Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- ESET - Gazer Backdoor
- IoCS
- Filenames
- • %TEMP%\KB943729.log
- • %TEMP%\CVRG72B5.tmp.cvr
- • %TEMP%\CVRG1A6B.tmp.cvr
- • %TEMP%\CVRG38D9.tmp.cvr
- • %TEMP%\~DF1E06.tmp
- • %HOMEPATH%\ntuser.dat.LOG3
- • %HOMEPATH%\AppData\Local\Adobe\AdobeUpdater.exe
- Registry keys
- • HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ScreenSaver
- • HKCU\Software\Microsoft\Windows NT\CurrentVersion\Explorer\ScreenSaver
- C&C URLs
- • daybreakhealthcare.co.uk/wp-includes/themees.php
- • simplecreative.design/wp-content/plugins/calculated- elds-form/single.php
- • 169.255.137.203/rss_0.php
- • outletpiumini.springwaterfeatures.com/wp-includes/pomo/settings.php
- • zerogov.com/wp-content/plugins.deactivate/paypal-donations/src/PaypalDonations/SimpleSubsribe.
- php
- • ales.ball-mill.es/ck nder/core/connector/php/php4/CommandHandler/CommandHandler.php
- • dyskurs.com.ua/wp-admin/includes/map-menu.php
- • warrixmalaysia.com.my/wp-content/plugins/jetpack/modules/contact-form/grunion-table-form.php
- • 217.171.86.137/con g.php
- • 217.171.86.137/rss_0.php
- • shinestars-lifestyle.com/old_shinstar/includes/old/front_footer.old.php
- • www.aviasiya.com/murad.by/life/wp-content/plugins/wp-accounting/inc/pages/page-search.php
- • baby.greenweb.co.il/wp-content/themes/san-kloud/admin.php
- • soligro.com/wp-includes/pomo/db.php
- • giadinhvabe.net/wp-content/themes/viettemp/out/css/class.php
- • tekfordummies.com/wp-content/plugins/social-auto-poster/includes/libraries/delicious/Delicious.php
- • kennynguyen.esy.es/wp-content/plugins/wp-statistics/vendor/maxmind-db/reader/tests/MaxMind/Db/
- test/Reader/BuildTest.php
- • sonneteck.com/wp-content/plugins/yith-woocommerce-wishlist/plugin-fw/licence/templates/panel/
- activation/activation.php
- • chagiocaxuanson.esy.es/wp-content/plugins/nextgen-gallery/products/photocrati_nextgen/modules/
- ngglegacy/admin/templates/manage_gallery/gallery_preview_page_ eld.old.php
- • hotnews.16mb.com/wp-content/themes/twentysixteen/template-parts/content-header.php
- • zszinhyosz.pe.hu/wp-content/themes/twentyfourteen/page-templates/full-hight.php
- • weandcats.com/wp-content/plugins/broken-link-checker/modules/checkers/http-module.php
- Mutexes
- {531511FA-190D-5D85-8A4A-279F2F592CC7}
- 21
- Gazing at Gazer
- Turla’s new second stage backdoor
- Hashes
- Table 6. Gazer sample hashes
- SHA1 hash
- Component Compilation Certi cate Time
- Eset Detection Name
- 27FA78DE705EbAA4b11C4b5FE7277F91906b3F92
- Gazer wiper x32
- 07/04/2016 15:04:24
- not signed
- Win32/Turla.CL
- 35F205367E2E5F8A121925bbAE6FF07626b526A7
- Gazer loader x32
- 05/02/2002 17:36:10
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win32/Turla.CC
- b151CD7C4F9E53A8DCbDEb7CE61CCDD146Eb68Ab
- Gazer loader x32
- 05/02/2002 17:36:10
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win32/Turla.CC
- E40bb5bEEC5678537E8FE537F872b2AD6b77E08A
- Gazer loader x32
- 05/02/2002 17:36:10
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win32/Turla.CC
- 522E5F02C06AD215C9D0C23C5A6A523D34AE4E91
- Gazer loader x64
- 05/02/2002 17:36:26
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win64/Turla.AA
- C380038A57FFb8C064851b898F630312FAbCbbA7
- Gazer loader x64
- 05/02/2002 17:36:26
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win64/Turla.AA
- 267F144D771b4E2832798485108DECD505Cb824A
- Gazer loader x64
- 05/02/2002 17:36:26
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win64/Turla.AA
- 52F6D09CCCDbC38D66C184521E7CCF6b28C4b4D9
- Gazer loader x32
- 04/10/2002 18:31:37
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win32/Turla.CC
- 475C59744ACCb09724DAE610763b7284646Ab63F
- Gazer loader x32
- 04/10/2002 18:31:37
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win32/Turla.CC
- 22542A3245D52b7bCDb3EAEF5b8b2693F451F497
- Gazer loader x32
- 04/10/2002 18:31:37
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win32/Turla.CC
- 2b9FAA8b0FCADAC710C7b2b93D492FF1028b5291
- Gazer loader x64
- 04/10/2002 18:34:18
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win64/Turla.AA
- E05Ab6978C17724b7C874F44F8A6CbFb1C56418D
- Gazer loader x64
- 04/10/2002 18:34:18
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win64/Turla.AA
- 6DEC3438D212b67356200bbAC5EC7FA41C716D86
- Gazer loader x64
- 04/10/2002 18:34:18
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win64/Turla.AA
- b548863DF838069455A76D2A63327434C02D0D9D
- Gazer loader x64
- 09/01/2016 19:30:10
- not signed
- Win64/Turla.AA
- C3E6511377DFE85A34E19b33575870DDA8884C3C
- Gazer loader x64
- 06/02/2016 19:29:15
- admin@ ultimatecomsup.biz valid from 16/12/2015 to 16/12/2017
- Win64/Turla.AA
- 9FF4F59CA26388C37D0b1F0E0b22322D926E294A
- Gazer loader x64
- 16/02/2016 16:00:44
- admin@ ultimatecomsup.biz valid from 16/12/2015 to 16/12/2017
- Win64/Turla.AA
- 22
- Gazing at Gazer
- Turla’s new second stage backdoor
- SHA1 hash Component Compilation Certi cate Eset Detection Time Name
- 029AA51549D0b9222Db49A53D2604D79AD1C1E59
- Gazer loader x64
- 18/02/2016 15:29:58
- admin@ ultimatecomsup.biz valid from 16/12/2015 to 16/12/2017
- Win64/Turla.AA
- CECC70F2b2D50269191336219A8F893D45F5E979
- Gazer loader x64
- 01/01/2017 08:39:30
- admin@ ultimatecomsup.biz valid from 16/12/2015 to 16/12/2017
- Win64/Turla.AG
- 7FAC4FC130637AFAb31C56CE0A01E555D5DEA40D
- Gazer loader x64
- 11/06/2017 23:43:51
- admin@ ultimatecomsup.biz valid from 16/12/2015 to 16/12/2017
- Win64/Turla.AD
- 5838A51426CA6095b1C92b87E1bE22276C21A044
- Gazer loader x32
- 19/06/2017 01:28:51
- admin@ ultimatecomsup.biz valid from 16/12/2015 to 16/12/2017
- Win32/Turla.CF
- 3944253F6b7019EED496FAD756F4651bE0E282b4
- Gazer loader x64
- 19/06/2017 01:30:00
- admin@ ultimatecomsup.biz valid from 16/12/2015 to 16/12/2017
- Win64/Turla.AD
- 228DA957A9ED661E17E00EFbA8E923FD17FAE054
- Gazer orchestrator x32
- 05/02/2002 17:31:28
- not signed
- Win32/Turla.CF
- 295D142A7bDCED124FDCC8EDFE49b9F3ACCEAb8A
- Gazer orchestrator x32
- 05/02/2002 17:31:28
- not signed
- Win32/Turla.CF
- 0F97F599FAb7F8057424340C246D3A836C141782
- Gazer orchestrator x32
- 05/02/2002 17:31:28
- not signed
- Win32/Turla.CF
- Dbb185E493A0FDC959763533D86D73F986409F1b
- Gazer orchestrator x32
- 05/02/2002 17:31:28
- not signed
- Win32/Turla.CC
- 4701828DEE543b994ED2578b9E0D3991F22bD827
- Gazer orchestrator x64
- 05/02/2002 17:34:25
- not signed
- Win64/Turla.AA
- 6FD611667bA19691958b5b72673b9b802EDD7FF8
- Gazer orchestrator x64
- 05/02/2002 17:34:25
- not signed
- Win64/Turla.AA
- FCAbEb735C51E2b8Eb6Fb07bDA8b95401D069bD8
- Gazer orchestrator x64
- 05/02/2002 17:34:25
- not signed
- Win64/Turla.AA
- 75831DF9CbCFD7bF812511148D2A0F117324A75F
- Gazer orchestrator x32
- 04/10/2002 18:31:28
- not signed
- Win32/Turla.CC
- bAE3AE65C32838Fb52A0F5AD2CDE8659D2bFF9F3
- Gazer orchestrator x32
- 04/10/2002 18:31:28
- not signed
- Win32/Turla.CC
- 37FF6841419ADC51EEb8756660b2Fb46F3Eb24ED
- Gazer orchestrator x64
- 04/10/2002 18:33:02
- not signed
- Win64/Turla.AA
- 9E6DE3577b463451b7AFCE24Ab646EF62AD6C2bD
- Gazer orchestrator x64
- 04/10/2002 18:33:02
- not signed
- Win64/Turla.AA
- 795C6EE27b147FF0A05C0477F70477E315916E0E
- Gazer orchestrator x64
- 04/10/2002 18:33:02
- not signed
- Win64/Turla.AA
- 8184AD9D6bbD03E99A397F8E925FA66CFbE5CF1b
- Gazer orchestrator x64
- 09/01/2016 19:28:29
- not signed
- Win64/Turla.AA
- 7CED96b08D7593E28FEE616ECCbC6338896517CF
- Gazer orchestrator x64
- 06/02/2016 19:29:04
- not signed
- Win64/Turla.AA
- 63C534630C2CE0070AD203F9704F1526E83AE586
- Gazer orchestrator x64
- 06/02/2016 19:29:04
- not signed
- Win64/Turla.AA
- 23F1E3bE3175D49E7b262CD88CFD517694DCbA18
- Gazer orchestrator x64
- 18/02/2016 15:29:32
- not signed
- Win64/Turla.AA
- 23
- Gazing at Gazer
- Turla’s new second stage backdoor
- SHA1 hash Component Compilation Certi cate Eset Detection Time Name
- 7A6F1486269AbDC1D658Db618DC3C6F2AC85A4A7
- Gazer orchestrator x64
- 01/01/2017 08:39:19
- not signed
- Win64/Turla.AG
- 11b35320Fb1CF21D2E57770D8D8b237Eb4330EAA
- Gazer orchestrator x64
- 11/06/2017 23:42:28
- not signed
- Win64/Turla.AD
- E8A2bAD87027F2bF3ECAE477F805DE13FCCC0181
- Gazer orchestrator x32
- 19/06/2017 01:28:21
- not signed
- Win32/Turla.CF
- 950F0b0C7701835C5FbDb6C5698A04b8AFE068E6
- Gazer orchestrator x64
- 19/06/2017 01:29:46
- not signed
- Win64/Turla.AD
- A5EEC8C6AADF784994bF68D9D937bb7AF3684D5C
- Gazer comm x64
- 05/02/2002 17:57:07
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win64/Turla.AH
- 411EF895FE8DD4E040E8bF4048F4327F917E5724
- Gazer comm x32
- 05/02/2002 17:58:22
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
- Win32/Turla.CC
- C1288DF9022bCD2C0A217b1536DFA83928768D06
- Gazer comm x32
- 06/02/2016 19:23:52
- not signed
- Win32/Turla.CC
- 4b6EF62D5D59F2FE7F245DD3042DC7b83E3CC923
- Gazer comm x32
- 11/06/2017 23:44:24
- not signed
- Win32/Turla.CF
- 7F54F9F2A6909062988AE87C1337F3CF38D68D35
- Gazer wiper x32
- 05/02/2002 17:39:07
- admin@solidloop.org
- valid from 14/10/2015 to 14/10/2016
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement