PULSE NAME
Intrusion into the Democratic National Committee
WHITE APT 29 AlienVault 2016-06-14 Modified: 2017-08-24
13
IOCs
MEDIUM VOLUME
CrowdStrike Services Inc., our Incident Response group, was called by the Democratic National Committee (DNC), the formal governing body for the US Democratic Party, to respond to a suspected breach. We deployed our IR team andtechnologyand immediately identified two sophisticated adversaries on the network – COZY BEAR and FANCY BEAR. In fact, our team considers them some of the best adversaries out of all the numerous nation-state, criminal and hacktivist/terrorist groups we encounter on a daily basis. In particular, we identified advanced methods consistent with nation-state level capabilities including deliberate targeting and ‘access management’ tradecraft – both groups were constantly going back into the environment to change out their implants, modify persistent methods, move to new Command & Control channels and perform other tasks to try to stay ahead of being detected.
Indicators of Compromise (13)
All FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 6c1bce76f4d2358656132b6b1d471571820688ccdbaca0d86d0ca082b9390536 2017-08-24
FileHash-SHA256 b101cd29e18a515753409ae86ce68a4cedbe0d640d385eb24b9bbb69cf8186ae 2017-08-24
FileHash-SHA256 4845761c9bed0563d0aa83613311191e075a9b58861e80392914d61a21bad976 2017-08-24
FileHash-SHA256 40ae43b7d6c413becc92b07076fa128b875c8dbb4da7c036639eccf5a9fc784f 2017-08-24
FileHash-SHA256 fd39d2837b30e7233bc54598ff51bdc2f8c418fa5b94dea2cadb24cf40f395e5 2017-08-24
URL http://58.49.58.58:443 2017-08-24
URL http://45.32.129.185:443 2017-08-24
URL http://185.100.84.134:443 2017-08-24
URL http://187.33.33.8:80 2017-08-24
URL http://218.1.98.203:80 2017-08-24
URL http://23.227.196.217:443 2017-08-24
URL http://185.86.148.227:443 2017-08-24
domain misdepatrment.com 2017-08-24