PULSE NAME
Cyber Conflict Decoy Document Used In Real Cyber Conflict
WHITE Sofacy AlienVault 2017-10-22 Modified: 2017-10-23
7
IOCs
LOW VOLUME
Cisco Talos discovered a new malicious campaign from the well known actor Group 74 (aka Tsar Team, Sofacy, APT28, Fancy Bear…). Ironically the decoy document is a flyer concerning the Cyber Conflict U.S. conference organized by the NATO Cooperative Cyber Defence Centre of Excellence on 7-8 November 2017 at Washington, D.C. Due to the nature of this document, we assume that this campaign targets people with an interest in cyber security. Unlike previous campaigns from this actor, the flyer does not contain an Office exploit or a 0-day, it simply contains a malicious Visual Basic for Applications (VBA) macro.
Indicators of Compromise (5 / 7 total)
All domain FileHash-SHA256 Mutex
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 522fd9b35323af55113455d823571f71332e53dde988c2eb41395cf6b0c15805 2017-10-22
FileHash-SHA256 c4be15f9ccfecf7a463f3b1d4a17e7b4f95de939e057662c3f97b52f7fa3c52f 2017-10-22
FileHash-SHA256 e5511b22245e26a003923ba476d7c36029939b2d1936e17a9b35b396467179ae 2017-10-22
FileHash-SHA256 ef027405492bc0719437eb58c3d2774cc87845f30c40040bbebbcc09a4e3dd18 2017-10-22
FileHash-SHA256 efb235776851502672dba5ef45d96cc65cb9ebba1b49949393a6a85b9c822f52 2017-10-22