The Blockbuster Saga Continues

2017-08-14 Paloalto Networks

https://researchcenter.paloaltonetworks.com/2017/08/unit42-blockbuster-saga-continues/

Thumbnail for The Blockbuster Saga Continues

Unit 42 identified continued Blockbuster-linked attack activity targeting individuals associated with United States defense contractors. The campaign used weaponized Microsoft Office documents with malicious macros and decoys copied from defense-contractor job descriptions and internal policy themes, marking a shift from earlier Korean-language targeting to English-speaking targets. The report ties the activity to prior Operation Blockbuster-related operations through reused macro source code, XOR keys, PE payload behavior, fake TLS communications, direct IPv4 C2 beaconing, and overlapping hosting paths and infrastructure. Indicators include weaponized document hashes, C2 or hosting IPs such as 210.202.40[.]35 and 104.192.193[.]149, and payload or document URLs on compromised systems.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 16c3a7f143e831dd0481d2d57aae885… 2017-08-14 2020-03-09
HASH 7429a6b6e8518a1ec1d1c37a8786359… 2017-08-14 2020-03-09
IPv4 107.6.12.135 2017-08-14 2020-02-25
IPv4 210.202.40.35 2017-08-14 2020-02-25
IPv4 176.35.250.93 2017-08-14 2017-12-19
IPv4 118.140.97.6 2017-08-14 2017-12-12
HASH 2f133525f76ab0ebb0b370601673361… 2017-08-14 2017-08-14
HASH de2d458c8e4befcd478a0010789d809… 2017-08-14 2017-08-14
HASH 6f673981892701d42159489c1b2614c… 2017-08-14 2017-08-14
HASH c63a415d23fc4ab10ad3acfdd47d42b… 2017-08-14 2017-08-14
HASH e09224a24a14a08c6fcb79b00b4a7b3… 2017-08-14 2017-08-14
HASH 062aadf3eb69686f4881860d88ce472… 2017-08-14 2017-08-14
HASH 1288e105c83a6f4bbad8471a9b5beda… 2017-08-14 2017-08-14
HASH ad075279d2ee6958105889d852e0d7f… 2017-08-14 2017-08-14
HASH acfae7e2fdda02e81b3e03f8c307417… 2017-08-14 2017-08-14
HASH f390ef86a4ad92dde125c983e6470f0… 2017-08-14 2017-08-14
HASH e83a08bcb4353bfd6edcdedbc9ead9a… 2017-08-14 2017-08-14
HASH 4d4465bd9a57c7a3c0b80fa32826975… 2017-08-14 2017-08-14
URL http://lansingturbo.org/docs/We… 2017-08-14 2017-08-14
DOMAIN lansingturbo.org 2017-08-14 2017-08-14
IPv4 213.152.51.169 2017-08-14 2017-08-14
IPv4 108.222.149.173 2017-08-14 2017-08-14
IPv4 104.192.193.149 2017-08-14 2017-08-14
IPv4 197.246.6.83 2017-08-14 2017-08-14
IPv4 59.90.93.97 2017-08-14 2017-08-14

Related Reports

« Back