PULSE NAME
Two Years of Pawn Storm
WHITE Sofacy AlienVault 2017-04-25 Modified: 2017-04-25
95
IOCs
HIGH VOLUME
By Feike Hacquebord at Trend Micro. Pawn Storm is an active cyber espionage actor group that has been very aggressive and ambitious in recent years. The group’s activities show that foreign and domestic espionage and influence on geopolitics are the group’s main motives, and not financial gain. Its main targets are armed forces, the defense industry, news media, politicians, and dissidents. We can trace activities of Pawn Storm back to 20041 , and before our initial report in 20142 there wasn’t much published about this actor group. However, since then we have released more than a dozen detailed posts on Pawn Storm. This new report is an updated dissection of the group’s attacks and methodologies—something to help organizations gain a more comprehensive and current view of these processes and what can be done to defend against them.
Indicators of Compromise (11 / 95 total)
All URL hostname domain IPv4
TYPEINDICATORDESCRIPTIONCREATED
URL http://help-yahoo-service.com/pw/reset.php 2017-04-25
URL http://poczta.mon.q0v.pl/owa/auth/expiredpassword.aspx?sid=JGVjVXJlcEBSQG1FdEVy 2017-04-25
URL http://poczta.mon.q0v.pl/auth/expiredpassword.aspx?sid=JGVjVXJlcEBSQG1FdEVy 2017-04-25
URL https://mail.academl.com/owa/auth/logon.aspx?replaceCurrent=1&url=https%3a%2f%2fmail.academi.com%2fowa%2f&tids=lkdmfvlkd 2017-04-25
URL http://mail.academl.com/owa/auth/logon.aspx?replaceCurrent=1&url=https://mail.academi.com/owa/&tids=lkdmfvlkd 2017-04-25
URL https://accounts.g00qle.com/ServiceLogin/?continue=3Dhttps://security.google.com/settings/security/secureaccount 2017-04-25
URL http://accounts.g00qle.com/ServiceLogin/?continue=3Dhttps://security.google.com/settings/security/secureaccount&hl=3Den&sarp=3Dhttps://mail.google.com/mail/&docid=amVmZnJleS5maXNjaEBnbWFpbC5jb20=&refer=SmVmZnJleStGaXNjaGVy&tel=1 2017-04-25
URL http://accounts.g00qle.com/ServiceLogin/?continue=3Dhttps://security.google.com/settings/security/secureaccount 2017-04-25
URL http://account.password-google.com/EditPasswd?e=orysiaua@gmail.com&n=T3J5c2lh&fn=T3J5c2lhK0x1dHNldnljaA== 2017-04-25
URL http://account.password-google.com/EditPasswd?e=example@gmail.com&n=&fn= 2017-04-25
URL http://tas-cass.org/wpmedia.php?q=653g3g3446g4g4342 2017-04-25