Pink Sandstorm Attacks

Overview

This report covers Pink Sandstorm's attacks, associated IOCs, and YARA rules for detection. It also highlights the malware and tools used by the group. It is not an in-depth analysis of Pink Sandstorm tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.

Pink Sandstorm

Pink Sandstorm is an Iranian cyber threat group closely associated with the Iranian Ministry of Intelligence and Security (MOIS). Active since 2020, the group specializes in conducting cyberattacks using wipers and ransomware. The primary targets of Pink Sandstorm are organizations in Israel. However, their attacks have also been observed against entities in Hong Kong and South Africa.

Origin Country

Iran

Motivation

Espionage

First Seen

2020

Industries Attacked

  • Education
  • Tech

Targeted Countries

  • Israel

ProcDump

Pink Sandstorm Targets Israeli Tech and Education Sectors

  • SHA-256: 5d1660a53aaf824739d82f703ed580004980d377bdc2834f1041d512e4305d07

  • SHA-256: f4c8369e4de1f12cc5a71eb5586b38fc78a9d8db2b189b8c25ef17a572d4d6b7

  • Sample: ANY.RUN

Mimikatz

Pink Sandstorm Targets Israeli Tech and Education Sectors

WinSCP

Pink Sandstorm Targets Israeli Tech and Education Sectors

  • SHA-256: 768ece399c75a27aca90313f625016e8e795f737667577d75af0042c896987f7
  • Sample: ANY.RUN

MONEYBIRD

Moneybird Attacks on Israeli Organizations

Moneybird sample

  • SHA-256: aa19839b1b6a846a847c5f4f2a2e8e634caeebeeff7af59865aecca1d7d9f43c

  • SHA-256: bc58d7ce32f93c74ab8032b19c5af4e45271a54d0071e93f8c4ea0eb23f16c01

  • Sample: ANY.RUN

WinEggDrop

Pink Sandstorm Targets Israeli Tech and Education Sectors

  • SHA-256: 49c3df62c4b62ce8960558daea4a8cf41b11c8f445e218cd257970cf939a3c25

SQLEXTRACTOR

Pink Sandstorm Targets Israeli Tech and Education Sectors

  • SHA-256: a8e63550b56178ae5198c9cc5b704a8be4c8505fea887792b6d911e488592a7c

IOC Summary

  • Pink Sandstorm Targets Israeli Tech and Education Sectors
IOCs (Click to expand)
  • SHA-256: 1ea4d26a31dad637d697f9fb70b6ed4d75a13d101e02e02bc00200b42353985c
  • SHA-256: 62e36675ed7267536bd980c07570829fe61136e53de3336eebadeca56ab060c2
  • SHA-256: abfde7c29a4a703daa2b8ad2637819147de3a890fdd12da8279de51a3cc0d96d
  • SHA-256: 63d51bc3e5cf4068ff04bd3d665c101a003f1d6f52de7366f5a2d9ef5cc041a7
  • SHA-256: 49c3df62c4b62ce8960558daea4a8cf41b11c8f445e218cd257970cf939a3c25
  • SHA-256: dacdb4976fd75ab2fd7bb22f1b2f9d986f5d92c29555ce2b165c020e2816a200
  • SHA-256: e43d66b7a4fa09a0714c573fbe4996770d9d85e31912480e73344124017098f9
  • SHA-256: 2a6e3b6e42be2f55f7ab9db9d5790b0cc3f52bee9a1272fc4d79c7c0a3b6abda
  • SHA-256: 5d1660a53aaf824739d82f703ed580004980d377bdc2834f1041d512e4305d07
  • SHA-256: f4c8369e4de1f12cc5a71eb5586b38fc78a9d8db2b189b8c25ef17a572d4d6b7
  • SHA-256: 13d8d4f4fa483111e4372a6925d24e28f3be082a2ea8f44304384982bd692ec9
  • SHA-256: a112e78e4f8b99b1ceddae44f34692be20ef971944b98e2def995c87d5ae89ee
  • SHA-256: 18c909a2b8c5e16821d6ef908f56881aa0ecceeaccb5fa1e54995935fcfd12f7
  • SHA-256: 2fb88793f8571209c2fcf1be528ca1d59e7ac62e81e73ebb5a0d77b9d5a09cb8
  • SHA-256: 9165d4f3036919a96b86d24b64d75d692802c7513f2b3054b20be40c212240a5
  • SHA-256: f65880ef9fec17da4142850e5e7d40ebfc58671f5d66395809977dd5027a6a3e
  • SHA-256: 38e406b17715b1b52ed8d8e4defdb5b79a4ddea9a3381a9f2276b00449ec8835
  • SHA-256: ec7dc5bfadce28b8a8944fb267642c6f713e5b19a9983d7c6f011ebe0f663097
  • SHA-256: c52525cd7d05bddb3ee17eb1ad6b5d6670254252b28b18a1451f604dfff932a4
  • SHA-256: a8e63550b56178ae5198c9cc5b704a8be4c8505fea887792b6d911e488592a7c
  • SHA-256: C9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e
  • SHA-256: 92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50
  • SHA-256: E61b8f44ab92cf0f9cb1101347967d31e1839979142a4114a7dd02aa237ba021
  • SHA-256: 768ece399c75a27aca90313f625016e8e795f737667577d75af0042c896987f7
  • ip: 185.105.46[.]34
  • ip: 185.105.46[.]19
  • ip: 93.188.207[.]110
  • ip: 109.237.107[.]212
  • ip: 217.29.62[.]166
  • ip: 81.177.22[.]182

YARA Rules

Moneybird Attacks on Israeli Organizations


rule ransomware_moneybird {
  meta: 
    author = "Marc Salinas @ Check Point Research" 
    description = "Detects a ransomware sample named Moneybird based on its pdb string."
    malware_family = "MoneyBird" 
    date = "11/05/2023"  
    sample = "aa19839b1b6a846a847c5f4f2a2e8e634caeebeeff7af59865aecca1d7d9f43c" 

  strings:
    $ran1 = "WE ARE MONEYBIRD!"
    $ran2 = "All of your data encrypted!"
    $ran3 = "ok.ru/profile"

    $ext1 = "Shiftlibgcrypt"
    $ext2 = "come to the aide of their"
    $ext3 = "stopmarker" wide

    $code1 = {44 89 4C 24 20 4C 89 44 24 18 48 89 54 24 10 89 4C 24 08 56 57 48 83 EC 78 48 8B 05 68 FE 1A 00 48 33 C4 48 89 44 24 60 48 8D 44 24 50 48 8D 0D DC 68 15 00 48 8B F8 48 8B F1 B9 10 00 00 00 F3 A4 45 33 C9 41 B8 09 00 00 00 BA 09 00 00 00 48 8D 4C 24 48 ?? ?? ?? ?? ?? 41 B8 20 00 00 00 48 8B 94 24 A0 00 00 00 48 8B 4C 24 48 ?? ?? ?? ?? ?? 48 8D 44 24 50 48 89 44 24 40 48 C7 44 24 30 FF FF FF FF}
    $code2 = {48 FF 44 24 30 48 8B 44 24 40 48 8B 4C 24 30 80 3C 08 00}
    $code3 = {48 8B 44 24 30 4C 8B C0 48 8D 54 24 50 48 8B 4C 24 48 ?? ?? ?? ?? ?? 8B 84 24 90 00 00 00 48 C7 44 24 20 00 00 00 00 45 33 C9 44 8B C0 48 8B 94 24 98 00 00 00 48 8B 4C 24 48 ?? ?? ?? ?? ?? 89 44 24 38 48 8B 4C 24 48 ?? ?? ?? ?? ?? 48 8B 4C 24 60 48 33 CC ?? ?? ?? ?? ?? 48 83 C4 78 5F 5E C3}

  condition:
    uint16(0) == 0x5A4D and (2 of ($ran*) or all of ($code*) or all of ($ext*))

FileScan.IO Moneybird detect


rule autogen_peexe_Greyware_bc58d7ce
{
    meta:
        author = "FileScan.IO Engine v1.1.0-52ab799"
        date = "2023-06-05"
        sample = "bc58d7ce32f93c74ab8032b19c5af4e45271a54d0071e93f8c4ea0eb23f16c01"
        score = 50
        tags = "greyware"
        isWeakRule = true

    strings:

        //IOC patterns
        $req0 = "\"You cannot concatenate the same moved string to itself. See N4910 16.4.5.9 [res.on.arguments]/1.3: \" \"If a function argument is"
        $req1 = "SOFTWARE\\Wow6432Node\\Microsoft\\VisualStudio\\14.0\\Setup\\VC"

        //optional strings
        $opt0 = "AdvAPI32.dll"
        $opt1 = "NETAPI32.DLL"
        $opt2 = "NTDll.dll"
        $opt3 = "VCRUNTIME140D.dll"
        $opt4 = "\\\\.\\PhysicalDrive%d"
        $opt5 = "advapi32.dll"
        $opt6 = "api-ms-win-core-registry-l1-1-0.dll"
        $opt7 = "callback != nullptr"
        $opt8 = "kernel32.dll"
        $opt9 = "mscoree.dll"

    condition:
        //require 75% of optional strings
        uint16(0) == 0x5A4D and filesize > 5938330 and filesize < 7257958 and all of ($req*) and 7 of ($opt*)
}

ioc.one Agrius_Function


rule Agrius_Function_Names {
    meta:
        description = "Detects malware used by Agrius threat actor based on unique function names"
        author = "Amitai B @ SentinelOne"
        version = "1.0"
        TLP = "White"
        last_modified = "2021-05-11"
    strings:
        $s1 = "GetWindowsTempPath"
        $s2 = "GetCurrentProcess"
        $s3 = "GetOwnPath"
        $s4 = "PublicFunction"
        $s5 = "SelfDelete"
        $s6 = "IsFirstInstance"
    condition:
        (filesize > 1KB and filesize < 300KB and 3 of ($s*))
}

https://ioc.one/auth/attribute/ff32dd96-191e-55e3-8614-be3d6e422f93


    
rule Agrius_Webshells {
    meta:
        description = "Detects variations of webshells used by Agrius"
        author = "Amitai B @ SentinelOne"
        version = "1.0"
        TLP = "White"
        last_modified = "2021-05-11"
    strings:
        $s1 = "public string base64ToStr(string instr)"
        $s2 = "Process prcsss=new Process()"
        $s3 = "<form id=\"PRIVATECode\" runat=\"server\">"
    condition:
        (filesize > 1KB and filesize < 150KB and any of them)
}

References

  • https://research.checkpoint.com/2023/agrius-deploys-moneybird-in-targeted-attacks-against-israeli-organizations/

  • https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors/

  • https://ioc.one/auth/attribute/16ed7b05-8ca5-50db-9c5f-a8081d2a7875

  • https://ioc.one/auth/attribute/ff32dd96-191e-55e3-8614-be3d6e422f93