This report covers Pink Sandstorm's attacks, associated IOCs, and YARA rules for detection. It also highlights the malware and tools used by the group. It is not an in-depth analysis of Pink Sandstorm tactics and tools but a collection of indicators to help identify similar activity, focusing on recent operations.
Pink Sandstorm is an Iranian cyber threat group closely associated with the Iranian Ministry of Intelligence and Security (MOIS). Active since 2020, the group specializes in conducting cyberattacks using wipers and ransomware. The primary targets of Pink Sandstorm are organizations in Israel. However, their attacks have also been observed against entities in Hong Kong and South Africa.
Iran
Espionage
2020
Pink Sandstorm Targets Israeli Tech and Education Sectors
SHA-256: 5d1660a53aaf824739d82f703ed580004980d377bdc2834f1041d512e4305d07
SHA-256: f4c8369e4de1f12cc5a71eb5586b38fc78a9d8db2b189b8c25ef17a572d4d6b7
Sample: ANY.RUN
Pink Sandstorm Targets Israeli Tech and Education Sectors
Pink Sandstorm Targets Israeli Tech and Education Sectors
768ece399c75a27aca90313f625016e8e795f737667577d75af0042c896987f7Moneybird Attacks on Israeli Organizations
SHA-256: aa19839b1b6a846a847c5f4f2a2e8e634caeebeeff7af59865aecca1d7d9f43c
SHA-256: bc58d7ce32f93c74ab8032b19c5af4e45271a54d0071e93f8c4ea0eb23f16c01
Sample: ANY.RUN
Pink Sandstorm Targets Israeli Tech and Education Sectors
49c3df62c4b62ce8960558daea4a8cf41b11c8f445e218cd257970cf939a3c25Pink Sandstorm Targets Israeli Tech and Education Sectors
a8e63550b56178ae5198c9cc5b704a8be4c8505fea887792b6d911e488592a7c1ea4d26a31dad637d697f9fb70b6ed4d75a13d101e02e02bc00200b42353985c62e36675ed7267536bd980c07570829fe61136e53de3336eebadeca56ab060c2abfde7c29a4a703daa2b8ad2637819147de3a890fdd12da8279de51a3cc0d96d63d51bc3e5cf4068ff04bd3d665c101a003f1d6f52de7366f5a2d9ef5cc041a749c3df62c4b62ce8960558daea4a8cf41b11c8f445e218cd257970cf939a3c25dacdb4976fd75ab2fd7bb22f1b2f9d986f5d92c29555ce2b165c020e2816a200e43d66b7a4fa09a0714c573fbe4996770d9d85e31912480e73344124017098f92a6e3b6e42be2f55f7ab9db9d5790b0cc3f52bee9a1272fc4d79c7c0a3b6abda5d1660a53aaf824739d82f703ed580004980d377bdc2834f1041d512e4305d07f4c8369e4de1f12cc5a71eb5586b38fc78a9d8db2b189b8c25ef17a572d4d6b713d8d4f4fa483111e4372a6925d24e28f3be082a2ea8f44304384982bd692ec9a112e78e4f8b99b1ceddae44f34692be20ef971944b98e2def995c87d5ae89ee18c909a2b8c5e16821d6ef908f56881aa0ecceeaccb5fa1e54995935fcfd12f72fb88793f8571209c2fcf1be528ca1d59e7ac62e81e73ebb5a0d77b9d5a09cb89165d4f3036919a96b86d24b64d75d692802c7513f2b3054b20be40c212240a5f65880ef9fec17da4142850e5e7d40ebfc58671f5d66395809977dd5027a6a3e38e406b17715b1b52ed8d8e4defdb5b79a4ddea9a3381a9f2276b00449ec8835ec7dc5bfadce28b8a8944fb267642c6f713e5b19a9983d7c6f011ebe0f663097c52525cd7d05bddb3ee17eb1ad6b5d6670254252b28b18a1451f604dfff932a4a8e63550b56178ae5198c9cc5b704a8be4c8505fea887792b6d911e488592a7cC9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e 92804faaab2175dc501d73e814663058c78c0a042675a8937266357bcfb96c50 E61b8f44ab92cf0f9cb1101347967d31e1839979142a4114a7dd02aa237ba021 768ece399c75a27aca90313f625016e8e795f737667577d75af0042c896987f7185.105.46[.]34185.105.46[.]1993.188.207[.]110109.237.107[.]212217.29.62[.]16681.177.22[.]182Moneybird Attacks on Israeli Organizations
rule ransomware_moneybird {
meta:
author = "Marc Salinas @ Check Point Research"
description = "Detects a ransomware sample named Moneybird based on its pdb string."
malware_family = "MoneyBird"
date = "11/05/2023"
sample = "aa19839b1b6a846a847c5f4f2a2e8e634caeebeeff7af59865aecca1d7d9f43c"
strings:
$ran1 = "WE ARE MONEYBIRD!"
$ran2 = "All of your data encrypted!"
$ran3 = "ok.ru/profile"
$ext1 = "Shiftlibgcrypt"
$ext2 = "come to the aide of their"
$ext3 = "stopmarker" wide
$code1 = {44 89 4C 24 20 4C 89 44 24 18 48 89 54 24 10 89 4C 24 08 56 57 48 83 EC 78 48 8B 05 68 FE 1A 00 48 33 C4 48 89 44 24 60 48 8D 44 24 50 48 8D 0D DC 68 15 00 48 8B F8 48 8B F1 B9 10 00 00 00 F3 A4 45 33 C9 41 B8 09 00 00 00 BA 09 00 00 00 48 8D 4C 24 48 ?? ?? ?? ?? ?? 41 B8 20 00 00 00 48 8B 94 24 A0 00 00 00 48 8B 4C 24 48 ?? ?? ?? ?? ?? 48 8D 44 24 50 48 89 44 24 40 48 C7 44 24 30 FF FF FF FF}
$code2 = {48 FF 44 24 30 48 8B 44 24 40 48 8B 4C 24 30 80 3C 08 00}
$code3 = {48 8B 44 24 30 4C 8B C0 48 8D 54 24 50 48 8B 4C 24 48 ?? ?? ?? ?? ?? 8B 84 24 90 00 00 00 48 C7 44 24 20 00 00 00 00 45 33 C9 44 8B C0 48 8B 94 24 98 00 00 00 48 8B 4C 24 48 ?? ?? ?? ?? ?? 89 44 24 38 48 8B 4C 24 48 ?? ?? ?? ?? ?? 48 8B 4C 24 60 48 33 CC ?? ?? ?? ?? ?? 48 83 C4 78 5F 5E C3}
condition:
uint16(0) == 0x5A4D and (2 of ($ran*) or all of ($code*) or all of ($ext*))
rule autogen_peexe_Greyware_bc58d7ce
{
meta:
author = "FileScan.IO Engine v1.1.0-52ab799"
date = "2023-06-05"
sample = "bc58d7ce32f93c74ab8032b19c5af4e45271a54d0071e93f8c4ea0eb23f16c01"
score = 50
tags = "greyware"
isWeakRule = true
strings:
//IOC patterns
$req0 = "\"You cannot concatenate the same moved string to itself. See N4910 16.4.5.9 [res.on.arguments]/1.3: \" \"If a function argument is"
$req1 = "SOFTWARE\\Wow6432Node\\Microsoft\\VisualStudio\\14.0\\Setup\\VC"
//optional strings
$opt0 = "AdvAPI32.dll"
$opt1 = "NETAPI32.DLL"
$opt2 = "NTDll.dll"
$opt3 = "VCRUNTIME140D.dll"
$opt4 = "\\\\.\\PhysicalDrive%d"
$opt5 = "advapi32.dll"
$opt6 = "api-ms-win-core-registry-l1-1-0.dll"
$opt7 = "callback != nullptr"
$opt8 = "kernel32.dll"
$opt9 = "mscoree.dll"
condition:
//require 75% of optional strings
uint16(0) == 0x5A4D and filesize > 5938330 and filesize < 7257958 and all of ($req*) and 7 of ($opt*)
}
rule Agrius_Function_Names {
meta:
description = "Detects malware used by Agrius threat actor based on unique function names"
author = "Amitai B @ SentinelOne"
version = "1.0"
TLP = "White"
last_modified = "2021-05-11"
strings:
$s1 = "GetWindowsTempPath"
$s2 = "GetCurrentProcess"
$s3 = "GetOwnPath"
$s4 = "PublicFunction"
$s5 = "SelfDelete"
$s6 = "IsFirstInstance"
condition:
(filesize > 1KB and filesize < 300KB and 3 of ($s*))
}
https://ioc.one/auth/attribute/ff32dd96-191e-55e3-8614-be3d6e422f93
rule Agrius_Webshells {
meta:
description = "Detects variations of webshells used by Agrius"
author = "Amitai B @ SentinelOne"
version = "1.0"
TLP = "White"
last_modified = "2021-05-11"
strings:
$s1 = "public string base64ToStr(string instr)"
$s2 = "Process prcsss=new Process()"
$s3 = "<form id=\"PRIVATECode\" runat=\"server\">"
condition:
(filesize > 1KB and filesize < 150KB and any of them)
}