PULSE NAME
Indicators from Wipro Breach
WHITE AlienVault 2019-04-18 Modified: 2019-04-18
52
IOCs
HIGH VOLUME
Wipro endpoints that were seeded with ScreenConnect, a legitimate remote access tool sold by Connectwise.com. Investigators believe the intruders were using the ScreenConnect software on the hacked Wipro systems to connect remotely to Wipro client systems, which were then used to leverage further access into Wipro customer networks. Additionally, investigators found at least one of the compromised endpoints was attacked with Mimikatz, an open source tool that can dump passwords stored in the temporary memory cache of a Microsoft Windows device.
Indicators of Compromise (2 / 52 total)
All URL hostname domain FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 dd5986339aaf23f2baf8c245923a0f69 2019-04-18
FileHash-MD5 e2e88d6ea5d5d2a4c7b8039988644043 2019-04-18