New data wiper malware used in Ukraine
Cosa significa
MISP EudorIA ha pubblicato l'advisory "New data wiper malware used in Ukraine". Occorre verificarne l'applicabilita rispetto a prodotti e servizi in uso.
Perché conta
Un advisory attendibile puo richiedere verifiche, aggiornamenti o mitigazioni, ma l'applicabilita va confermata sul perimetro reale.
Azioni consigliate
- Verificare tecnologie, versioni e servizi interessati nel proprio inventario.
- Consultare la fonte originale prima di pianificare la mitigazione.
Testo acquisito dalla fonte
Evento MISP pubblicato con TLP:CLEAR: New data wiper malware used in Ukraine. Report from - [URL rimossa] (1645824136) html [if IE 8 ]> **WMI query format:** > > *SELECT * FROM Win32\_PingStatus WHERE Address={configured\_c2\_domain}* > > **3.** Sends a network request to download the next stage payload using the IP address obtained from step #2 and also exfiltrate the information collected from step #1 using the UserAgent field > **UserAgent Format:** > > {hardcoded\_useragent\_string}**::**%USERPROFILE%**\_**%SYSTEMDRIVE%.SerialNumber**::\.**{static\_string}**\.** > > **4.** Drops and executes the downloaded payload **Note:** At the time of analysis we didn’t get this next stage payload but based on past analysis the threat actor is known to drop some remote desktop application like UltraVNC **Attack Chain #2** We identified another attack-chain used by the same threat actor which is not documented anywhere in the public domain, to the best of our knowledge. Based on our research, this campaign has been active since as early as November 2020 and only 7 unique samples have been identified till date related to this campaign. The most recent instance was observed on 11th Feb 2022 and based on the filename, we believe that it was distributed on 8th Feb 2022 to the targeted victim(s). This low-volume campaign involves RAR archive files distributed through spear phishing emails. These RAR archive files contain a malicious Windows shortcut file (LNK) which do
- Fonte
- MISP EudorIA
- Entità pubblicatrice
- MISP EudorIA
- Tipo entità
- Comunità di intelligence
- Area
- Global
- Lingua originale
- it · traduzione non necessaria
- Pubblicazione
- 30/07/2026 02:46
- Condivisione
- TLP:CLEAR
- Indicatori dichiarati dalla fonte
- 43
- IOC indicizzati per la ricerca
- 0 valori nel periodo di conservazione
- IOC disponibili nel feed STIX
- 33Ultima verifica di condivisione: 2026-09-26T10:01:13.915026+00:00
- Evento MISP
- 56cb2bd3-5525-46bd-a454-ea895a5b4d0d
- MITRE ATT&CK
- Data Destruction - T1485, Disk Structure Wipe - T1561.002, Group Policy Modification - T1484.001, Inhibit System Recovery - T1490, Signed Binary Proxy Execution - T1218
- Classificazione
- Alta