PULSE NAME
The Digital Plagiarist Campaign: TelePorting the Carbanak Crew to a New Dimension
WHITE Anunak AlienVault 2017-01-09 Modified: 2017-08-30
31
IOCs
MEDIUM VOLUME
Over the past few months, the tr1adx team has been tracking a Threat Actor which we codenamed "TelePort Crew". We believe the TelePort Crew Threat Actor is operating out of Russia or Eastern Europe with the groups major motivations appearing to be financial in nature through cybercrime and/or corporate espionage. We have dubbed the groups latest campaign Digital Plagiarist for its signature practice of mirroring legitimate sites (using Tenmaxs TelePort Pro and TelePort Ultra site mirroring software) onto similarly named domains, on which the TelePort Crew would host and serve up malware laden Office documents. The Threat Actor would then craft specific spear phishing emails to direct their targets to visit the malicious web sites and open the malware laden documents. Corerrelation of the TelePort Crews TTPs and infrastructure leads us to believe the group is closely affiliated with, and may in fact be, the Carbanak Threat Actor.
Indicators of Compromise (31)
All domain FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
domain iris-woridwide.com 2017-01-09
domain zynga-ltd.com 2017-01-09
domain perrigointernational.com 2017-01-09
domain bols-googls.com 2017-01-09
domain google-ssls.com 2017-01-09
domain microfocus-official.com 2017-01-09
domain waldorfs-astoria.com 2017-01-09
domain google5-ssl.com 2017-01-09
domain syngenta-usa.com 2017-01-09
domain bentley-systems-ltd.com 2017-01-09
domain ai0ha.com 2017-01-09
domain prsnewwire.com 2017-01-09
domain google2-ssl.com 2017-01-09
domain taskretaiitechnology.com 2017-01-09
domain ornuafood.com 2017-01-09
domain atlantis-bahamas.com 2017-01-09
domain sizzier.com 2017-01-09
domain strideindustrialusa.com 2017-01-09
domain ssl-googles4.com 2017-01-09
domain fda-gov.com 2017-01-09
domain google3-ssl.com 2017-01-09
domain dhl-service-au.com 2017-01-09
domain esb-energy-int.com 2017-01-09
domain ssl-googlesr5.com 2017-01-09
domain google4-ssl.com 2017-01-09
domain google-stel.com 2017-01-09
domain treasury-government.com 2017-01-09
FileHash-MD5 950afc52444e3b23a4923ab07c1e7d87 2017-01-09
FileHash-MD5 ae8404ad422e92b1be7561c418c35fb7 2017-01-09
FileHash-SHA1 400f02249ba29a19ad261373e6ff3488646e95fb 2017-01-09
FileHash-SHA1 1827a7daa98c127af11318eebe23ec367f9146c9 2017-01-09