PULSE NAME
OilRig Group Steps Up Attacks with New Delivery Documents and New Injector Trojan
WHITE OilRig AlienVault 2017-10-09 Modified: 2017-10-09
18
IOCs
MEDIUM VOLUME
Unit 42’s ongoing research into the OilRig campaign shows that the threat actors involved in the original attack campaign continue to add new Trojans to their toolset and continue their persistent attacks in the Middle East. When we first discovered the OilRig attack campaign in May 2016, we believed at the time it was a unique attack campaign likely operated by a known, existing threat group. As we have progressed in our research and uncovered additional attack phases, tooling, and infrastructure as discussed in our recent posting “Striking Oil: A Closer Look at Adversary Infrastructure”, it has become apparent that the threat group responsible for the OilRig attack campaign is likely to be a unique, previously unknown adversary. Additionally, others have been referring to the group responsible for the OilRig campaign itself as the OilRig group as well. To that end, we are elevating the OilRig attack campaign to be known as the OilRig group.
Indicators of Compromise (18)
All domain FileHash-SHA256 CVE
TYPEINDICATORDESCRIPTIONCREATED
domain adpolioe.com 2017-10-09
domain cdnakamaiplanet.com 2017-10-09
domain cdnmsnupdate.com 2017-10-09
domain microsoft-publisher.com 2017-10-09
domain msoffice-cdn.com 2017-10-09
domain msoffice365update.com 2017-10-09
domain ntpupdateserver.com 2017-10-09
domain office365-management.com 2017-10-09
FileHash-SHA256 0ccb2117c34e3045a4d2c0d193f1963c8c0e8566617ed0a561546c932d1a5c0c 2017-10-09
FileHash-SHA256 119c64a8b35bd626b3ea5f630d533b2e0e7852a4c59694125ff08f9965b5f9cc 2017-10-09
FileHash-SHA256 33c187cfd9e3b68c3089c27ac64a519ccc951ccb3c74d75179c520f54f11f647 2017-10-09
FileHash-SHA256 66358a295b8b551819e053f2ee072678605a5f2419c1c486e454ab476c40ed6a 2017-10-09
FileHash-SHA256 74f61b6ff0eb58d76f4cacfb1504cb6b72684d0d0980d42cba364c6ef28223a8 2017-10-09
FileHash-SHA256 963f93824d87a56fe91283652eab5841e2ec538c207091dbc9606b962e38805d 2017-10-09
FileHash-SHA256 a9f1375da973b229eb649dc3c07484ae7513032b79665efe78c0e55a6e716821 2017-10-09
FileHash-SHA256 f92ab374edd488d85f2e113b40ea8cb8baf993f5c93c12455613ad3265f42b17 2017-10-09
FileHash-SHA256 fcad263d0fe2b418db05f47d4036f0b42aaf201c9b91281dfdcb3201b298e4f4 2017-10-09
CVE CVE-2017-0199 2017-10-09