The Blockbuster Saga Continues
2017-08-14 • Paloalto Networks •
https://researchcenter.paloaltonetworks.com/2017/08/unit42-blockbuster-saga-continues/
Unit 42 identified continued Blockbuster-linked attack activity targeting individuals associated with United States defense contractors. The campaign used weaponized Microsoft Office documents with malicious macros and decoys copied from defense-contractor job descriptions and internal policy themes, marking a shift from earlier Korean-language targeting to English-speaking targets. The report ties the activity to prior Operation Blockbuster-related operations through reused macro source code, XOR keys, PE payload behavior, fake TLS communications, direct IPv4 C2 beaconing, and overlapping hosting paths and infrastructure. Indicators include weaponized document hashes, C2 or hosting IPs such as 210.202.40[.]35 and 104.192.193[.]149, and payload or document URLs on compromised systems.
Indicators of Compromise
| Type | Value | First Seen | Last Seen |
|---|---|---|---|
| HASH | 16c3a7f143e831dd0481d2d57aae885… | 2017-08-14 | 2020-03-09 |
| HASH | 7429a6b6e8518a1ec1d1c37a8786359… | 2017-08-14 | 2020-03-09 |
| IPv4 | 107.6.12.135 | 2017-08-14 | 2020-02-25 |
| IPv4 | 210.202.40.35 | 2017-08-14 | 2020-02-25 |
| IPv4 | 176.35.250.93 | 2017-08-14 | 2017-12-19 |
| IPv4 | 118.140.97.6 | 2017-08-14 | 2017-12-12 |
| HASH | 2f133525f76ab0ebb0b370601673361… | 2017-08-14 | 2017-08-14 |
| HASH | de2d458c8e4befcd478a0010789d809… | 2017-08-14 | 2017-08-14 |
| HASH | 6f673981892701d42159489c1b2614c… | 2017-08-14 | 2017-08-14 |
| HASH | c63a415d23fc4ab10ad3acfdd47d42b… | 2017-08-14 | 2017-08-14 |
| HASH | e09224a24a14a08c6fcb79b00b4a7b3… | 2017-08-14 | 2017-08-14 |
| HASH | 062aadf3eb69686f4881860d88ce472… | 2017-08-14 | 2017-08-14 |
| HASH | 1288e105c83a6f4bbad8471a9b5beda… | 2017-08-14 | 2017-08-14 |
| HASH | ad075279d2ee6958105889d852e0d7f… | 2017-08-14 | 2017-08-14 |
| HASH | acfae7e2fdda02e81b3e03f8c307417… | 2017-08-14 | 2017-08-14 |
| HASH | f390ef86a4ad92dde125c983e6470f0… | 2017-08-14 | 2017-08-14 |
| HASH | e83a08bcb4353bfd6edcdedbc9ead9a… | 2017-08-14 | 2017-08-14 |
| HASH | 4d4465bd9a57c7a3c0b80fa32826975… | 2017-08-14 | 2017-08-14 |
| URL | http://lansingturbo.org/docs/We… | 2017-08-14 | 2017-08-14 |
| DOMAIN | lansingturbo.org | 2017-08-14 | 2017-08-14 |
| IPv4 | 213.152.51.169 | 2017-08-14 | 2017-08-14 |
| IPv4 | 108.222.149.173 | 2017-08-14 | 2017-08-14 |
| IPv4 | 104.192.193.149 | 2017-08-14 | 2017-08-14 |
| IPv4 | 197.246.6.83 | 2017-08-14 | 2017-08-14 |
| IPv4 | 59.90.93.97 | 2017-08-14 | 2017-08-14 |