PULSE NAME
Continued activity by APT28
WHITE Sofacy AlienVault 2019-05-30 Modified: 2019-10-02
30
IOCs
MEDIUM VOLUME
Upon execution, nbmssl.dll (MD5: d51d485f98810ab1278df4e41b692761) decrypts strings and URLs utilizing two observed encryption keys. One for string decryption and another for URL decryption. Strings are decrypted and then concatenated to build URLs which may be backup C2 nodes. Additionally, three URLs are decrypted to test for network connectivity. First, google.com is decrypted followed by yahoo.com. A DNS request is then generated for google.com, if that fails it attempts to reach yahoo.com. If an attempt succeeds, the file calls out to what appears to be a C2 node named maylaytravelgroup.com with multiple GET requests.
Indicators of Compromise (1 / 30 total)
All domain FileHash-SHA256 FileHash-MD5 FileHash-SHA1
TYPEINDICATORDESCRIPTIONCREATED
FileHash-SHA256 b40909ac0b70b7bd82465dfc7761a6b4e0df55b894dd42290e3f72cb4280fa44 2019-05-30