PULSE NAME
A Look Into Fysbis: Sofacy’s Linux Backdoor
WHITE Sofacy AlienVault 2016-02-13 Modified: 2017-08-23
11
IOCs
MEDIUM VOLUME
The Sofacy group, also known as APT28 and Sednit, is a fairly well known cyber espionage group believed to have ties to Russia. Their targets have spanned all across the world, with a focus on government, defense organizations and various Eastern European governments. From these reports, we know that the group uses an abundance of tools and tactics, ranging across zero-day exploits targeting common applications such as Java or Microsoft Office, heavy use of spear-phishing attacks, compromising legitimate websites to stage watering-hole attacks, and targeting over a variety of operating systems – Windows, OSX, Linux, even mobile iOS.
Indicators of Compromise (11)
All FileHash-SHA256 domain FileHash-MD5 YARA
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 fd8b2ea9a2e8a67e4cb3904b49c789d57ed9b1ce5bebfe54fe3d98214d6a0f61 2017-08-23
FileHash-SHA256 8bca0031f3b691421cb15f9c6e71ce193355d2d8cf2b190438b6962761d0c6bb 2017-08-23
FileHash-SHA256 02c7cf55fd5c5809ce2dce56085ba43795f2480423a4256537bfdfda0df85592 2017-08-23
domain azureon-line.com 2017-08-23
domain mozilla-plugins.com 2017-08-23
FileHash-MD5 364ff454dcf00420cff13a57bcb78467 2017-08-23
FileHash-MD5 e107c5c84ded6cd9391aede7f04d64c8 2017-08-23
FileHash-MD5 075b6695ab63f36af65f7ffd45cccd39 2017-08-23
domain mozillaplagins.com 2017-08-23
YARA d2f582c70bb93bf81ff8179513402df63c245ae7 2017-08-23
YARA 55a38e3869f093256fd1deda5bdca6fdfda42905 2017-08-23