Several Polish banks hacked information stolen by unknown attackers
2017-02-03 • Badcyber •
https://badcyber.com/several-polish-banks-hacked-information-stolen-by-unknown-attackers/
BadCyber reported a major compromise affecting multiple Polish commercial banks after unusual network traffic and unauthorized files were found on workstations and servers. The suspected infection source was the Polish Financial Supervision Authority website, where a modified JavaScript file loaded an external iframe from sap.misapor[.]ch that could deliver payloads to selected visitors. After exploitation, the malware connected to foreign servers and could support reconnaissance, lateral movement, data exfiltration, and remote-access functionality. The malware was described as previously undocumented, packed and obfuscated, multi-stage, encrypted, and not recognized by available antivirus tools during the initial analysis. BadCyber published hashes and malicious URLs tied to the KNF compromise, including sap.misapor[.]ch and eye-watch[.]in paths, while noting that attacker motivation and the contents of encrypted outbound transfers were still unknown.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | d4616f9706403a0d5a2f9a8726230a4… | 2017-02-03 | 2020-03-09 |
| DOMAIN | knf.gov | 2017-02-03 | 2017-05-30 |
| HASH | 85d316590edfb4212049c4490db08c4b | 2017-02-03 | 2017-04-03 |
| HASH | 4f0d7a33d23d53c0eb8b34d102cdd66… | 2017-02-03 | 2017-04-03 |
| HASH | c1364bbf63b3617b25b58209e4529d8c | 2017-02-03 | 2017-04-03 |
| HASH | bedceafa2109139c793cb158cec9fa4… | 2017-02-03 | 2017-04-03 |
| HASH | 1bfbc0c9e0d9ceb5c3f4f6ced6bcfeae | 2017-02-03 | 2017-04-03 |
| URL | http://www.knf.gov.pl/DefaultDe… | 2017-02-03 | 2017-04-03 |
| URL | https://sap.misapor.ch/vishop/v… | 2017-02-03 | 2017-04-03 |
| DOMAIN | sap.misapor.ch | 2017-02-03 | 2017-04-03 |
| URL | http://sap.misapor.ch/vishop/vi… | 2017-02-03 | 2017-02-12 |
| URL | https://www.eye-watch.in/design… | 2017-02-03 | 2017-02-12 |
| IPv4 | 196.29.166.218 | 2017-02-03 | 2017-02-12 |
| IPv4 | 125.214.195.17 | 2017-02-03 | 2017-02-12 |
| HASH | cc6a731e9daff84bae4214603e1c3ba… | 2017-02-03 | 2017-02-03 |
| HASH | fc8607c155617e09d540c5030eabad9… | 2017-02-03 | 2017-02-03 |
| HASH | 496207db444203a6a9c02a32aff28d5… | 2017-02-03 | 2017-02-03 |