PULSE NAME
Sednit Downloader DOWNDELPH
WHITE Sofacy AlienVault 2016-10-27 Modified: 2017-03-06
17
IOCs
MEDIUM VOLUME
The Sednit group—variously also known as APT28, Fancy Bear, Sofacy, Pawn Storm, STRONTIUM and Tsar Team—is a group of attackers operating since 2004 if not earlier, whose main objective is to steal confidential information from specific targets. Over the past two years, this group’s activity has increased significantly, with numerous attacks against government departments and embassies all over the world. Among their most notable presumed targets are the American Democratic National Committee, the German parliament and the French television network TV5Monde [3]. Moreover, the Sednit group has a special interest in Eastern Europe, where it regularly targets individuals and organizations involved in geopolitics
Indicators of Compromise (17)
All domain FileHash-SHA1 IPv4
TYPEINDICATORDESCRIPTIONCREATED
domain intelmeserver.com 2016-10-27
FileHash-SHA1 e8aca4b0cfe509783a34ff908287f98cab968d9e 2016-10-27
FileHash-SHA1 669a02e330f5afc55a3775c4c6959b3f9e9965cf 2016-10-27
FileHash-SHA1 5fc4d555ca7e0536d18043977602d421a6fd65f9 2016-10-27
FileHash-SHA1 4c9c7c4fd83edaf7ec80687a7a957826de038dd7 2016-10-27
FileHash-SHA1 49acba812894444c634b034962d46f986e0257cf 2016-10-27
FileHash-SHA1 9f3ab8779f2b81cae83f62245afb124266765939 2016-10-27
FileHash-SHA1 5c132ae63e3b41f7b2385740b9109b473856a6a5 2016-10-27
FileHash-SHA1 593d0eb95227e41d299659842395e76b55aa048d 2016-10-27
FileHash-SHA1 1cc2b6b208b7687763659aeb5dcb76c5c2fbbf26 2016-10-27
FileHash-SHA1 6caa48cd9532da4cabd6994f62b8211ab9672d9e 2016-10-27
FileHash-SHA1 ee788901cd804965f1cd00a0afc713c8623430c4 2016-10-27
FileHash-SHA1 516ec3584073a1c05c0d909b8b6c15ecb10933f1 2016-10-27
FileHash-SHA1 7394ea20c3d510c938ef83a2d0195b767cd99ed7 2016-10-27
FileHash-SHA1 4f92d364ce871c1aebbf3c5d2445c296ef535632 2016-10-27
IPv4 104.171.117.216 2016-10-27
IPv4 141.255.160.52 2016-10-27