PULSE NAME
Farseer: Previously Unknown Malware Family bolsters the Chinese armoury
WHITE Farseer AlienVault 2019-02-26 Modified: 2019-02-26
50
IOCs
MEDIUM VOLUME
Last year, Unit 42 wrote about a newly discovered espionage Android malware family, HenBox, which had countless features for spying on their victims – primarily the Uyghur population – including interaction with Xiaomi IoT devices, and the Chinese consumer electronics manufacturer’s smart phones. Through investigations into infrastructure used by HenBox malware, Unit 42 has discovered another malware family built for the more frequently-targeted Microsoft Windows operating system they named ‘Farseer’. As with HenBox, Farseer also has infrastructure ties to other malware, such as Poison Ivy, Zupdax, and PKPLUG. Unit 42 named this malware Farseer malware due to a string found in the PDB path embedded within the executable files.
Indicators of Compromise (50)
All domain FileHash-SHA256 hostname
TYPEINDICATORDESCRIPTIONCREATED
domain adminloader.com 2019-02-26
domain adminsysteminfo.com 2019-02-26
domain csip6.biz 2019-02-26
domain honor2020.ga 2019-02-26
domain linkdatax.com 2019-02-26
domain md5c.net 2019-02-26
FileHash-SHA256 0306585900f1b1bddc76149352f90962c365959e44a486ba3547c80d12d56e41 2019-02-26
FileHash-SHA256 06c091bb0630539dec0d26eb6bfbf9108152e4c5af27ff649ce84238cd88f81e 2019-02-26
FileHash-SHA256 0c7e35ca1312204063319a3455ec14bc4b701de205503e63de584f28d99f0291 2019-02-26
FileHash-SHA256 10bd4507eb12bebc17e216e16950bf77e56c2aad01be7033bf0d5c235f2ad6e5 2019-02-26
FileHash-SHA256 1e46c88420c657c685786bee88f606d494f3d50bcbc616b0f64d2886edd572f2 2019-02-26
FileHash-SHA256 1e62b7dcb503f47a6330c4dcfc49ea9d921b7d2f8c508769d27df04e61b9471d 2019-02-26
FileHash-SHA256 2085fca368af15a1bd54f7809dfee7cdd4d73df7af88fa53fe5341f0523ca7ea 2019-02-26
FileHash-SHA256 24b52403ff652416c84afed7e12ece11dc59b07f7dba5f007e117a4cfc67c1ab 2019-02-26
FileHash-SHA256 271e29fe8e23901184377ab5d0d12b40d485f8c404aef0bdcc4a4148ccbb1a1a 2019-02-26
FileHash-SHA256 2e84de3408283423ed58764139eed4dd7e343115b943b58a46e2dc25ca2ef3c8 2019-02-26
FileHash-SHA256 3d47b99d34e169a8283062937c373264829cf6fe1c7fa0bacee135c392ca24bb 2019-02-26
FileHash-SHA256 4552f70d94743206489da85da2e9eb9f1eb3ad017a42edb7a60edb69e5c15a32 2019-02-26
FileHash-SHA256 4ab41a025624f342deb85d798c6d6264a9fb88b8b3d9037cf8d5248a9f730339 2019-02-26
FileHash-SHA256 542b2ca4fe2d7d13fa317c58f46942cdf6eb33771bb898d7be773f8ccb50b13c 2019-02-26
FileHash-SHA256 5a461104a2b6e313d3d0ee08c26e90db965139b1bff4a785ec297047d570340c 2019-02-26
FileHash-SHA256 6e367e10f9c0fb818394e9517ab13c1da00b2545602c23bf6ab83e93063076b8 2019-02-26
FileHash-SHA256 75ca95ae317b1e848d54bbb01798d5b61ebcaf4328b3940b5d5f644a01f1943a 2019-02-26
FileHash-SHA256 7f091da89c4412d71ae583481f91a471751a3c0e8db0037cf31ffd00f4245b5b 2019-02-26
FileHash-SHA256 7d5386253d403b74e86658699f9a6d683b7ac3065c4e2cdae192b32b9ac54edb 2019-02-26
FileHash-SHA256 8890a06d3233ecf661c040ca5c03393c3afd620ccce49fbe08477bbf6b7d9b04 2019-02-26
FileHash-SHA256 8ff03c13d0a78003840b7a612e372242c7def123b4fbf5ea1780f2d70eb806a1 2019-02-26
FileHash-SHA256 97c04702aaa0a9018cc46ea874e7e3644146ba4d6b3b30c78a6a6430172b13c7 2019-02-26
FileHash-SHA256 9e08efc73dc9145358898d2735c5f31d45a2571663c7f4963abd217ae979c7ca 2019-02-26
FileHash-SHA256 a999489d95e5a94f75de4695c9579ffc88bae02048838e3523f089d970a35abb 2019-02-26
FileHash-SHA256 b782b4c5f8fe2ee318e50ddf985c9132bff6d48b01ea36d6825967bf89e5d0c2 2019-02-26
FileHash-SHA256 b82caa5087c6fd8ac79019185c6f8884f5dd9d0266bb7ad635277f3c7ca5c615 2019-02-26
FileHash-SHA256 c1e80458ae652dbf40981dfe33bf109d1b4c85d0affbd16c8d1df6be9e233e05 2019-02-26
FileHash-SHA256 c8b2232360d5d6f56cd6b1076e5e21f0d501f5cb725e0a9b32a0ab661b4c38dd 2019-02-26
FileHash-SHA256 d11d871b07520f43437183fa44bd118c01a3c4c86cffe0cc7343ae9038565cf1 2019-02-26
FileHash-SHA256 d44f388842d93807c0b56399c8b7eae5b3dd76871e4908ef3d7d8a559f014fe6 2019-02-26
FileHash-SHA256 da02edf3f33d9801d066c1f93feef33cdedc1bc7b5605498404e8cad8015729f 2019-02-26
FileHash-SHA256 f169b8d93ea27ab6ae24c26eaecc039a838bd7e74aef18c1e7a953283c418c30 2019-02-26
FileHash-SHA256 f46f162ef279cc6e9c022cffe3a6685d001524e312e7a5f23bd24d76fed1fa99 2019-02-26
FileHash-SHA256 fd8bb808c7b16cffcb83d7e86d642b5cb6e913e22df69c8dd03ce4e7498f5fdc 2019-02-26
hostname app.newfacebk.com 2019-02-26
hostname dns.cdncool.com 2019-02-26
hostname md.sony36.com 2019-02-26
hostname netvovo.windowsnetwork.org 2019-02-26
hostname up.outhmail.com 2019-02-26
hostname update.newfacebk.com 2019-02-26
hostname update.tcpdo.net 2019-02-26
hostname w3.changeip.org 2019-02-26
hostname www3.mefound.com 2019-02-26
hostname www5.zyns.com 2019-02-26