2017-08-23
FileHash-SHA1 a734193f550dda5c1ffd9fec3a0186a0a793449c 2017-08-23
FileHash-SHA1 6ff3ae5ba4e9a312602cbd44a398a02ab0437378 2017-08-23
FileHash-SHA1 19e7c7a78c5d58945b615d98ff0990389485933f 2017-08-23
FileHash-SHA1 a048c093c5da06af148ca75299960f618f878b3a 2017-08-23
FileHash-SHA1 237784574afb8868213c900c18a114d3fa528b95 2017-08-23
FileHash-SHA1 3a9a23c01393a4046a5f38fdbac371d5d4a282f1 2017-08-23
FileHash-SHA1 8d5f2bf805a9047d58309788a3c9e8de395469a8 2017-08-23
FileHash-SHA1 1f9462aa39645376c74566d55866f7921bd848f7 2017-08-23
FileHash-SHA1 3707029dc5cbbe17fd4de34134847f92e7324c45 2017-08-23
FileHash-SHA1 983d33f547588a59b53d7f794768b264454446d5 2017-08-23
FileHash-SHA1 81e43d653acd2b55c8d3107e5b50007870d84d76 2017-08-23
FileHash-SHA1 f869c7ea683337a2249908c21b9d3283cc2dd780 2017-08-23
FileHash-SHA1 b4a94a214fc664b8d184154431e1c5a73ca0ae63 2017-08-23
FileHash-SHA1 4db58e7d0fca8d6748e17087eb34e562b78e1fde 2017-08-23
CVE CVE-2015-2426 2017-08-23
CVE CVE-2015-1770 2017-08-23
domain weekend-service.com 2017-08-23
YARA 00ab1e641dea8654c6ee48fa4c34a79408bce133 2017-08-23
YARA a12fa13c677c3ab226f53667f7d3074cd62e39c8 2017-08-23
FileHash-SHA256 0b5dc030e73074b18b1959d1cf7177ff510dbc2a0ec2b8bb927936f59eb3d14d 2017-08-23
FileHash-SHA256 18e3e840a5e5b75747d6b961fca66a670e3faef252aaa416a88488967b47ac1c 2017-08-23
FileHash-SHA256 ad6bb982a1ecfe080baf0a2b27950f989c107949b1cf02b6e0907f1a568ece15 2017-08-23
FileHash-SHA256 fc609adef44b5c64de029b2b2cff22a6f36b6bdf9463c1bd320a522ed39de5d9 2017-08-23