PULSE NAME
TARGETED ATTACKS AGAINST BANKS IN THE MIDDLE EAST
WHITE oilrig AlienVault 2016-05-23 Modified: 2016-10-05
4
IOCs
LOW VOLUME
The attackers sent multiple emails containing macro-enabled XLS files to employees working in the banking sector in the Middle East. The themes of the messages used in the attacks are related to IT Infrastructure such as a log of Server Status Report or a list of Cisco Iron Port Appliance details. In one case, the content of the email appeared to be a legitimate email conversation between several employees, even containing contact details of employees from several banks. This email was then forwarded to several people, with the malicious Excel file attached. Another interesting technique leveraged by this malware was the use of DNS queries as a data exfiltration channel. This was likely done because DNS is required for normal network operations. The DNS protocol is unlikely to be blocked (allowing free communications out of the network) and its use is unlikely to raise suspicion among network defenders.
Indicators of Compromise (4)
All FileHash-SHA256 domain URL
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 54611a3e8bc4d8ef5dad90f9317c64166e6c579aac7b6cb6a36b73cc5b86564a 2016-05-23
FileHash-SHA256 78549ca133d2b5f8bffbf1387d633adfa4ed45c1fb20993df534245d5ca11b68 2016-05-23
domain go0gie.com 2016-05-23
URL http://go0gIe.com/sysupdate.aspx?req=1307395055 2016-05-23