PULSE NAME
Introducing WhiteBear
WHITE Turla Group AlienVault 2017-08-30 Modified: 2017-08-30
9
IOCs
LOW VOLUME
As a part of our Kaspersky APT Intelligence Reporting subscription, customers received an update in mid-February 2017 on some interesting APT activity that we called WhiteBear. Much of the contents of that report are reproduced here. WhiteBear is a parallel project or second stage of the Skipper Turla cluster of activity documented in another private intelligence report “Skipper Turla – the White Atlas framework” from mid-2016. Like previous Turla activity, WhiteBear leverages compromised websites and hijacked satellite connections for command and control (C2) infrastructure.
Indicators of Compromise (9)
All URL domain FileHash-MD5 IPv4
TYPEINDICATORDESCRIPTIONCREATED
URL http://soligro.com/wp-includes/pomo/db.php 2017-08-30
domain mydreamhoroscope.com 2017-08-30
domain soligro.com 2017-08-30
FileHash-MD5 06bd89448a10aa5c2f4ca46b4709a879 2017-08-30
FileHash-MD5 19ce5c912768958aa3ee7bc19b2b032c 2017-08-30
FileHash-MD5 b099b82acb860d9a9a571515024b35f0 2017-08-30
IPv4 169.255.137.203 2017-08-30
IPv4 217.171.86.137 2017-08-30
IPv4 66.178.107.140 2017-08-30