PULSE NAME
Threat Group Targets the U.S. Automotive Industry
WHITE FIN7 AlienVault 2024-04-19 Modified: 2024-05-19
24
IOCs
MEDIUM VOLUME
BlackBerry analysts uncovered an attack on a major U.S. automotive manufacturer by the financially motivated threat group FIN7. The group deployed phishing emails with malicious links to deliver the well-known Anunak backdoor and leveraged living-off-the-land binaries, scripts, and libraries for initial access. Evidence suggests this was part of a broader FIN7 campaign targeting entities with large potential ransom payouts.
Indicators of Compromise (24)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 YARA domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 87aa5f3f514af2b9ef28db9f092f3249 2024-04-19
FileHash-MD5 bb23dde1e3ecef7d93a39e77e32ef96c 2024-04-19
FileHash-MD5 e5af2190a29646267fc14d395b7b9cb2 2024-04-19
FileHash-SHA1 20a2de20e662a5bc758808831ac35a6950c64474 2024-04-19
FileHash-SHA1 837c31430a7860b1d1f9ed6deae4c4bd37fc9d05 2024-04-19
FileHash-SHA1 d29b4588a3b20e371c56ae6e1d68e6021db056e5 2024-04-19
FileHash-SHA256 5ce7b63ef05d9f5cb8e309e6b195e3acb69cc72b899f4ae07c48b85bedfb286e 2024-04-19
FileHash-SHA256 7e927e1db12c404683c9c8b232e8cecb7334eed618992e965388b0b63508509f 2024-04-19
FileHash-SHA256 a186ea72c942232998429e0d8b1bc0e0876bdb535738eba0ed9f4be9aeaa81db 2024-04-19
FileHash-SHA256 bc4ef49e904d63415ee1c810c90019e12a590ff3b6293f4b69af65713a8da9fa 2024-04-19
FileHash-SHA256 c8d8d666b509afaa0ef349cc3de9a6eec6dde98cc8a0e50228f8793275fae401 2024-04-19
FileHash-SHA256 cdc0186ff3fcb67986f4f1f54e3a2991dd73f8bde20acf3a739e0fff7c6d94a7 2024-04-19
FileHash-SHA256 d4960f3c7cc891ff2bafd0a080451e42e0a23ba4db54ae2d7d355497a3b3d81a 2024-04-19
FileHash-SHA256 d63060e61c98074c58926a6239185e8128fd0fbc2a45ccf60f3c831bb18ffc93 2024-04-19
FileHash-SHA256 ff4c287c60ede1990442115bddd68201d25a735458f76786a938a0aa881d14ef 2024-04-19
YARA d57c640196c28ed658ab24c1c544bf10373b559b 2024-04-19
domain advanced-ip-sccanner.com 2024-04-19
domain ipscanneronline.com 2024-04-19
domain ipscannershop.com 2024-04-19
domain myipscanner.com 2024-04-19
domain myscannappo.com 2024-04-19
domain myscannappo.info 2024-04-19
domain myscannappo.online 2024-04-19
domain theipscanner.com 2024-04-19