Виявлено нове шкідливе програмне забезпечення GreyEnergy.

Виявлено нове шкідливе програмне забезпечення GreyEnergy, яке використовується в атаках на об’єкти критичної інфраструктури в Центральній та Східній Європі з 2015 року. Функціонал GreyEnergy має багато схожого з відомим вірусом BlackEnergy.

Більш детальний опис вірусу можна подивитися тут:

https://eset.ua/download_files/marketing/Releases/GreyEnergy_final_ua.pdf

Нижче приведенні Індикатори компрометації вірусу GreyEnergy.

Радимо адміністраторам інформаційної безпеки перевірити факти підключення до зазначених командно-контрольних серверів зі своїх мереж.

Індикатори компрометації (ІОС):

Файли:

GreyEnergy: 

SHA-1:

177AF8F6E8D6F4952D13F88CDF1887CB7220A645

https://www.virustotal.com/#/file/f50ee030224bf617ba71d88422c25d7e489571bc1aba9e65dc122a45122c9321/detection

 

GreyEnergy mini:

SHA-1:

455D9EB9E11AA9AF9717E0260A70611FF84EF900

https://www.virustotal.com/#/file/dcade5e14c26c19e935b13d5170d74f99e75d3e4dba443db1dab8bea78745584/detection

51309371673ACD310F327A10476F707EB914E255

https://www.virustotal.com/#/file/d4e97a18be820a1a3af639c9bca21c5f85a3f49a37275b37fd012faeffcb7c4a/detection

CB11F36E271306354998BB8ABB6CA67C1D6A3E24

CC1CE3073937552459FB8ED0ADB5D56FA00BCD43

https://www.virustotal.com/#/file/b60c0c04badc8c5defab653c581d57505b3455817b57ee70af74311fa0b65e22/detection

30AF51F1F7CB9A9A46DF3ABFFB6AE3E39935D82C

https://www.virustotal.com/#/file/c2d06ad0211c24f36978fe34d25b0018ffc0f22b0c74fd1f915c608bf2cfad15/detection

 

GreyEnergy завантажувачі:

SHA-1:

04F75879132B0BFBA96CB7B210124BC3D396A7CE

69E2487EEE4637FE62E47891154D97DFDF8AAD57

716EFE17CD1563FFAD5E5E9A3E0CAC3CAB725F92

93EF4F47AC160721768A00E1A2121B45A9933A1D

94F445B65BF9A0AB134FAD2AAAD70779EAFD9288

https://www.virustotal.com/#/file/6c52a5850a57bea43a0a52ff0e2d2179653b97ae5406e884aee63e1cf340f58b/detection

A414F0A651F750EEA18F6D6C64627C4720548581

B3EF67F7881884A2E3493FE3D5F614DBBC51A79B

EBD5DC18C51B6FB0E9985A3A9E86FF66E22E813E

EC7E018BA36F07E6DADBE411E35B0B92E3AD8ABA

 

GreyEnergy DLL завантажувачі:

SHA-1:

0B5D24E6520B8D6547526FCBFC5768EC5AD19314

https://www.virustotal.com/#/file/0db5e5b68dc4b8089197de9c1e345056f45c006b7b487f7d8d57b49ae385bad0/detection

10D7687C44BECA4151BB07F78C6E605E8A552889

https://www.virustotal.com/#/file/6974b8acf6a8f7684673b01753c3a8248a1c491900cccf771db744ca0442f96a/detection

2A7EE7562A6A5BA7F192B3D6AED8627DFFDA4903

3CBDC146441E4858A1DE47DF0B4B795C4B0C2862

https://www.virustotal.com/#/file/4470e40f63443aa27187a36bbb0c2f4def42b589b61433630df842b6e365ae3d/detection

4E137F04A2C5FA64D5BF334EF78FE48CF7C7D626

62E00701F62971311EF8E57F33F6A3BA8ED28BF7

https://www.virustotal.com/#/file/b602ce32b7647705d68aedbaaf4485f1a68253f8f8132bd5d5f77284a6c2d8bb/detection

646060AC31FFDDFBD02967216BC71556A0C1AEDF

748FE84497423ED209357E923BE28083D42D69DE

https://www.virustotal.com/#/file/7ceab4ac6b3376bb6b6e11e8b6b2a3c2398e0c1f1faef138bf60aa1765bfd25a/detection

B75D0379C5081958AF83A542901553E1710979C7

BFC164E5A28A3D56B8493B1FC1CA4A12FA1AC6AC

https://www.virustotal.com/#/file/037723bdb9100d19bf15c5c21b649db5f3f61e421e76abe9db86105f1e75847b/detection

C1EB0150E2FCC099465C210B528BF508D2C64520

CBB7BA92CDF86FA260982399DAB8B416D905E89B

DF051C67EE633231E4C76EC247932C1A9868C14F

DFD8665D91C508FAF66E2BC2789B504670762EA2

https://www.virustotal.com/#/file/c6a54912f77a39c8f909a66a940350dcd8474c7a1d0e215a878349f1b038c58a/detection

E2436472B984F4505B4B938CEE6CAE26EF043FC7

E3E61DF9E0DD92C98223C750E13001CBB73A1E31

https://www.virustotal.com/#/file/165a7853ef51e96ce3f88bb33f928925b24ca5336e49845fc5fc556812092740/detection

E496318E6644E47B07D6CAB00B93D27D0FE6B415

EDA505896FFF9A29BD7EAE67FD626D7FFA36C7B2

F00BEFDF08678B642B69D128F2AFAE32A1564A90

F36ECAC8696AA0862AD3779CA464B2CD399D8099

https://www.virustotal.com/#/file/c21cf6018c2ee0a90b9d2c401aae8071c90b5a4bc9848a94d678d77209464f79/detection

 

GreyEnergy DLL в пам’яті:

SHA-1:

0BCECB797306D30D0BA5EAEA123B5BF69981EFF4

11159DB91B870E6728F1A7835B5D8BE9424914B9

6ABD4B82A133C4610E5779C876FCB7E066898380

848F0DBF50B582A87399428D093E5903FFAEEDCD

99A81305EF6E45F470EEE677C6491045E3B4D33A

A01036A8EFE5349920A656A422E959A2B9B76F02

C449294E57088E2E2B9766493E48C98B8C9180F8

C7FC689FE76361EF4FDC1F2A5BAB71C0E2E09746

D24FC871A721B2FD01F143EB6375784144365A84

DA617BC6DCD2083D93A9A83D4F15E3713D365960

E4FCAA1B6A27AA183C6A3A46B84B5EAE9772920B

 

Moonraker Petya:

SHA-1: 1AA1EF7470A8882CA81BB9894630433E5CCE4373

 

Шкідливі скрипти (PHP, ASP):

SHA-1:

10F4D12CF8EE15747BFB618F3731D81A905AAB04

https://www.virustotal.com/#/file/8ad201eabb8eccce639c402c95be73daf5ade3668a069aef3ef704f03b98b57e/detection

13C5B14E19C9095ABA3F1DA56B1A76793C7144B9

1BA30B645E974DE86F24054B238FE77A331D0D2C

438C8F9607E06E7AC1261F99F8311B004C23DEC3

4D1C282F9942EC87C5B4D9363187AFDC120F4DC7

4E0C5CCFFB7E2D17C26F82DB5564E47F141300B3

5377ADB779DE325A74838C0815EEA958B4822F82

58A69A8D1B94E751050DECF87F2572E09794F0F8

5DD34FB1C8E224C17DCE04E02A4409E9393BCE58

639BCE78F961C4B9ECD9FE1A8537733388B99857

7127B880C8E31FBEB1D376EB55A6F878BC77B21A

71BA8FE0C9C32A9B987E2BB827FE54DAE905D65E

78A7FBDD6ADF073EA6D835BE69084E071B4DA395

81332D2F96A354B1B8E11984918C43FB9B5CB9DB

https://www.virustotal.com/#/file/9df76b532c90d19a92138dd6b395b580330fcd87bab53240b436640e80895ed1/detection

8CC008B3189F8CE9A96C2C41F864D019319EB2EE

940DE46CD8C50C28A9C0EFC65AEE7D567117941B

A415E12591DD47289E235E7022A6896CB2BFDE96

D3AE97A99D826F49AD03ADDC9F0D5200BE46AB5E

E69F5FF2FCD18698BB584B6BC15136D61EB4F594

E83A090D325E4A9E30B88A181396D62FEF5D54D5

ECF21EFC09E4E2ACFEEB71FB78CB1F518E1F5724

 

Сканери портів:

SHA-1:

B371A5D6465DC85C093A5FB84D7CDDEB1EFFCC56

B40BDE0341F52481AE1820022FA8376E53A20040

 

Mimikatz:

SHA-1:

89D7E0DA80C9973D945E6F62E843606B2E264F7E

8B295AB4789105F9910E4F3AF1B60CBBA8AD6FC0

AD6F835F239DA6683CAA54FCCBCFDD0DC40196BE

 

WinExe:

SHA-1:

0666B109B0128599D535904C1F7DDC02C1F704F2

https://www.virustotal.com/#/file/1d19bc1785fad34633bb808960e22084ae615a1c66e7d0e93bb314460600b333/detection

2695FCFE83AB536D89147184589CCB44FC4A60F3

https://www.virustotal.com/#/file/7ffb56ab3f450d0e53215be644a650c73856900eea1e551494618588b6ae7896/detection

3608EC28A9AD7AF14325F764FB2F356731F1CA7A

https://www.virustotal.com/#/file/513d3fd092d2c22071e9a4a24dca8d2b7f9d146f3075e736f374d9e315ec018e/detection

37C837FB170164CBC88BEAE720DF128B786A71E0

https://www.virustotal.com/#/file/993d38b57284ebead293296c4aaf4ecffe4f8ac63ca115ae9463368b407cef97/detection

594B809343FEB1D14F80F0902D764A9BF0A8C33C

https://www.virustotal.com/#/file/095c7fa99dbc1ed7a3422a52cc61044ae4a25f7f5e998cc53de623f49da5da43/detection

7C1F7CE5E57CBDE9AC7755A7B755171E38ABD70D

https://www.virustotal.com/#/file/72a7e5cec3e07cef6481f12eb93db98cda8332df3fc736c385d90b023fca3eed/detection

90122C0DC5890F9A7B5774C6966EA694A590BD38

https://www.virustotal.com/#/file/6a0f5d4b6ad2320234d150b9ac187a7b3b6ce8608e8ce6e8f87cbbc8d5c8eb56/detection

C59F66808EA8F07CBDE74116DDE60DAB4F9F3122

https://www.virustotal.com/#/file/854e63d079bf78f779c8254b99ef0f54de2b3c931476d6657e28f626b8c058a6/detection

CEB96B364D6A8B65EA8FA43EB0A735176E409EB0

FCEAA83E7BD9BCAB5EFBA9D1811480B8CB0B8A3E

https://www.virustotal.com/#/file/02adab3ae1d03b5af93b9d84dc0237867eef160d23704fbf8bcb58a3ffc8dbcd/detection

 

Командно-контрольні сервери (C2):

GreyEnergy mini С2:

https://82.118.236[.]23:8443/27c00829d57988279f3ec61a05dee75a

http://82.118.236[.]23:8080/27c00829d57988279f3ec61a05dee75a

https://88.198.13[.]116:8443/xmlservice

http://88.198.13[.]116:8080/xmlservice https://217.12.204[.]100/news/

http://217.12.204[.]100/news/

http://pbank.co[.]ua/favicon.ico (IP: 185.128.40.90)

 

GreyEnergy С2:

109.200.202.7

193.105.134.68

163.172.7.195

163.172.7.196

5.149.248.77

31.148.220.112

62.210.77.169

85.25.211.10 32

138.201.198.164

124.217.254.55

46.249.49.231

37.59.14.94

213.239.202.149

88.198.13.116

217.12.202.111

176.31.116.140

185.217.0.121

178.150.0.200

176.121.10.137

178.255.40.194

193.105.134.56

94.130.88.50

185.216.33.126

 

Корисні посилання:

https://eset.ua/download_files/marketing/Releases/GreyEnergy_final_ua.pdf

0

Автор публікації

Офлайн 2 тижні

Ihor Romanets

0
Коментарі: 0Публікації: 197Реєстрація: 02-10-2017