misp-circl-feed/feeds/circl/misp/5845344a-80bc-4c94-9ea8-4f39950d210f.json

773 lines
26 KiB
JSON
Raw Permalink Normal View History

2023-04-21 13:25:09 +00:00
{
2023-12-14 14:30:15 +00:00
"Event": {
"analysis": "2",
"date": "2015-06-24",
"extends_uuid": "",
"info": "OSINT - MMD-0033-2015 - Linux/XorDDoS infection incident report (CNC: HOSTASA.ORG)",
"publish_timestamp": "1518770889",
"published": true,
"threat_level_id": "3",
"timestamp": "1515812443",
"uuid": "5845344a-80bc-4c94-9ea8-4f39950d210f",
"Orgc": {
"name": "CIRCL",
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
},
"Tag": [
{
"colour": "#004646",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "type:OSINT",
"relationship_type": ""
},
{
"colour": "#ffffff",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "tlp:white",
"relationship_type": ""
}
],
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": false,
"type": "link",
"uuid": "58453471-130c-4e59-bd91-43e3950d210f",
"value": "http://blog.malwaremustdie.org/2015/06/mmd-0033-2015-linuxxorddos-infection_23.html"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": false,
"type": "comment",
"uuid": "584534e9-6130-4419-8a7e-480e950d210f",
"value": "Background\r\nThis post is an actual malware infection incident of the\"Linux/XOR.DDoS\" malware (please see previous post as reference-->[LINK]) and malware was in attempt to infect a real Linux server.\r\n\r\nIncident details:\r\n\r\nSource of attack:\r\nAn attack was coming from 107.182.141.40 with the below GeoIP details:\r\nThe attacker was compromising a Linux host via ssh password bruting to then executing a one liner shell (sh) command line and then the malware initiation commands was executed on the compromised system:"
},
{
"category": "Network activity",
"comment": "On port 41625",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "ip-dst",
"uuid": "584535cc-3170-42af-a962-46f0950d210f",
"value": "107.182.141.40"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "domain",
"uuid": "584535cc-7c64-47d1-bece-41cd950d210f",
"value": "44ro4.cn"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "ip-dst",
"uuid": "584535cc-55c0-45a4-845f-444f950d210f",
"value": "198.15.234.66"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "ip-dst",
"uuid": "584535cc-09f8-4ff3-b148-4f0a950d210f",
"value": "103.240.140.152"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "ip-dst",
"uuid": "584535cd-8664-47ce-ac71-4edb950d210f",
"value": "103.240.141.54"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "ip-dst",
"uuid": "584535cd-feb0-4d4d-a5df-48df950d210f",
"value": "192.126.126.64"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "ip-dst",
"uuid": "584535cd-a058-4e65-950c-4b2d950d210f",
"value": "23.234.60.143"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "hostname",
"uuid": "584535cd-7c0c-447d-a65a-4a97950d210f",
"value": "aa.hostasa.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "hostname",
"uuid": "584535cd-df28-43d2-b262-480c950d210f",
"value": "ns4.hostasa.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "hostname",
"uuid": "584535ce-b260-4fe1-a494-4ed3950d210f",
"value": "ns3.hostasa.org"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1515750274",
"to_ids": true,
"type": "hostname",
"uuid": "584535ce-d284-492d-ad13-4854950d210f",
"value": "ns2.hostasa.org"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1480930766",
"to_ids": true,
"type": "filename|md5",
"uuid": "584535ce-dc00-43a9-a9f0-47e0950d210f",
"value": "a06.zip|3c49b5160b981f06bd5242662f8d0a54"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1480930766",
"to_ids": true,
"type": "filename|md5",
"uuid": "584535ce-062c-4524-883e-4266950d210f",
"value": "a07.zip|bcb6b83a4e6e20ffe0ce3c750360ddf5"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1480930767",
"to_ids": true,
"type": "filename|md5",
"uuid": "584535cf-641c-411a-b5e6-412f950d210f",
"value": "a08.zip|a99c10cb9713770b9e7dda376cddee3a"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1480930767",
"to_ids": true,
"type": "filename|md5",
"uuid": "584535cf-5070-4869-9b6e-43e4950d210f",
"value": "a09.zip|d1b5b4b4b5a118e384c7ff487e14ac3f"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1480930768",
"to_ids": true,
"type": "filename|md5",
"uuid": "584535d0-0390-464c-ac22-4afd950d210f",
"value": "a10.zip|83eea5625ca2affd3e841d3b374e88eb"
}
],
"Object": [
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "7",
"timestamp": "1515750277",
"uuid": "a2f1551a-ffc6-439a-8ed9-5eb83308cc80",
"ObjectReference": [
{
"comment": "",
"object_uuid": "a2f1551a-ffc6-439a-8ed9-5eb83308cc80",
"referenced_uuid": "8c404d5c-48e0-4cb4-a64d-2b89af2399ee",
2023-04-21 13:25:09 +00:00
"relationship_type": "analysed-with",
2023-12-14 14:30:15 +00:00
"timestamp": "1518770889",
"uuid": "5a588383-c360-467b-879b-48e102de0b81"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha1",
"timestamp": "1515750274",
"to_ids": true,
"type": "sha1",
"uuid": "5a588382-4300-49ec-b8b3-441f02de0b81",
"value": "c50933e1f8a194e608049839707d8d698dd5caa5"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1515750274",
"to_ids": true,
"type": "md5",
"uuid": "5a588382-f47c-4364-b7cb-4edf02de0b81",
"value": "3c49b5160b981f06bd5242662f8d0a54"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1515750274",
"to_ids": true,
"type": "sha256",
"uuid": "5a588382-8f60-4902-8f7d-405002de0b81",
"value": "c394440c56fdcda9739fbb966e9ac2eab9e11e2eeff0720eb4c850a05b33eefc"
}
]
},
{
"comment": "",
"deleted": false,
"description": "VirusTotal report",
"meta-category": "misc",
"name": "virustotal-report",
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
"template_version": "1",
"timestamp": "1515750274",
"uuid": "8c404d5c-48e0-4cb4-a64d-2b89af2399ee",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "permalink",
"timestamp": "1515750274",
"to_ids": false,
"type": "link",
"uuid": "5a588382-5a9c-4f0e-8ee9-4a1e02de0b81",
"value": "https://www.virustotal.com/file/c394440c56fdcda9739fbb966e9ac2eab9e11e2eeff0720eb4c850a05b33eefc/analysis/1495044102/"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "detection-ratio",
"timestamp": "1515750274",
"to_ids": false,
"type": "text",
"uuid": "5a588382-47d4-494f-a42c-484b02de0b81",
"value": "41/55"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "last-submission",
"timestamp": "1515750274",
"to_ids": false,
"type": "datetime",
"uuid": "5a588382-2fe4-4634-a2d8-4fd302de0b81",
"value": "2017-05-17T18:01:42"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "7",
"timestamp": "1515750277",
"uuid": "075320ce-9dca-48cd-a4ca-085096e80a7a",
"ObjectReference": [
{
"comment": "",
"object_uuid": "075320ce-9dca-48cd-a4ca-085096e80a7a",
"referenced_uuid": "e865f3a2-beea-4193-a717-991bbb031ae0",
2023-04-21 13:25:09 +00:00
"relationship_type": "analysed-with",
2023-12-14 14:30:15 +00:00
"timestamp": "1518770889",
"uuid": "5a588383-42f0-4318-b8f2-405102de0b81"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha1",
"timestamp": "1515750274",
"to_ids": true,
"type": "sha1",
"uuid": "5a588382-8034-47e0-b5d0-455e02de0b81",
"value": "038b7e9406fe5cb0a0be8f95ac935923c6d83c28"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1515750274",
"to_ids": true,
"type": "md5",
"uuid": "5a588382-3e94-40cb-b1b2-435a02de0b81",
"value": "d1b5b4b4b5a118e384c7ff487e14ac3f"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1515750274",
"to_ids": true,
"type": "sha256",
"uuid": "5a588383-11cc-459d-bbac-481802de0b81",
"value": "0a312a4154dcec2bc6ce1d3b51c037b122ace5848ec99c2b861ab6124addae9b"
}
]
},
{
"comment": "",
"deleted": false,
"description": "VirusTotal report",
"meta-category": "misc",
"name": "virustotal-report",
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
"template_version": "1",
"timestamp": "1515750275",
"uuid": "e865f3a2-beea-4193-a717-991bbb031ae0",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "permalink",
"timestamp": "1515750275",
"to_ids": false,
"type": "link",
"uuid": "5a588383-6004-4f2d-928d-4ffd02de0b81",
"value": "https://www.virustotal.com/file/0a312a4154dcec2bc6ce1d3b51c037b122ace5848ec99c2b861ab6124addae9b/analysis/1494973480/"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "detection-ratio",
"timestamp": "1515750275",
"to_ids": false,
"type": "text",
"uuid": "5a588383-cc48-4b4e-acfc-458302de0b81",
"value": "39/56"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "last-submission",
"timestamp": "1515750275",
"to_ids": false,
"type": "datetime",
"uuid": "5a588383-f040-4fc0-8f07-47e202de0b81",
"value": "2017-05-16T22:24:40"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "7",
"timestamp": "1515750278",
"uuid": "dcb939f0-8874-48f7-bce3-b8bbad431c41",
"ObjectReference": [
{
"comment": "",
"object_uuid": "dcb939f0-8874-48f7-bce3-b8bbad431c41",
"referenced_uuid": "63ddf759-d832-4a3d-a389-1462c56dc4cb",
2023-04-21 13:25:09 +00:00
"relationship_type": "analysed-with",
2023-12-14 14:30:15 +00:00
"timestamp": "1518770889",
"uuid": "5a588384-ce44-45ce-96b2-4d5902de0b81"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha1",
"timestamp": "1515750275",
"to_ids": true,
"type": "sha1",
"uuid": "5a588383-7cb0-426b-b008-47fd02de0b81",
"value": "dca946f677a1be95fb3ef6adc950730b4736a405"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1515750275",
"to_ids": true,
"type": "md5",
"uuid": "5a588383-1880-4239-84f8-489402de0b81",
"value": "83eea5625ca2affd3e841d3b374e88eb"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1515750275",
"to_ids": true,
"type": "sha256",
"uuid": "5a588383-6c08-4cb0-a7a1-4db802de0b81",
"value": "fd6060b963d1b5ca7a07b5a283ad99105298a6708e44d286440a506738a17e34"
}
]
},
{
"comment": "",
"deleted": false,
"description": "VirusTotal report",
"meta-category": "misc",
"name": "virustotal-report",
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
"template_version": "1",
"timestamp": "1515750275",
"uuid": "63ddf759-d832-4a3d-a389-1462c56dc4cb",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "permalink",
"timestamp": "1515750275",
"to_ids": false,
"type": "link",
"uuid": "5a588383-b518-43b4-a9c0-461202de0b81",
"value": "https://www.virustotal.com/file/fd6060b963d1b5ca7a07b5a283ad99105298a6708e44d286440a506738a17e34/analysis/1495062664/"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "detection-ratio",
"timestamp": "1515750275",
"to_ids": false,
"type": "text",
"uuid": "5a588383-8f60-4231-a75c-45bf02de0b81",
"value": "42/57"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "last-submission",
"timestamp": "1515750275",
"to_ids": false,
"type": "datetime",
"uuid": "5a588383-d874-40f3-aaeb-403602de0b81",
"value": "2017-05-17T23:11:04"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "7",
"timestamp": "1515750278",
"uuid": "4af33ce3-3a10-4c2e-bcb2-67bd4626e18b",
"ObjectReference": [
{
"comment": "",
"object_uuid": "4af33ce3-3a10-4c2e-bcb2-67bd4626e18b",
"referenced_uuid": "c976c2d7-cfaf-48b4-bd93-827f80aa378b",
2023-04-21 13:25:09 +00:00
"relationship_type": "analysed-with",
2023-12-14 14:30:15 +00:00
"timestamp": "1518770889",
"uuid": "5a588384-4350-4553-b6ae-42ce02de0b81"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha1",
"timestamp": "1515750275",
"to_ids": true,
"type": "sha1",
"uuid": "5a588383-4cd0-4309-bb97-426002de0b81",
"value": "1f1dd4d74eba8949fb1d2316c13f77b3ffa96f98"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1515750275",
"to_ids": true,
"type": "md5",
"uuid": "5a588383-47a0-4513-8421-4d2602de0b81",
"value": "a99c10cb9713770b9e7dda376cddee3a"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1515750275",
"to_ids": true,
"type": "sha256",
"uuid": "5a588383-3544-47be-8042-4c2402de0b81",
"value": "92a260d856e00056469fb26f5305a37f6ab443d735d1476281b053b10b3c4f86"
}
]
},
{
"comment": "",
"deleted": false,
"description": "VirusTotal report",
"meta-category": "misc",
"name": "virustotal-report",
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
"template_version": "1",
"timestamp": "1515750275",
"uuid": "c976c2d7-cfaf-48b4-bd93-827f80aa378b",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "permalink",
"timestamp": "1515750275",
"to_ids": false,
"type": "link",
"uuid": "5a588383-0dc8-446d-bf84-405502de0b81",
"value": "https://www.virustotal.com/file/92a260d856e00056469fb26f5305a37f6ab443d735d1476281b053b10b3c4f86/analysis/1495027397/"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "detection-ratio",
"timestamp": "1515750275",
"to_ids": false,
"type": "text",
"uuid": "5a588383-7a18-4f91-82a5-4c7202de0b81",
"value": "40/57"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "last-submission",
"timestamp": "1515750275",
"to_ids": false,
"type": "datetime",
"uuid": "5a588383-bce4-46b2-a6eb-401f02de0b81",
"value": "2017-05-17T13:23:17"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "7",
"timestamp": "1515750278",
"uuid": "f3c99c36-0463-4296-80ff-5c8407bd7d95",
"ObjectReference": [
{
"comment": "",
"object_uuid": "f3c99c36-0463-4296-80ff-5c8407bd7d95",
"referenced_uuid": "176aed31-3194-43c2-90ce-8711f4450e5d",
2023-04-21 13:25:09 +00:00
"relationship_type": "analysed-with",
2023-12-14 14:30:15 +00:00
"timestamp": "1518770889",
"uuid": "5a588384-e73c-4a06-9fb9-494e02de0b81"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha1",
"timestamp": "1515750275",
"to_ids": true,
"type": "sha1",
"uuid": "5a588383-83d0-4abd-af69-404702de0b81",
"value": "d88755b78834e87418aa3cb3bfee5de5c378bd2f"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1515750275",
"to_ids": true,
"type": "md5",
"uuid": "5a588383-fb44-4893-9a90-476702de0b81",
"value": "bcb6b83a4e6e20ffe0ce3c750360ddf5"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1515750275",
"to_ids": true,
"type": "sha256",
"uuid": "5a588383-1e04-4d75-845c-4d3702de0b81",
"value": "61b0107a7a06ecbb8cc1d323967291d15450df7e8bab5d96c822a98c9399a521"
}
]
},
{
"comment": "",
"deleted": false,
"description": "VirusTotal report",
"meta-category": "misc",
"name": "virustotal-report",
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
"template_version": "1",
"timestamp": "1515750275",
"uuid": "176aed31-3194-43c2-90ce-8711f4450e5d",
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "permalink",
"timestamp": "1515750275",
"to_ids": false,
"type": "link",
"uuid": "5a588383-a874-4dbe-9820-466402de0b81",
"value": "https://www.virustotal.com/file/61b0107a7a06ecbb8cc1d323967291d15450df7e8bab5d96c822a98c9399a521/analysis/1495007597/"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "detection-ratio",
"timestamp": "1515750275",
"to_ids": false,
"type": "text",
"uuid": "5a588383-e9b0-4feb-ab0c-40d802de0b81",
"value": "42/57"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "last-submission",
"timestamp": "1515750275",
"to_ids": false,
"type": "datetime",
"uuid": "5a588383-8f98-40a9-a0a8-41e502de0b81",
"value": "2017-05-17T07:53:17"
}
]
}
2023-04-21 13:25:09 +00:00
]
2023-12-14 14:30:15 +00:00
}
2023-04-21 13:25:09 +00:00
}