Operation Daybreak
2016-06-17 • Kaspersky •
Kaspersky linked Operation Daybreak to ScarCruft based on shared infrastructure and targeting, describing targeted attacks against more than two dozen high-profile victims across Asia, Europe, the Middle East, and the United States. The campaign used a previously unknown Adobe Flash Player exploit, CVE-2016-4171, delivered through a hacked website that performed browser checks before redirecting victims to attacker-controlled infrastructure in Poland. The exploit chain used Base64 and RC4 in JavaScript, randomized encrypted second-stage payloads to frustrate hash-based detection, and three Flash objects before delivering a Korean-language decoy PDF about China and North Korean nuclear issues. A second-stage DLL abused Windows DDE behavior to execute a malicious VBS and install a CAB payload containing multiple DLLs, including cldbct.dll, which connected to webconncheck.myfw[.]us:8080/8xrss.php. The use of rare payloads, invalid Tencent-themed certificates, and multiple zero-day exploit operations shows a focused actor investing in high-value targeted access.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | f8a2d4ddf9dc2de750c8b4b7ee45ba3f | 2016-06-17 | 2016-06-17 |
| HASH | e51ce28c2e2d226365bc5315d3e5f83e | 2016-06-17 | 2016-06-17 |
| HASH | 8844a537e7f533192ca8e81886e70fbc | 2016-06-17 | 2016-06-17 |
| HASH | a6f14b547d9a7190a1f9f1c06f906063 | 2016-06-17 | 2016-06-17 |
| HASH | 3e5ac6bbf108feec97e1cc36560ab0b6 | 2016-06-17 | 2016-06-17 |
| HASH | 067681b79756156ba26c12bc36bf835c | 2016-06-17 | 2016-06-17 |
| URL | http://webconncheck.myfw.us:808… | 2016-06-17 | 2016-06-17 |
| DOMAIN | webconncheck.myfw.us | 2016-06-17 | 2016-06-17 |
| DOMAIN | reg.flnet.org | 2016-06-17 | 2016-06-17 |
| IPv4 | 212.7.217.10 | 2016-06-17 | 2016-06-17 |