PULSE NAME
OpBlueRaven: Unveiling Fin7/Carbanak - Part II: BadUSB Attacks
WHITE FIN7 AlienVault 2020-09-02 Modified: 2020-10-02
16
IOCs
MEDIUM VOLUME
This article aims to provide its readers with the details about PRODAFT & INVICTUS Threat Intelligence (PTI) team's latest operation on different threat actors; who have been detected to be working in cooperation with the notorious FIN7 APT group. We appreciate all your support after the first part of this series. Before disclosing the relationship between Fin7 and REvil groups, we are trying to reach the ransomware victims. Until reaching all necessary parties, we will continue to publish articles about FIN7 attackers' tools.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Carbanak - S0030 Bella RAT BadUSB Tirion Loader
Indicators of Compromise (16)
All domain
TYPEINDICATORDESCRIPTIONCREATED
domain softowii.com 2020-09-02
domain hawrickday.com 2020-09-02
domain vmware-cdn.com 2020-09-02
domain uoplotr.com 2020-09-02
domain digitalsoundmaker99.com 2020-09-02
domain moviedvdpower.com 2020-09-02
domain colorpickerdesk.com 2020-09-02
domain fgfotr.com 2020-09-02
domain expressdesign9.com 2020-09-02
domain untypicaldesign9.com 2020-09-02
domain hong-security.com 2020-09-02
domain tableofcolorize.com 2020-09-02
domain mozillaupdate.com 2020-09-02
domain milkmovemoney.com 2020-09-02
domain landscapesboxdesign9.com 2020-09-02
domain nattplot.com 2020-09-02