Several Polish banks hacked information stolen by unknown attackers

2017-02-03 Badcyber

https://badcyber.com/several-polish-banks-hacked-information-stolen-by-unknown-attackers/

Thumbnail for Several Polish banks hacked information stolen by unknown attackers

BadCyber reported a major compromise affecting multiple Polish commercial banks after unusual network traffic and unauthorized files were found on workstations and servers. The suspected infection source was the Polish Financial Supervision Authority website, where a modified JavaScript file loaded an external iframe from sap.misapor[.]ch that could deliver payloads to selected visitors. After exploitation, the malware connected to foreign servers and could support reconnaissance, lateral movement, data exfiltration, and remote-access functionality. The malware was described as previously undocumented, packed and obfuscated, multi-stage, encrypted, and not recognized by available antivirus tools during the initial analysis. BadCyber published hashes and malicious URLs tied to the KNF compromise, including sap.misapor[.]ch and eye-watch[.]in paths, while noting that attacker motivation and the contents of encrypted outbound transfers were still unknown.

Indicators of Compromise

Type Value First Seen Last Seen
HASH d4616f9706403a0d5a2f9a8726230a4… 2017-02-03 2020-03-09
DOMAIN knf.gov 2017-02-03 2017-05-30
HASH 85d316590edfb4212049c4490db08c4b 2017-02-03 2017-04-03
HASH 4f0d7a33d23d53c0eb8b34d102cdd66… 2017-02-03 2017-04-03
HASH c1364bbf63b3617b25b58209e4529d8c 2017-02-03 2017-04-03
HASH bedceafa2109139c793cb158cec9fa4… 2017-02-03 2017-04-03
HASH 1bfbc0c9e0d9ceb5c3f4f6ced6bcfeae 2017-02-03 2017-04-03
URL http://www.knf.gov.pl/DefaultDe… 2017-02-03 2017-04-03
URL https://sap.misapor.ch/vishop/v… 2017-02-03 2017-04-03
DOMAIN sap.misapor.ch 2017-02-03 2017-04-03
URL http://sap.misapor.ch/vishop/vi… 2017-02-03 2017-02-12
URL https://www.eye-watch.in/design… 2017-02-03 2017-02-12
IPv4 196.29.166.218 2017-02-03 2017-02-12
IPv4 125.214.195.17 2017-02-03 2017-02-12
HASH cc6a731e9daff84bae4214603e1c3ba… 2017-02-03 2017-02-03
HASH fc8607c155617e09d540c5030eabad9… 2017-02-03 2017-02-03
HASH 496207db444203a6a9c02a32aff28d5… 2017-02-03 2017-02-03

Related Reports

« Back