PULSE NAME
The MeDoc Connection
WHITE AlienVault 2017-07-05 Modified: 2017-07-05
6
IOCs
LOW VOLUME
The Nyetya attack was a destructive ransomware variant that affected many organizations inside of Ukraine and multinational corporations with operations in Ukraine. In cooperation with Cisco Advanced Services Incident Response, Talos identified several key aspects of the attack. The investigation found a supply chain-focused attack at M.E.Doc software that delivered a destructive payload disguised as ransomware. By utilizing stolen credentials, the actor was able to manipulate the update server for M.E.Doc to proxy connections to an actor-controlled server. Based on the findings, Talos remains confident that the attack was destructive in nature. The effects were broad reaching, with Ukraine Cyber police confirming over 2000 affected companies in Ukraine alone.
Indicators of Compromise (6)
All FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 027cc450ef5f8c5f653329641ec1fed91f694e0d229928963b30f6b0d7d3a745 2017-07-05
FileHash-SHA256 02ef73bd2458627ed7b397ec26ee2de2e92c71a0e7588f78734761d8edbdcd9f 2017-07-05
FileHash-SHA256 2fd2863d711a1f18eeee5c7c82f2349c5d4e00465de9789da837fcdca4d00277 2017-07-05
FileHash-SHA256 d462966166450416d6addd3bfdf48590f8440dd80fc571a389023b7c860ca3ac 2017-07-05
FileHash-SHA256 eae9771e2eeb7ea3c6059485da39e77b8c0c369232f01334954fbac1c186c998 2017-07-05
FileHash-SHA256 f9d6fe8bd8aca6528dec7eaa9f1aafbecde15fd61668182f2ba8a7fc2b9a6740 2017-07-05