PULSE NAME
EPS Processing Zero-Days Exploited by Multiple Threat Actors
WHITE Turla Group AlienVault 2017-05-09 Modified: 2017-07-21
25
IOCs
MEDIUM VOLUME
Recently, FireEye identified three new zero-day vulnerabilities in Microsoft Office products that are being exploited in the wild. At the end of March 2017, we detected another malicious document leveraging an unknown vulnerability in EPS and a recently patched vulnerability in Windows Graphics Device Interface (GDI) to drop malware. Following the April 2017 Patch Tuesday, in which Microsoft disabled EPS, FireEye detected a second unknown vulnerability in EPS. FireEye believes that two actors – Turla and an unknown financially motivated actor – were using the first EPS zero-day (CVE-2017-0261), and APT28 was using the second EPS zero-day (CVE-2017-0262) along with a new Escalation of Privilege (EOP) zero-day (CVE-2017-0263). Turla and APT28 are Russian cyber espionage groups that have used these zero-days against European diplomatic and military entities. The unidentified financial group targeted regional and global banks with offices in the Middle East.
Indicators of Compromise (25)
All FileHash-SHA256 domain hostname FileHash-MD5 IPv4 CVE FileHash-SHA1 Mutex YARA
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 6785e29698444243677300db6a0c519909ae9e620d575e76d9be4862b33ed490 2017-05-09
FileHash-SHA256 91acb0d56771af0196e34ac95194b3d0bf3200bc5f6208caf3a91286958876f9 2017-05-09
FileHash-SHA256 ef783cc3c4e1e0649b4629f3396cff4c0e0e0e67c07cacb8a9ae7c0cfa16bf0c 2017-05-09
domain wmdmediacodecs.com 2017-05-09
hostname tnsc.webredirect.org 2017-05-09
FileHash-MD5 006bdb19b6936329bffd4054e270dc6a 2017-05-09
FileHash-MD5 15660631e31c1172ba5a299a90938c02 2017-05-09
FileHash-MD5 2abe3cc4bff46455a945d56c27e9fb45 2017-05-09
FileHash-MD5 e091425d23b8db6082b40d25e938f871 2017-05-09
FileHash-MD5 f8e92d8b5488ea76c40601c8f1a08790 2017-05-09
IPv4 138.201.44.30 2017-05-09
IPv4 185.106.122.113 2017-05-09
IPv4 84.200.2.12 2017-05-09
CVE CVE-2017-0261 2017-05-09
CVE CVE-2017-0001 2017-05-09
CVE CVE-2017-0263 2017-05-09
CVE CVE-2017-0262 2017-05-09
CVE CVE-2017-7255 2017-05-09
FileHash-SHA1 18b7dd3917231d7bae93c11f915e9702aa5d1bbb 2017-05-09
FileHash-SHA1 6a90e0b5ec9970a9f443a7d52eee4c16f17fcc70 2017-05-09
FileHash-SHA1 d072d9f81390c14ffc5f3b7ae066ba3999f80fee 2017-05-09
FileHash-SHA1 d5235d136cfcadbef431eea7253d80bde414db9d 2017-05-09
FileHash-SHA1 e338d49c270baf64363879e5eecb8fa6bdde8ad9 2017-05-09
Mutex flPGdvyhPykxGvhDOAZnU 2017-05-09
YARA 90a8520f63cd025dda3e99992f068f10a6f49cf1 2017-07-21