← Back to Pulse Feed
PULSE DETAIL
PULSE NAME
Similarities Between Carbanak and FIN7 Malware Suggest Actors Are Closely Related
Several days ago, researchers at FireEye attributed a recent phishing campaign to FIN7, a campaign in which cybercriminals delivered malicious Microsoft Office documents to users, deploying both Cobalt Strike and a VBS-based backdoor on infected workstations. This report contained a sentence of particular interest to Cyber4Sight: “FIN7 is referred to by many vendors as ‘Carbanak Group,’ although we do not equate all usage of the Carbanak backdoor with FIN7.” In their previous report on this threat actor group, FireEye stopped short of making this direct connection, stating instead that “The use of the CARBANAK malware in FIN7 operations also provides limited evidence that these campaigns are linked to previously observed CARBANAK operations leading to fraudulent banking transactions, ATM compromise, and other monetization schemes.”
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| URL | http://198.100.119.7:443/cd | — | 2017-04-28 | |
| URL | http://198.100.119.7:80/cd | — | 2017-04-28 | |
| URL | http://198.100.119.7:8080/cd | — | 2017-04-28 | |
| URL | http://204.155.31.167:443/cd | — | 2017-04-28 | |
| URL | http://204.155.31.167:80/cd | — | 2017-04-28 | |
| URL | http://204.155.31.167:8080/cd | — | 2017-04-28 | |
| URL | http://204.155.31.174:443/cd | — | 2017-04-28 | |
| URL | http://204.155.31.174:80/cd | — | 2017-04-28 | |
| URL | http://204.155.31.174:8080/cd | — | 2017-04-28 | |
| URL | http://31.148.219.141:443/cd | — | 2017-04-28 | |
| URL | http://31.148.219.141:80/cd | — | 2017-04-28 | |
| URL | http://31.148.219.141:8080/cd | — | 2017-04-28 | |
| IPv4 | 198.100.119.6 | — | 2017-04-28 | |
| IPv4 | 198.100.119.7 | — | 2017-04-28 | |
| IPv4 | 204.155.31.167 | — | 2017-04-28 | |
| IPv4 | 204.155.31.174 | — | 2017-04-28 | |
| IPv4 | 31.148.219.141 | — | 2017-04-28 | |
| YARA | f4498958e90780e3b4d1bc1582022ddab92477b6 | — | 2017-07-24 | |
| YARA | 907fcd2eb041563d29662c37e181a023c147e96f | — | 2017-07-24 | |
| YARA | 5bfaee4b7379bcf4d9228af708490b82db851a28 | — | 2017-07-24 |