KidM to CybersecurityEnglish · 8 months ago'PhantomBlu' Cyberattackers Backdoor Microsoft Office Users via OLEwww.darkreading.comexternal-linkmessage-square2fedilinkarrow-up112arrow-down10
arrow-up112arrow-down1external-link'PhantomBlu' Cyberattackers Backdoor Microsoft Office Users via OLEwww.darkreading.comKidM to CybersecurityEnglish · 8 months agomessage-square2fedilink
minus-squareKidOPMlinkfedilinkEnglisharrow-up2·edit-28 months agoIoCs: IOCs Hashes (SHA-256) Email – 16e6dfd67d5049ffedb8c55bee6ad80fc0283757bc60d4f12c56675b1da5bf61 Docx – 1abf56bc5fbf84805ed0fbf28e7f986c7bb2833972793252f3e358b13b638bb1 Injected ZIP – 95898c9abce738ca53e44290f4d4aa4e8486398de3163e3482f510633d50ee6c LNK file – d07323226c7be1a38ffd8716bc7d77bdb226b81fd6ccd493c55b2711014c0188 Final ZIP – 94499196a62341b4f1cd10f3e1ba6003d0c4db66c1eb0d1b7e66b7eb4f2b67b6 26/64 Client32.exe – 89f0c8f170fe9ea28b1056517160e92e2d7d4e8aa81f4ed696932230413a6ce1 26/73 URLs and Hostnames yourownmart[.]com/solar[.]txt firstieragency[.]com/depbrndksokkkdkxoqnazneifidmyyjdpji[.]txt yourownmart[.]com firstieragency[.]com parabmasale[.]com tapouttv28[.]com IP Addresses 192[.]236[.]192[.]48 173[.]252[.]167[.]50 199[.]188[.]205[.]15 46[.]105[.]141[.]54 Others Message ID contains: “sendinblue[.]com” Return Path contains: “sender-sib[.]com” Source
IoCs:
IOCs Hashes (SHA-256) Email – 16e6dfd67d5049ffedb8c55bee6ad80fc0283757bc60d4f12c56675b1da5bf61
Docx – 1abf56bc5fbf84805ed0fbf28e7f986c7bb2833972793252f3e358b13b638bb1
Injected ZIP – 95898c9abce738ca53e44290f4d4aa4e8486398de3163e3482f510633d50ee6c
LNK file – d07323226c7be1a38ffd8716bc7d77bdb226b81fd6ccd493c55b2711014c0188
Final ZIP – 94499196a62341b4f1cd10f3e1ba6003d0c4db66c1eb0d1b7e66b7eb4f2b67b6 26/64
Client32.exe – 89f0c8f170fe9ea28b1056517160e92e2d7d4e8aa81f4ed696932230413a6ce1 26/73
URLs and Hostnames yourownmart[.]com/solar[.]txt
firstieragency[.]com/depbrndksokkkdkxoqnazneifidmyyjdpji[.]txt
yourownmart[.]com
firstieragency[.]com
parabmasale[.]com
tapouttv28[.]com
IP Addresses 192[.]236[.]192[.]48
173[.]252[.]167[.]50
199[.]188[.]205[.]15
46[.]105[.]141[.]54
Others Message ID contains: “sendinblue[.]com”
Return Path contains: “sender-sib[.]com”
Source