PULSE NAME
Similarities Between Carbanak and FIN7 Malware Suggest Actors Are Closely Related
WHITE Anunak AlienVault 2017-04-28 Modified: 2017-07-24
20
IOCs
MEDIUM VOLUME
Several days ago, researchers at FireEye attributed a recent phishing campaign to FIN7, a campaign in which cybercriminals delivered malicious Microsoft Office documents to users, deploying both Cobalt Strike and a VBS-based backdoor on infected workstations. This report contained a sentence of particular interest to Cyber4Sight: “FIN7 is referred to by many vendors as ‘Carbanak Group,’ although we do not equate all usage of the Carbanak backdoor with FIN7.” In their previous report on this threat actor group, FireEye stopped short of making this direct connection, stating instead that “The use of the CARBANAK malware in FIN7 operations also provides limited evidence that these campaigns are linked to previously observed CARBANAK operations leading to fraudulent banking transactions, ATM compromise, and other monetization schemes.”
Indicators of Compromise (20)
All URL IPv4 YARA
TYPEINDICATORDESCRIPTIONCREATED
URL http://198.100.119.7:443/cd 2017-04-28
URL http://198.100.119.7:80/cd 2017-04-28
URL http://198.100.119.7:8080/cd 2017-04-28
URL http://204.155.31.167:443/cd 2017-04-28
URL http://204.155.31.167:80/cd 2017-04-28
URL http://204.155.31.167:8080/cd 2017-04-28
URL http://204.155.31.174:443/cd 2017-04-28
URL http://204.155.31.174:80/cd 2017-04-28
URL http://204.155.31.174:8080/cd 2017-04-28
URL http://31.148.219.141:443/cd 2017-04-28
URL http://31.148.219.141:80/cd 2017-04-28
URL http://31.148.219.141:8080/cd 2017-04-28
IPv4 198.100.119.6 2017-04-28
IPv4 198.100.119.7 2017-04-28
IPv4 204.155.31.167 2017-04-28
IPv4 204.155.31.174 2017-04-28
IPv4 31.148.219.141 2017-04-28
YARA f4498958e90780e3b4d1bc1582022ddab92477b6 2017-07-24
YARA 907fcd2eb041563d29662c37e181a023c147e96f 2017-07-24
YARA 5bfaee4b7379bcf4d9228af708490b82db851a28 2017-07-24