TWO BYTES TO $951M

2016-04-25 Bae Systems

http://baesystemsai.blogspot.kr/2016/04/two-bytes-to-951m.html

Thumbnail for TWO BYTES TO $951M

BAE Systems analyzed custom malware linked to the Bangladesh Bank SWIFT heist, where attackers attempted to transfer $951 million and $81 million remained unaccounted for. The malware was built for an environment running SWIFT Alliance Access with an Oracle database, registered itself as a service, and parsed local SWIFT FIN messages to identify attacker-defined transaction strings. It could patch a SWIFT Alliance module in memory to bypass a conditional authorization check, then generate SQL statements to delete transaction records or manipulate balance-reporting data. The tooling also used an encrypted configuration file, local logging paths, and command-and-control callbacks tied to SWIFT login and logout events, showing detailed knowledge of the victim payment infrastructure.

Indicators of Compromise

Type Value First Seen Last Seen
IPv4 196.202.103.174 2016-04-25 2016-08-25
HASH 76bab478dcc70f979ce62cd306e9ba5… 2016-04-25 2016-04-25
HASH 525a8e3ae4e3df8c9c61f2a49e38541… 2016-04-25 2016-04-25
HASH 70bf16597e375ad691f2c1efa194dbe… 2016-04-25 2016-04-25
HASH 6207b92842b28a438330a2bf0ee8dca… 2016-04-25 2016-04-25

Related Reports

« Back