PULSE NAME
Arsenal honed against Russia's government organizations
WHITE Awaken Likho AlienVault 2024-10-11 Modified: 2024-11-10
48
IOCs
MEDIUM VOLUME
Core Werewolf, a threat actor targeting Russia's defense industry and critical infrastructure since 2021, has evolved its tactics. The group now employs a new loader written in AutoIt and has expanded its delivery methods to include Telegram alongside email. Their campaign involves RAR archives containing SFX executables, which deploy obfuscated AutoIt scripts, legitimate AutoIt interpreters, and decoy PDF documents. The loader gathers system information, exfiltrates data to a C2 server, and potentially downloads additional malicious payloads. The attackers use deceptive file names matching the content of decoy documents to increase credibility. This campaign demonstrates the ongoing sophistication and adaptability of threat actors targeting Russian government organizations.
Indicators of Compromise (48)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 URL domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 13dbc816bca4f7668452fd8d28bb95e1 2024-10-11
FileHash-MD5 20e4539a0c14c63afa24744b3767f103 2024-10-11
FileHash-MD5 22a0ffa0c20131cd10fe074dbbcdd262 2024-10-11
FileHash-MD5 2c77773840821a49d71ac7c9e31258f9 2024-10-11
FileHash-MD5 36f96f199cf97ee8cbdd0271bd6598ca 2024-10-11
FileHash-MD5 6834ec008b5dc8980a1c7a3e13a1a8ea 2024-10-11
FileHash-MD5 6a495d68c106da8e9e4ec4bab72969c7 2024-10-11
FileHash-MD5 770c3ea782ea6d4430b64e24ebce8ca8 2024-10-11
FileHash-MD5 88849c55911c4b1866fb7099f9c54407 2024-10-11
FileHash-MD5 9a454c6e336ac65df9a0330db086565f 2024-10-11
FileHash-MD5 9c0933a8a4fcb108dae9ee4cf9f7645b 2024-10-11
FileHash-MD5 a3bd5a90c900bd78b015804c2e2159c6 2024-10-11
FileHash-MD5 e058d942a6dadfb09bd652ce1e1b2518 2024-10-11
FileHash-MD5 f3b95a48f3415e8909b979f9219a68b4 2024-10-11
FileHash-SHA1 01bea2e4ff7bba835d88714ec4fde8d97a250639 2024-10-11
FileHash-SHA1 21b551deb21e6218741e424086b1eaad0064fe65 2024-10-11
FileHash-SHA1 2ba32d676b04da49276527d4b428c36b2cb61b81 2024-10-11
FileHash-SHA1 2c2660577d4f853935a64c47cf8967a74e32d0f8 2024-10-11
FileHash-SHA1 2f835234ff7b497944220a72315c1b80d2474fa5 2024-10-11
FileHash-SHA1 2fcc26ba22a592f7cd1dc81c212e79795fc05f76 2024-10-11
FileHash-SHA1 35da880d75ab18f132dfed65adf545e079a99f55 2024-10-11
FileHash-SHA1 4f47703cdc419e2942ff2697b7ee40a4d703956f 2024-10-11
FileHash-SHA1 5eba332d8372d94d17e87b6c8234b2cad052bb17 2024-10-11
FileHash-SHA1 7d53b53514fd54af5e547c02eb8163dbd25f79ca 2024-10-11
FileHash-SHA1 80ef6745cd0412ab587def958f6425de2b144935 2024-10-11
FileHash-SHA1 871a675d43758907d02d5b7e57d8a96f70dd3b27 2024-10-11
FileHash-SHA1 a2146ccfffbabed1501e8ad00fada778e3817f94 2024-10-11
FileHash-SHA1 bcef3e23516e7df558b07da2edee8c47398a2472 2024-10-11
FileHash-SHA256 00ec82306c9df4aee9dda42933ed55afa9e53ed74c2018bc0ce43d87edad2f98 2024-10-11
FileHash-SHA256 114de7d5e7dd6088f68705d519fc35530433506965ec5288e9dfb005bfec73c8 2024-10-11
FileHash-SHA256 19ff0ce570aabefcab0eed08afdaffd16c5516d91962e099498ecaf97f394766 2024-10-11
FileHash-SHA256 2b62b9481c0bcdf46a24a792f44e152ea5b7c5143cb06af9d82ff8c2c8433551 2024-10-11
FileHash-SHA256 3cfc1ecd00d52349c0b1ac0692774b31a97342330ef664b546fa3b8aa1d3a6c2 2024-10-11
FileHash-SHA256 6a3584f8e6b5f8e2fb5826aa0f042bf30b06e7467f022499a71273e15daaa216 2024-10-11
FileHash-SHA256 703835c57b8985141ef3ef652e2593935a47bd9779d08963c5eb973b8b82d08a 2024-10-11
FileHash-SHA256 731b4673f28da5d8b48f016a478be4e1ffea247d5b44a6612c506110b8fdd97c 2024-10-11
FileHash-SHA256 75cd7ef3e87d59f32939832e3b5eeb586d0fc1467721a30b64132bc5f833697f 2024-10-11
FileHash-SHA256 a049cc364151ddfb3b87c11050a9b027ec4a1687ae4415b8d07afa4bc7aeaced 2024-10-11
FileHash-SHA256 a8ea0f64e7e08d59b45068c1ff4eda4d7fd9d92148cd3d4c664da9c18aaf1f32 2024-10-11
FileHash-SHA256 b09807247282baaddb32ffe114b046325dd648a4c298f3b5c9addaa635b0520c 2024-10-11
FileHash-SHA256 d42942acee6154609c1c5f61bb0fb863c4598dd82e6d28af58c9dfbee71c4521 2024-10-11
FileHash-SHA256 eecfa15d69a6322fac39e945d68664a037e48a60644a76acd8b49490e6c93c06 2024-10-11
URL http://1tutor.ru/DESKTOP-ET51AJO_Bruno/9733698215789059.au3 2024-10-11
URL http://1tutor.ru/DESKTOP-ET51AJO_Bruno/9733698215789059.txt 2024-10-11
domain 1tutor.ru 2024-10-11
domain cntula.ru 2024-10-11
domain conversesuisse.net 2024-10-11
domain dsksb.ru 2024-10-11