PULSE NAME
Sednit update: Analysis of Zebrocy
WHITE Sofacy AlienVault 2018-04-24 Modified: 2018-12-05
108
IOCs
HIGH VOLUME
The Sednit group – also known as APT28, Fancy Bear, Sofacy or STRONTIUM – is a group of attackers operating since 2004, if not earlier, and whose main objective is to steal confidential information from specific targets. Toward the end of 2015, we started seeing a new component deployed by the group; a downloader for the main Sednit backdoor, Xagent. Kaspersky mentioned this component for the first time in 2017 in their APT trend report and recently wrote an article where they quickly described it under the name Zebrocy. This new component is a family of malware, comprising downloaders and backdoors written in Delphi and AutoIt. These components play the same role in the Sednit ecosystem as Seduploader; that of first-stage malware.
Indicators of Compromise (45 / 108 total)
All domain URL FileHash-SHA1 FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 00b39f2deaf1f1fc29e5acb63f4d1100e04fd701 2018-04-24
FileHash-SHA1 07e44b44c5f1043d16f6011a2cf0d2e7c5a52787 2018-04-24
FileHash-SHA1 0983d940ba42135106bf7a1e87ed5a1975fc7ead 2018-04-24
FileHash-SHA1 0cd61d367dd0b13000774ab77abf3d4cfb713c8e 2018-04-24
FileHash-SHA1 0f946f619ae8e2181a5bd76c8af03347742765c6 2018-04-24
FileHash-SHA1 185ab7a371b58ff367c155ec0dabe28842d340bd 2018-04-24
FileHash-SHA1 226083c7190f1a939d5b7b352400450690d59f65 2018-04-24
FileHash-SHA1 245868d6805c66181808973e93f23293d6d2f7d1 2018-04-24
FileHash-SHA1 267abd7105ac26d5cb6ecb96292f83708f64b994 2018-04-24
FileHash-SHA1 2900ed173a9f5dc99f905942a6be595cc6f03387 2018-04-24
FileHash-SHA1 2b5a7f4e054d0130883c8821b629121e0228bf54 2018-04-24
FileHash-SHA1 2c01ae417e5de213845b1ed46d4e82d45edd598d 2018-04-24
FileHash-SHA1 36b5e59a01e7f244d4a3bbb539e57aa468115dc8 2018-04-24
FileHash-SHA1 37bd951c483da057337ef8f38d6e48051cbb39d0 2018-04-24
FileHash-SHA1 41686703ce9e9aec64b6ad1c516746751219bc62 2018-04-24
FileHash-SHA1 4a6dcbccab5344388b331d543cc2260ca531c7ca 2018-04-24
FileHash-SHA1 4ccbe222bd97dc229b36efaf52520939da9d51c8 2018-04-24
FileHash-SHA1 4e6470f4a245efaa138c8c6eedb046e916706383 2018-04-24
FileHash-SHA1 4f07d18475601d0492cbf678ee0f0860c729910e 2018-04-24
FileHash-SHA1 51ae516792570bcd069a657c27859cd3fdc07d00 2018-04-24
FileHash-SHA1 54b14fc84f152b43c63babc46f2597b053e94627 2018-04-24
FileHash-SHA1 55179f0c6bce5a37311a44efe3f9845096c09668 2018-04-24
FileHash-SHA1 62dcf2f33ecc6014fa9a10f4e9ac9fd9bb0a6d23 2018-04-24
FileHash-SHA1 6fd7ce97061169b835ea77976651b5bf20aca4ef 2018-04-24
FileHash-SHA1 7349843e4dac1226ad6ce3e3cda8c389dd599548 2018-04-24
FileHash-SHA1 7b5c223a4968cc2190c1b5444cad47187d27ec50 2018-04-24
FileHash-SHA1 83882e13b369986b513f4aae245c112b82ec2097 2018-04-24
FileHash-SHA1 8aedf7a462024acf72d708c89230e4f02d94bc78 2018-04-24
FileHash-SHA1 8bd56b580974ae195e9f92b3aa525547d33434c1 2018-04-24
FileHash-SHA1 9beacd8e145fa01e16409d44d8b9470af6c7afd8 2018-04-24
FileHash-SHA1 a172fe6e91170f858c8ce5d734c094996bdf83d0 2018-04-24
FileHash-SHA1 ae93b6ec2d56512a1c7e8c053d2a6ce6fdfb7e4c 2018-04-24
FileHash-SHA1 afd5a60b7fff4deea15f7011339ad2cc2987a937 2018-04-24
FileHash-SHA1 b8b847d3d0139db68dba730b3424b29dcb40b3c7 2018-04-24
FileHash-SHA1 c0271dbb02636402742c390ffbeee6418f696668 2018-04-24
FileHash-SHA1 c08d89c7f7be69d5d705d4ac7e24e8f48e22faaf 2018-04-24
FileHash-SHA1 c2f3ca699aef3d226a800c2262efdca1470e00dc 2018-04-24
FileHash-SHA1 cdf9c24b86bc9a872035dcf3f53f380c904ed98b 2018-04-24
FileHash-SHA1 d379b94a3eb4fd9c9a973f64d436d7fc2e9d6762 2018-04-24
FileHash-SHA1 d4ab51bc5c26183771e3358d76e348943f9dd2fc 2018-04-24
FileHash-SHA1 d6fdc72792ee736b8d606d40d72cb89d6e8a3e18 2018-04-24
FileHash-SHA1 dabeadf0a9af3a8a0802f8445670806cd7671b1d 2018-04-24
FileHash-SHA1 f10b2c052afc07e2dec9dbe816031059fdc900ba 2018-04-24
FileHash-SHA1 f63e29621c8becac47ae6eac7bf9577bd0a37b73 2018-04-24
FileHash-SHA1 fea8752d90d2b4f0fc49ac0d58d62090782d8c5b 2018-04-24