FreeMilk: A Highly Targeted Spear Phishing Campaign

2017-10-05 Paloalto Networks

https://researchcenter.paloaltonetworks.com/2017/10/unit42-freemilk-highly-targeted-spear-phishing-campaign/

Thumbnail for FreeMilk: A Highly Targeted Spear Phishing Campaign

Unit 42 documented FreeMilk, a limited spear-phishing campaign that used hijacked email conversations and tailored decoy documents to exploit CVE-2017-0199. Successful exploitation downloaded PoohMilk as a first-stage loader and Freenki as a second-stage downloader from compromised infrastructure such as old.jrchina[.]com. Freenki collected host data, MAC addresses, system details, and screenshots, then requested a secondary C2 and executed a decoded payload with the hard-coded argument “abai.” The campaign targeted organizations and individuals including a Middle East bank, European intellectual property firms, an international sporting organization, and people with indirect ties to a North East Asian country, while related activity used Hancom-themed phishing and a watering-hole attack against a defector-operated media site.

Indicators of Compromise

Type Value First Seen Last Seen
HASH ef40f7ddff404d1193e025081780e32… 2017-10-05 2020-03-09
HASH 99c1b4887d96cb94f32b280c1039b3a… 2017-10-05 2018-10-03
HASH 7f35521cdbaa4e86143656ff9c52cef… 2017-10-05 2018-10-03
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
URL http://old.jrchina.com/btob_asi… 2017-10-05 2018-03-23
DOMAIN old.jrchina.com 2017-10-05 2018-03-23
DOMAIN foodforu.heliohost.org 2017-10-05 2018-03-23
HASH 35273d6c25665a19ac14d469e143622… 2017-10-05 2018-01-16
HASH 1893af524edea4541c317df288adbf1… 2017-10-05 2018-01-16
DOMAIN discgolfglow.com 2017-04-03 2018-01-16
HASH 1163da8c37ad9ba98d59b921ba8cf8e… 2017-10-05 2017-10-05
HASH 0f82ea2f92c7e906ee9ffbbd8212be6… 2017-10-05 2017-10-05
HASH 34478d6692f8c28332751b31fd695b7… 2017-10-05 2017-10-05
HASH 201b876bcb97f6c8972cc677bdf1e3e… 2017-10-05 2017-10-05
HASH 40572e1fc37f4376fdb2a33a6c37663… 2017-10-05 2017-10-05
HASH 64ef80e7639c8c5dddf239883617e67… 2017-10-05 2017-10-05
HASH a50543919c52ccaea40155ce35aa791… 2017-10-05 2017-10-05
HASH ba5905c2fe46bd6734973139e759ba4… 2017-10-05 2017-10-05
HASH 3d3f31627c09d1e68647b2a66491efb3 2017-10-05 2017-10-05
URL http://www.ethanpublishing.com/… 2017-10-05 2017-10-05

Related Reports

« Back