PULSE NAME
Who’s who in the Zoo
WHITE AlienVault 2018-05-03 Modified: 2018-05-03
25
IOCs
MEDIUM VOLUME
ZooPark is a cyberespionage operation that has been focusing on Middle Eastern targets since at least June 2015. The threat actors behind the operation infect Android devices using several generations of malware, with the attackers including new features in each iteration. We label them from v1-v4, with v4 being the most recent version deployed in 2017. From the technical point of view, the evolution of ZooPark has shown notable progress: from the very basic first and second versions, the commercial spyware fork in its third version and then to the complex spyware that is version 4. This last step is especially interesting, showing a big leap from straightforward code functionality to highly sophisticated malware.
Indicators of Compromise (25)
All domain URL hostname FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
domain alnaharegypt.news 2018-05-03
domain androidupdaters.com 2018-05-03
domain dlgmail.com 2018-05-03
domain rhubarb2.com 2018-05-03
domain rhubarb3.com 2018-05-03
domain showroommontorgueil.com 2018-05-03
URL http://showroommontorgueil.com/modules/homepageadvertise2/slides/alnaharegypt.news 2018-05-03
URL http://www.alhayatnews.com/ArabicRSS.apk 2018-05-03
URL http://www.alnaharegypt.com/t~467369 2018-05-03
hostname entekhab10.xp3.biz 2018-05-03
hostname www.alnaharegypt.com 2018-05-03
FileHash-MD5 232bd3dde6914db0a3dbfc21ed178887 2018-05-03
FileHash-MD5 519018ecfc50c0cf6cd0c88cc41b2a69 2018-05-03
FileHash-MD5 5ad36f6dd060e52771a8e4a1dd90c50c 2018-05-03
FileHash-MD5 5efddd7f0fc2125e78a2ca18b68464ec 2018-05-03
FileHash-MD5 699a7eedd244f402303bcffdee1f0ed1 2018-05-03
FileHash-MD5 6a388edbce88bb0331ae875ceeb2f319 2018-05-03
FileHash-MD5 7d7ad116e6a42d4e518378e2313e9392 2018-05-03
FileHash-MD5 a7d00c8629079f944b61c4dd5c77c8fb 2018-05-03
FileHash-MD5 ac4402e04de0949d7beed975db84e594 2018-05-03
FileHash-MD5 b44b91b14f176fbf93d998141931a4aa 2018-05-03
FileHash-MD5 b714b092d2f28fcf78ef8d02b46dbf9c 2018-05-03
FileHash-MD5 cb67abd070ae188390fc040cbe60e677 2018-05-03
FileHash-MD5 e2f62b5acf3795a62e9d54e1301c4e7b 2018-05-03
FileHash-MD5 ec5a6f0e743f4b858aba9de96a33fb0c 2018-05-03