PULSE NAME
Indicators from Wipro Breach
WHITE AlienVault 2019-04-18 Modified: 2019-04-18
52
IOCs
HIGH VOLUME
Wipro endpoints that were seeded with ScreenConnect, a legitimate remote access tool sold by Connectwise.com. Investigators believe the intruders were using the ScreenConnect software on the hacked Wipro systems to connect remotely to Wipro client systems, which were then used to leverage further access into Wipro customer networks. Additionally, investigators found at least one of the compromised endpoints was attacked with Mimikatz, an open source tool that can dump passwords stored in the temporary memory cache of a Microsoft Windows device.
Indicators of Compromise (2 / 52 total)
All URL hostname domain FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA1 1a1db93766e31994507511c9c70a1dd94465cf6d 2019-04-18
FileHash-SHA1 ac9fc01c1284bbe9ee4ddf424216a82b5d64a42c 2019-04-18