PULSE NAME
Threat Actor TA505 Targets Financial Enterprises Using LOLBINS and a new backdoor malware
WHITE TA505 AlienVault 2019-04-25 Modified: 2019-04-25
9
IOCs
LOW VOLUME
In this research, Cybereason introduce a meticulously planned, malicious operation against a financial institution in April of 2019. This advanced operation combines a targeted phishing attack with advanced tools that gather intel on the environment. The operation chooses whether or not to create persistence and installs a sophisticated backdoor called ServHelper used to take over the network.
Indicators of Compromise (2 / 9 total)
All URL domain FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
URL http://aasdkkkdsa3442.icu/ 2019-04-25
URL http://aasdkkkdsa3442.icu/jquery/jquery.php 2019-04-25