PULSE NAME
StrongPity2 spyware replaces FinFisher in MitM campaign – ISP involved?
WHITE StrongPity AlienVault 2017-12-08 Modified: 2019-07-12
19
IOCs
MEDIUM VOLUME
Continuing our research into FinFisher – the infamous spyware known also as FinSpy and sold to governments and their agencies worldwide – we noticed that the FinFisher malware in our previously-documented campaign, which had strong indicators of internet service provider (ISP) involvement, had been replaced by different spyware. Detected by ESET as Win32/StrongPity2, this spyware notably resembles one that was attributed to the group called StrongPity. As well as detecting and blocking this threat, all ESET products – including the free ESET Online scanner – thoroughly clean systems compromised by StrongPity2.
Indicators of Compromise (19)
All FileHash-SHA256 domain URL hostname FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 462e85023952d23b74d697911653604b40497424e7a6fe505366addae6c375f7 2017-12-08
domain updserv-east-cdn3.com 2017-12-08
URL https://downloading.internetdownloading.co 2017-12-08
URL https://updserv-east-cdn3.com/kU2QLsNB6TzexJv5vGdunVXT.php 2017-12-08
URL https://updserv-east-cdn3.com/p55C3xhxTuD5rkBQbB8wE99Q.php 2017-12-08
URL https://updserv-east-cdn3.com/s3s3sxhxTuDSrkBQb88wE99Q.php 2017-12-08
hostname downloading.internetdownloading.co 2017-12-08
FileHash-SHA1 49c2bcae30a537454ad0b9344b38a04a0465a0b5 2017-12-08
FileHash-SHA1 4ad3ecc01d3aa73b97f53e317e3441244cf60cbd 2017-12-08
FileHash-SHA1 76fc68607a608018277afa74ee09d5053623ff36 2017-12-08
FileHash-SHA1 87a38a8c357f549b695541d603de30073035043d 2017-12-08
FileHash-SHA1 8b33b11991e1e94b7a1b03d6fb20541c012be0e3 2017-12-08
FileHash-SHA1 9f2d9d2131eff6220abaf97e2acd1bbb5c66f4e0 2017-12-08
FileHash-SHA1 a0437a2c8c50b8748ca3344c38bc80279779add7 2017-12-08
FileHash-SHA1 e17b5e71d26b2518871c73e8b1459e85fb922814 2017-12-08
FileHash-SHA1 f8009ef802a28c2e21bce76b31094ed4a16e70d6 2017-12-08
hostname www.myrappid.com 2017-12-08
hostname www.pinkturtle.me 2017-12-08
domain myrappid.com 2017-12-08