PULSE NAME
FacexWorm Targets Cryptocurrency Trading Platforms, Abuses Facebook Messenger for Propagation
WHITE AlienVault 2018-05-01 Modified: 2018-05-01
28
IOCs
MEDIUM VOLUME
Our Cyber Safety Solutions team identified a malicious Chrome extension we named FacexWorm, which uses a miscellany of techniques to target cryptocurrency trading platforms accessed on an affected browser and propagates via Facebook Messenger. A very small percentage of users were affected by these malicious extensions, and Chrome had already removed many of these extensions prior to being alerted by Trend Micro. FacexWorm isn’t new. It was uncovered in August 2017, though its whys and hows were still unclear at the time. Last April 8, however, we noticed a spike in its activities that coincided with external reports of FacexWorm surfacing in Germany, Tunisia, Japan, Taiwan, South Korea, and Spain.
Indicators of Compromise (28)
All URL hostname domain FileHash-SHA256
TYPEINDICATORDESCRIPTIONCREATED
URL http://ijocire.bid/e6105edf3ecbc810299f2c3f4f8d768a.b 2018-05-01
URL http://seap.co/fugoguba/iseyuda.json?nacmsszykj 2018-05-01
URL http://opekibutuk.dirg.me/sc.php 2018-05-01
URL http://pingli.bid/75071f1169fae2f73763e1af7e2b346c.b 2018-05-01
URL http://uef.date/imanum/dayumec.json?ocmxtjjdak 2018-05-01
URL http://upej.date/72dc4f8eb83928ead3395b27e8e54b7c.b 2018-05-01
hostname video-sig.blogspot.com 2018-05-01
hostname video-goyd.blogspot.com 2018-05-01
domain dirg.me 2018-05-01
domain dnseat.us 2018-05-01
domain ijocire.bid 2018-05-01
domain ikesa.date 2018-05-01
domain jsapi.me 2018-05-01
domain jsdo.bid 2018-05-01
domain pingli.bid 2018-05-01
domain roes.me 2018-05-01
domain seap.co 2018-05-01
domain uef.date 2018-05-01
domain upej.date 2018-05-01
domain uto.date 2018-05-01
domain yci.date 2018-05-01
FileHash-SHA256 008c71429e51ae5163fc914a4f0e7157fc0389020ed0a921fe64540467cbb371 2018-05-01
FileHash-SHA256 026742d5eb89338f639d13e543180043973b531b9004a52391b262337dd5df91 2018-05-01
FileHash-SHA256 22a8c09181a9f6e06d102bbb0d5372560cf3a432fe3c68e6554a81e3083fbc4f 2018-05-01
FileHash-SHA256 3445b059e5e8b1e5a56cc57a38506317bf44035c95a2a053c916ca54017a40e5 2018-05-01
FileHash-SHA256 ea5abce0977b31238b715bd08b04808f8ff863134516c085cf5e0403b4268635 2018-05-01
hostname dot.filmnag.com 2018-05-01
hostname vido.vigor.design 2018-05-01