EudorIACyber Intelligence
Monitoraggio operativo Newsletter IT EN
← Torna all'intelligence
Avviso tecnico

New data wiper malware used in Ukraine

Fonte aperta verificata
Intelligence con provenienza tracciabile. EudorIA conserva gli indicatori tecnici acquisiti dai feed supportati, con fonte, data e contesto. Gli IOC condivisibili sono disponibili nei feed STIX; le azioni di rilevamento e blocco richiedono la valutazione di validita, confidenza e applicabilita al perimetro del cliente. Consulta i feed STIX
Sintesi operativa EudorIA

Cosa significa

Priorità 70/100

MISP EudorIA ha pubblicato l'advisory "New data wiper malware used in Ukraine". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.

Perché conta

Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.

DestinatariITSOCCISO

Testo acquisito dalla fonte

Evento MISP pubblicato con TLP:CLEAR: New data wiper malware used in Ukraine. Report from - [URL rimossa] (1645824136) html [if IE 8 ]> **WMI query format:** > > *SELECT * FROM Win32\_PingStatus WHERE Address={configured\_c2\_domain}* > > **3.** Sends a network request to download the next stage payload using the IP address obtained from step #2 and also exfiltrate the information collected from step #1 using the UserAgent field > **UserAgent Format:** > > {hardcoded\_useragent\_string}**::**%USERPROFILE%**\_**%SYSTEMDRIVE%.SerialNumber**::\.**{static\_string}**\.** > > **4.** Drops and executes the downloaded payload **Note:** At the time of analysis we didn’t get this next stage payload but based on past analysis the threat actor is known to drop some remote desktop application like UltraVNC **Attack Chain #2** We identified another attack-chain used by the same threat actor which is not documented anywhere in the public domain, to the best of our knowledge. Based on our research, this campaign has been active since as early as November 2020 and only 7 unique samples have been identified till date related to this campaign. The most recent instance was observed on 11th Feb 2022 and based on the filename, we believe that it was distributed on 8th Feb 2022 to the targeted victim(s). This low-volume campaign involves RAR archive files distributed through spear phishing emails. These RAR archive files contain a malicious Windows shortcut file (LNK) which do

Fonte
MISP EudorIA
Entità pubblicatrice
MISP EudorIA
Tipo entità
Comunità di intelligence
Area
Global
Lingua originale
it · traduzione non necessaria
Pubblicazione
30/07/2026 02:46
Condivisione
TLP:CLEAR
Indicatori dichiarati dalla fonte
43
IOC indicizzati per la ricerca
0 valori nel periodo di conservazione
IOC disponibili nel feed STIX
33Ultima verifica di condivisione: 2026-09-26T10:01:13.915026+00:00
Evento MISP
56cb2bd3-5525-46bd-a454-ea895a5b4d0d
MITRE ATT&CK
Data Destruction - T1485, Disk Structure Wipe - T1561.002, Group Policy Modification - T1484.001, Inhibit System Recovery - T1490, Signed Binary Proxy Execution - T1218
Classificazione
Alta
Apri la fonte originale