KoffeyMaker: notebook vs. ATM
Indicators of compromiseauto-extracted · verify before use · export allAll →
| Type | Indicator | Context |
|---|---|---|
| md5 | 0bcb612e6c705f8ba0a9527598bbf3f3 | 410a89c6d0379dc56c85d9daf0 d7b647f5bcd459eb395e8c4a09353f0d 0bcb612e6c705f8ba0a9527598bbf3f3 ae962a624866391a4321c21656737dcb 83ac7fdba166519b29bb2a2a3a |
| md5 | 2e90763ac4413eb815c45ee044e13a43 | aad19596cca380fd02ab036eb2 9a587ac619f0184bad123164f2aa97ca 2e90763ac4413eb815c45ee044e13a43 b60e43d869b8d2a0071f8a2c0ce371aa 3d1da9b83fe5ef07017cf2b97d |
| md5 | 3d1da9b83fe5ef07017cf2b97ddc76f1 | 3ac4413eb815c45ee044e13a43 b60e43d869b8d2a0071f8a2c0ce371aa 3d1da9b83fe5ef07017cf2b97ddc76f1 45d4f8b3ed5a41f830f2d3ace3c2b031 f2c434120bec3fb47adce00027 |
| md5 | 45d4f8b3ed5a41f830f2d3ace3c2b031 | d869b8d2a0071f8a2c0ce371aa 3d1da9b83fe5ef07017cf2b97ddc76f1 45d4f8b3ed5a41f830f2d3ace3c2b031 f2c434120bec3fb47adce00027c2b35e 8fc365663541241ad626183d6a |
| md5 | 46972ca1a08cfa1506d760e085c71c20 | 9b29bb2a2a3ab480f8 Drivers 84c29dfad3f667502414e50a9446ed3f 46972ca1a08cfa1506d760e085c71c20 ff3e0881aa352351e405978e066d9796 4ea7a6ca093a9118df931ad749 |
| md5 | 49c708aad19596cca380fd02ab036eb2 | m the Carbanak group . Hash sums KDIAG, incl. patched files 49c708aad19596cca380fd02ab036eb2 9a587ac619f0184bad123164f2aa97ca 2e90763ac4413eb815c45ee044 |
| md5 | 4ea7a6ca093a9118df931ad7492cfed5 | a1a08cfa1506d760e085c71c20 ff3e0881aa352351e405978e066d9796 4ea7a6ca093a9118df931ad7492cfed5 a8da5b44f926c7f7d11f566967a73a32 f046dc9e38024ab15a4de1bbfe |
| md5 | 6677722da6a071499e2308a121b9051d | 120bec3fb47adce00027c2b35e 8fc365663541241ad626183d6a48882a 6677722da6a071499e2308a121b9051d a731270f952f654b9c31850e9543f4ad b925ce410a89c6d0379dc56c85 |
| md5 | 83ac7fdba166519b29bb2a2a3ab480f8 | 2e6c705f8ba0a9527598bbf3f3 ae962a624866391a4321c21656737dcb 83ac7fdba166519b29bb2a2a3ab480f8 Drivers 84c29dfad3f667502414e50a9446ed3f 46972ca1a08cfa1506 |
| md5 | 84c29dfad3f667502414e50a9446ed3f | 1a4321c21656737dcb 83ac7fdba166519b29bb2a2a3ab480f8 Drivers 84c29dfad3f667502414e50a9446ed3f 46972ca1a08cfa1506d760e085c71c20 ff3e0881aa352351e405978e06 |
| md5 | 8fc365663541241ad626183d6a48882a | b3ed5a41f830f2d3ace3c2b031 f2c434120bec3fb47adce00027c2b35e 8fc365663541241ad626183d6a48882a 6677722da6a071499e2308a121b9051d a731270f952f654b9c31850e95 |
| md5 | 9a1a781fed629d1d0444a3ae3b6e2882 | 44f926c7f7d11f566967a73a32 f046dc9e38024ab15a4de1bbfe830701 9a1a781fed629d1d0444a3ae3b6e2882 YARA rule 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 2 |
| md5 | 9a587ac619f0184bad123164f2aa97ca | KDIAG, incl. patched files 49c708aad19596cca380fd02ab036eb2 9a587ac619f0184bad123164f2aa97ca 2e90763ac4413eb815c45ee044e13a43 b60e43d869b8d2a0071f8a2c0c |
| md5 | a731270f952f654b9c31850e9543f4ad | 663541241ad626183d6a48882a 6677722da6a071499e2308a121b9051d a731270f952f654b9c31850e9543f4ad b925ce410a89c6d0379dc56c85d9daf0 d7b647f5bcd459eb395e8c4a09 |
| md5 | a8da5b44f926c7f7d11f566967a73a32 | 81aa352351e405978e066d9796 4ea7a6ca093a9118df931ad7492cfed5 a8da5b44f926c7f7d11f566967a73a32 f046dc9e38024ab15a4de1bbfe830701 9a1a781fed629d1d0444a3ae3b |
| md5 | ae962a624866391a4321c21656737dcb | f5bcd459eb395e8c4a09353f0d 0bcb612e6c705f8ba0a9527598bbf3f3 ae962a624866391a4321c21656737dcb 83ac7fdba166519b29bb2a2a3ab480f8 Drivers 84c29dfad3f6675024 |
| md5 | b60e43d869b8d2a0071f8a2c0ce371aa | c619f0184bad123164f2aa97ca 2e90763ac4413eb815c45ee044e13a43 b60e43d869b8d2a0071f8a2c0ce371aa 3d1da9b83fe5ef07017cf2b97ddc76f1 45d4f8b3ed5a41f830f2d3ace3 |
| md5 | b925ce410a89c6d0379dc56c85d9daf0 | 2da6a071499e2308a121b9051d a731270f952f654b9c31850e9543f4ad b925ce410a89c6d0379dc56c85d9daf0 d7b647f5bcd459eb395e8c4a09353f0d 0bcb612e6c705f8ba0a9527598 |
| md5 | d7b647f5bcd459eb395e8c4a09353f0d | 0f952f654b9c31850e9543f4ad b925ce410a89c6d0379dc56c85d9daf0 d7b647f5bcd459eb395e8c4a09353f0d 0bcb612e6c705f8ba0a9527598bbf3f3 ae962a624866391a4321c21656 |
| md5 | f046dc9e38024ab15a4de1bbfe830701 | ca093a9118df931ad7492cfed5 a8da5b44f926c7f7d11f566967a73a32 f046dc9e38024ab15a4de1bbfe830701 9a1a781fed629d1d0444a3ae3b6e2882 YARA rule 1 2 3 4 5 6 7 8 |
| md5 | f2c434120bec3fb47adce00027c2b35e | b83fe5ef07017cf2b97ddc76f1 45d4f8b3ed5a41f830f2d3ace3c2b031 f2c434120bec3fb47adce00027c2b35e 8fc365663541241ad626183d6a48882a 6677722da6a071499e2308a121 |
| md5 | ff3e0881aa352351e405978e066d9796 | fad3f667502414e50a9446ed3f 46972ca1a08cfa1506d760e085c71c20 ff3e0881aa352351e405978e066d9796 4ea7a6ca093a9118df931ad7492cfed5 a8da5b44f926c7f7d11f566967 |
Full article632 words · extracted from securelist.com · click to collapse
04 Dec 2018
minute read
Despite CCTV and the risk of being caught by security staff, attacks on ATMs using a direct connection — so-called black box attacks — are still popular with cybercriminals. The main reason is the low “entry requirements” for would-be cyber-robbers: specialized sites offer both the necessary tools and how-to instructions.
Kaspersky Lab’ experts investigated one such toolkit, dubbed KoffeyMaker, in 2017-2018, when a number of Eastern European banks turned to us for assistance after their ATMs were quickly and almost freely raided. It soon became clear that we were dealing with a black box attack — a cybercriminal opened the ATM, connected a laptop to the cash dispenser, closed the ATM, and left the crime scene, leaving the device inside. Further investigation revealed the “crime instrument” to be a laptop with ATM dispenser drivers and a patched KDIAG tool; remote access was provided through a connection to a USB GPRS modem. The operating system was Windows, most likely XP, ME, or 7 for better driver compatibility.
ATM dispenser connected to a computer without the necessary drivers
The situation then unfolded according to the usual scenario: the cybercriminal returned at the appointed hour and pretended to use the ATM, while an accomplice remotely connected to the hidden laptop, ran the KDIAG tool, and instructed the dispenser to issue banknotes. The attacker took the money and later retrieved the laptop, too. The whole operation could well be done solo, but the scheme whereby a “mule” handles the cash and ATM side, while a second “jackpotter” provides technical support for a share of the loot, is more common. A single ATM can spit out tens of thousands of dollars, and only hardware encryption between an ATM PC and its dispenser can prevent an attack from occurring.
Overall, the attack was reminiscent of Cutlet Maker, which we described last year, except for the software tools. We were able to reproduce all the steps of KoffeyMaker in our test lab. All the required software was found without too much difficulty. Legitimate tools were used to carry out the attack with the exception of the patched KDIAG utility, which Kaspersky Lab products detect as RiskTool.Win32.DIAGK.a. Note that the same version of this program was previously used by cybercriminals from the Carbanak group.
Hash sums
KDIAG, incl. patched files
49c708aad19596cca380fd02ab036eb2
9a587ac619f0184bad123164f2aa97ca
2e90763ac4413eb815c45ee044e13a43
b60e43d869b8d2a0071f8a2c0ce371aa
3d1da9b83fe5ef07017cf2b97ddc76f1
45d4f8b3ed5a41f830f2d3ace3c2b031
f2c434120bec3fb47adce00027c2b35e
8fc365663541241ad626183d6a48882a
6677722da6a071499e2308a121b9051d
a731270f952f654b9c31850e9543f4ad
b925ce410a89c6d0379dc56c85d9daf0
d7b647f5bcd459eb395e8c4a09353f0d
0bcb612e6c705f8ba0a9527598bbf3f3
ae962a624866391a4321c21656737dcb
83ac7fdba166519b29bb2a2a3ab480f8
Drivers
84c29dfad3f667502414e50a9446ed3f
46972ca1a08cfa1506d760e085c71c20
ff3e0881aa352351e405978e066d9796
4ea7a6ca093a9118df931ad7492cfed5
a8da5b44f926c7f7d11f566967a73a32
f046dc9e38024ab15a4de1bbfe830701
9a1a781fed629d1d0444a3ae3b6e2882
YARA rule
|
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 |
rulesoftware_zz_patched_KDIAG { meta: author="Kaspersky Lab" filetype="PE" date="2018-04-28" version="1.0" hash="49c708aad19596cca380fd02ab036eb2" strings: $b0={2580000000EB13FF75EC} $b1={EB1F8D85FC FE FF FF50687B2F0000} $s0="@$MOD$ 040908 0242/0000 CRS1.EXE W32 Copyright (c) Wincor Nixdorf" condition: ( uint16(0)==0x5A4Dand all of($s*)and all of($b*) ) } |
Latest Webinars
Reports
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
Kaspersky experts break down a new Armored Likho campaign that poses as a fundraising efforts and delivers a new Still Toolkit aimed at stealing Telegram data and eavesdropping on victims.
Kaspersky researchers reveal previously undocumented malware attributed to Mirage Kitten (UNC1549, Smoke Sandstorm, Nimbus Manticore): NightLedger backdoor, ArcBridge, and BridgeHead tunneling tools.
Text extracted automatically; images, tables and formatting may be missing. Original: https://securelist.com/koffeymaker-notebook-vs-atm/89161/