VayGren and Mr.Burns: Strong Ties in Finance
· Published 10/07/2024 09:49 · Modified 10/07/2024 10:18
Essential information
- Published
- 10/07/2024 09:49
- Modified
- 10/07/2024 10:18
- Tags
- 2024-07-10 ave maria burnsrat metastealer purecrypter purelogs redline stealer teamviewer warzonerat
- Related entities
- 131 observables, 1 intrusion sets (apt), 31 techniques (mitre), 9 malware, 1 others
Description
F.A.C.C.T experts analyzed the tools and connections of cybercriminals attacking Russian accountants. An analysis of the infection chain of the VasyGrek attacker, his forum activity and connection with the malware developer Mr.Burns is presented. The history of Mr.Burns, starting in 2010, is given, as well as a description of the current version of the BurnsRAT malware, sold on forums and used in attacks on Russian companies.
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (131)
-
ebdce7eae3a77ed05ed6279c46a8be8c560085f82ce0f9e4de0ad8c700c16fc4 -
f7878a67c6de2ff26c79ab890e4a60b76c67a7583c6a24bd96cd93a5f4a0e0aa -
e4a91db9e43655931fd3926ec00dbe8a063fbe0d3f0af7d902fd3b9d8281fb3d -
e360674d2abf0bea085d01bc3595e19efb3ac061ab8090a32d0c579c621c46f6 -
d79d130aa4f0b207e741909c45be613a1e3720cb82a0578012cc508c28da6bad -
c3b30120feef022d552f85b780d4c988ee82bc07e6b5948db5d32e59d44fa704 -
c2f97483f8a5a96fa39e8bd3d3458093ac527a8c8efd662e838d95a9bc2354fb -
bf9fc94905d75ccf3640d35899d533e50c7ba8bdce396443ae2d0507657a9e81 -
bbad7c6e8f0d7ae94941257e7ece4d2b144aad56e25760c8876b808f3e8420e6 -
ba629f7ee519379f1a5a8a4683ee9a48d1b0996268bfaf1162e4bf0f2b792b77 -
b2193cb3f8bd13c8a5769d5ce499a36b9c44e2eb2800bcdf22320525beaf9586 -
af8018b310bf030f6feca0f6f23d3e65f8926114d7cd493573badae24f5da0d1
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Techniques (MITRE) (31)
-
Non-Standard Port MITRE
-
Registry Run Keys / Startup Folder MITRE
-
Non-Application Layer Protocol MITRE
-
Screen Capture MITRE
-
Web Protocols MITRE
-
Security Software Discovery MITRE
-
Match Legitimate Resource Name or Location MITRE
-
File Deletion MITRE
-
Malicious File MITRE
-
DLL MITRE
-
Data from Local System MITRE
-
Hijack Execution Flow MITRE
Malware (9)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Family
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
-
Family The MITRE Corporation Confidence 100
[RedLine Stealer](https://attack.mitre.org/software/S1240) is an information-stealer malware variant first identified in 2020.(Citation: ESET RedLine Stealer November 2024)(Citation: Proofpoint RedLine Stealer March 2020)(Citation: Splunk RedLine Stealer June 2023) [RedLine Stealer](https://attack.mitre.org/software/S1240)…
First seen 01/01/1970 · Last seen 16/11/5138 · -
AlienVault Confidence 100
PureCrypter is a fully-featured malware loader, developed by a threat actor called “PureCoder," that has been in use since at least 2021 to distribute a variety of remote…
First seen 01/01/1970 · Last seen 16/11/5138 ·
Others (1)
-
Finance