PULSE NAME
FIN7.5 the infamous cybercrime rig FIN7 continues its activities
WHITE AlienVault 2019-05-08 Modified: 2019-05-23
65
IOCs
HIGH VOLUME
On August 1, 2018, the US Department of Justice announced that it had arrested several individuals suspected of having ties to the FIN7 cybercrime rig. FIN7 operations are linked to numerous intrusion attempts having targeted hundreds of companies since at least as early as 2015. Interestingly, this threat actor created fake companies in order to hire remote pentesters, developers and interpreters to participate in their malicious business. The main goal behind its malicious activities was to steal financial assets from companies, such as debit cards, or get access to financial data or computers of finance department employees in order to conduct wire transfers to offshore accounts.
Indicators of Compromise (65)
All FileHash-SHA256 domain hostname FileHash-MD5
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 3400127b9943eee765ab379f402268df4f8306670b9d5ce51c89708f5b930cc0 2019-05-08
FileHash-SHA256 90a9d7fcc772e9e54ee90053dcae3104f01d4ea7b483395d8aacef2af1e4f270 2019-05-08
FileHash-SHA256 9a0a7878648fca27b74e556b72386e08d90dd055a5d041eee7ddc719faa3fe64 2019-05-08
FileHash-SHA256 a622a5700d17c8652df5c99bd8d3dc7f4e18174345491c3ee048380d63528548 2019-05-08
FileHash-SHA256 0feca8aafa1881e2499d9020d6c6711093317deb0fad0915c68bc8b42e309e12 2019-05-08
FileHash-SHA256 256cdaf7b661bfdb81b648792f7680af5f4f45799eafc53087c4e66036318ae2 2019-05-08
FileHash-SHA256 5440dca28197de46630b1faa2cfc4b0e336f14190a9775299ee66fd9cc9cef59 2019-05-08
FileHash-SHA256 b5ba024e3ac0e96443b3a115f648e0e91291c3f154f9d6a90430ccea1a9595ac 2019-05-08
FileHash-SHA256 c6ee797d90356c5605c2cc1894981de347aad0962874752a96abd5218e4433ba 2019-05-08
FileHash-SHA256 eb51c45bd7eb203ac8fd7d925994636df4d28aeae8f6c59863a5fab4b11bca5f 2019-05-08
FileHash-SHA256 eba90ec314d793fcffba299cc249ec685e0340904e8f7f4479e56e89d2178832 2019-05-08
domain cdnj-cloudflare.com 2019-05-08
domain facebook77-cdn.com 2019-05-08
domain googl-analytic.com 2019-05-08
domain somtelnetworks.com 2019-05-08
domain infosys-cdn.com 2019-05-08
domain k-24tv.com 2019-05-08
domain servicebing-cdn.com 2019-05-08
domain businessdailyafrica.net 2019-05-08
domain cdn-googleapi.com 2019-05-08
domain digicert-cdn.com 2019-05-08
domain infotrak-research.com 2019-05-08
domain akamaiservice-cdn.com 2019-05-08
domain msdn-update.com 2019-05-08
domain hpservice-cdn.com 2019-05-08
domain gmail-cdn3.com 2019-05-08
domain appleservice-cdn.com 2019-05-08
domain yahooservices-cdn.com 2019-05-08
domain cisco-cdn.com 2019-05-08
domain geotrusts.com 2019-05-08
domain globaltech-cdn.com 2019-05-08
domain logitech-cdn.com 2019-05-08
domain digi-cert.org 2019-05-08
domain nairobiwired.com 2019-05-08
domain cdn-skype.com 2019-05-08
domain booking-cdn.com 2019-05-08
domain itaxkenya.com 2019-05-08
domain instagram-cdn.com 2019-05-08
domain exchange-cdn.com 2019-05-08
domain bing-cdn.com 2019-05-08
domain windowsupdatemicrosoft.com 2019-05-08
domain nlscdn.com 2019-05-08
domain sport-pesa.org 2019-05-08
domain live-cdn2.com 2019-05-08
domain pci-cdn.com 2019-05-08
domain msdn-cdn.com 2019-05-08
domain secureclientupdate.com 2019-05-08
domain mse-cdn.com 2019-05-08
domain cloudflare-cdn-r5.com 2019-05-08
domain testing-cdn.com 2019-05-08
domain google-services-s5.com 2019-05-08
domain vmware-cdn.com 2019-05-08
domain tw32-cdn.com 2019-05-08
domain cdn-yahooapi.com 2019-05-08
domain riscomponents.pw 2019-05-08
domain realtek-cdn.com 2019-05-08
domain digicertweb.com 2019-05-08
hostname doddyfire.dyndns.org 2019-05-08
hostname warmaha.warzonedns.com 2019-05-08
hostname server.mtcc.me 2019-05-08
hostname tain.warzonedns.com 2019-05-08
hostname toekie.ddns.net 2019-05-08
hostname noreply377.ddns.net 2019-05-08
domain bindupdate.com 2019-05-23
FileHash-MD5 dcfa396e3f500d67afa7157adb639819 2019-05-23