MAR-10201537 – HIDDEN COBRA FASTCash-Related Malware

2018-10-02 USCISA

https://www.cisa.gov/news-events/analysis-reports/ar18-275a

Thumbnail for MAR-10201537 – HIDDEN COBRA FASTCash-Related Malware

CISA analyzed HIDDEN COBRA malware used in the DPRK-linked FASTCash operation to facilitate fraudulent ATM withdrawals. Malicious XCOFF components injected into legitimate processes on IBM AIX financial systems and modified ISO 8583 transaction messages. Supporting Windows malware provided proxy, remote-command, file-transfer, payload-installation, and data-exfiltration capabilities while modifying firewall settings. One remote-access Trojan contained the hard-coded command-and-control address 75.99.63.27 and listened on TCP port 443.

Indicators of Compromise

Type Value First Seen Last Seen
HASH 3a5ba44f140821849de2d82d5a137c3… 2018-08-28 2024-10-13
HASH 10ac312c8dd02e417dd24d53c99525c… 2018-08-28 2024-10-13
HASH d465637518024262c063f4a82d799a4… 2018-08-28 2021-12-02
HASH ca9ab48d293cc84092e8db8f0ca99cb… 2018-08-28 2021-12-02
HASH 820ca1903a30516263d630c7c08f2b9… 2018-08-28 2020-03-09
HASH a9bc09a17d55fc790568ac864e38854… 2018-08-28 2020-03-09
HASH 4a740227eeb82c20286d9c112ef95f0… 2018-08-28 2020-03-09
HASH 9ddacbcd0700dc4b9babcd09ac1cebe… 2018-10-02 2019-01-23
HASH 1f2cd2bc23556fb84a51467fedb89cb… 2018-10-02 2019-01-23
HASH e03dc5f1447f243cf1f305c58d95000… 2018-10-02 2018-10-02
HASH f3e521996c85c0cdb2bfb3a0fd91eb0… 2018-08-28 2018-10-02
HASH ab88f12f0a30b4601dc26dbae57646e… 2018-08-28 2018-10-02
IPv4 75.99.63.27 2018-08-28 2018-10-02

Related Actors

Related Reports

« Back