misp-circl-feed/feeds/circl/misp/5d9aedea-94c8-4c33-a80d-2bc1950d210f.json

394 lines
34 KiB
JSON
Raw Permalink Normal View History

2023-04-21 13:25:09 +00:00
{
2023-12-14 14:30:15 +00:00
"Event": {
"analysis": "0",
"date": "2019-10-03",
"extends_uuid": "",
"info": "OSINT - #EmissaryPanda #APT older sample (2018)",
"publish_timestamp": "1575970236",
"published": true,
"threat_level_id": "3",
"timestamp": "1575970217",
"uuid": "5d9aedea-94c8-4c33-a80d-2bc1950d210f",
"Orgc": {
"name": "CIRCL",
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
},
"Tag": [
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Threat Group-3390\"",
"relationship_type": ""
},
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Threat Group-3390 - G0027\"",
"relationship_type": ""
},
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:mitre-intrusion-set=\"Threat Group-3390\"",
"relationship_type": ""
},
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:mitre-intrusion-set=\"Threat Group-3390 - G0027\"",
"relationship_type": ""
},
{
"colour": "#10c700",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:threat-actor=\"Emissary Panda\"",
"relationship_type": ""
},
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:threat-actor=\"LuckyMouse\"",
"relationship_type": ""
},
{
"colour": "#14f800",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:threat-actor=\"Threat Group-3390\"",
"relationship_type": ""
},
{
"colour": "#002642",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "osint:source-type=\"microblog-post\"",
"relationship_type": ""
},
{
"colour": "#004646",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "type:OSINT",
"relationship_type": ""
},
{
"colour": "#0071c3",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "osint:lifetime=\"perpetual\"",
"relationship_type": ""
},
{
"colour": "#0087e8",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "osint:certainty=\"50\"",
"relationship_type": ""
},
{
"colour": "#ffffff",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "tlp:white",
"relationship_type": ""
}
],
"Attribute": [
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1570437695",
"to_ids": true,
"type": "hostname",
"uuid": "5d9afa3f-1dcc-4d8d-ab0c-4d53950d210f",
"value": "tdjsyqty0takah2x.gitoos.com"
},
{
"category": "External analysis",
"comment": "",
"data": "/9j/4AAQSkZJRgABAQAAAQABAAD/2wBDAAUDBAQEAwUEBAQFBQUGBwwIBwcHBw8LCwkMEQ8SEhEPERETFhwXExQaFRERGCEYGh0dHx8fExciJCIeJBweHx7/2wBDAQUFBQcGBw4ICA4eFBEUHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh4eHh7/wgARCAG2AsADASIAAhEBAxEB/8QAHAABAAMBAQEBAQAAAAAAAAAAAAQFBgMHAgEI/8QAGQEBAQEBAQEAAAAAAAAAAAAAAAIBAwQF/9oADAMBAAIQAxAAAAH2UAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAgE9U2R0ApO3l3bhr+uTi9/P7F2x2x8XuBoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAGWyHOR7PFV3/1SVHrffP6Dw/QznnvqfmXq8d3Aicamx9P849H4+joOPYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAADzes9E869fjsM9YWd89LpYE/w/QZnTVnSMrJ2idq7QmgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACurjRfFdaEHrJFRZwsl0jVRYvGK1v7iNnm9AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAKq1yRn5s3QeiMTrqmFO75Wfs5nKuZF53JmU8sj6XGXRuwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAM3pOZibHhSdpsfqPqI23/SNx1Ltc7WJfDnO0cyXc7mkVNlWdBFAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAOfQc+nPHGxjefyek7ebBnRsT4nM3n0BWWapgTeOUrLvjwzPXl6FJ803fDtYKu0mj8qi2QpoIRNQvwnOPySELkWTl9n0AAh/hNAAAAAAAAAAAAAAAAAAAAAAABns5fw+szoF1CuazcedehcL+xmgAPOvRcFuS6znz+v8vhqsXa/P933ewZPn78UyBufkiwrYrjOq724j0mj/V0Vbe8py+z1r1rPnlMixvHhZZ2n7p6uFiLd02irIHGFbZt/OGA0AAAAAAAAAAAAAAAAAAAACHhfRo+5g+GuXlXsOXbnQAACtsh5p8+mce/DB6S8+5vn0q5ObLHOwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFfYNyum8MDWazhW2MVY2nm2kNKAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACozWhqTIXVd1NpjPRsCej/UaSAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAR/OPT6065qp4l7mLCfWbXpHkSBoAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD4+x8/QVM6RU9udsjyOVhmgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAU1VP5+nnwspGHivSHn19xq7kYfpjaM521es0NK841hdsZwzd0yPWp0XfF3U7dcKGoN4ztNubtn5TbZn6Fu+YW4Tomdg5uwZu33JrN/ubo2egGwYvXbnYNAAAAAAAAAAAAAAAAAAAAAAAovq4xnSZmL6SKWEvYd+FYyNr+Jlaz0is3KT92tOqhp/Q4LKXrrk757E9NXOA+94nfPL7StYeP6AZh5urN8+530ttXy2pOG+N4zcL12qsxX1s07j+msGI1E9UhlAAAAAAAAAAAAAAAAAAAAAAAPn6Eb5liot8V5ef0KgRC6QJ4AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABx8n9V88Pu3vhidFwoj0xGkgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAFfktz5obC/wAtanzmNV56egWsOWfqL3PsAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAACtsh5lI9EjHnGtve5Q0Fh536M1feo0Hm9+msMfsHkDYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAzNPssXPq7dK/wDefsm7bLavr8wNgAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABy6in/bcfH2AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAH//xAAwEAACAwABAgUBBgcBAQAAAAADBAECBQATYAYQERIUFRYgISIwUCMkMTI0NTaQM//aAAgBAQABBQL/AM12nqjkumWsr7FfURKkp2cVoApq+vPKXrevlpG6S8NXmKJzbnshZjLN0y9m67vSk7Xtkl24jMOYfBXgg+bXEI9jHHorIMu8zQc+tOzNm03umGtB2iLVF/LtZF/ycfD1gP1iLUer7JgrVskFo4OPSnZmmv8AmSN+BC0pW1rlPkx+PlpJhKW2V05GmTii0C7O0FfkUZQYgo0vxkdawmLpj8o/Podo2rW0fFDyAjiBTKxLWrWLPLxxJgPr2cdsQefU+AcCX7j1hwtHynCDyI4XJJWFWTLGpaL17L0D9EdrXtYKJiySChJmMSSnltFvJbx8UyRQ2s3dCF60uZDGN7qdl60/zWaL356YqDjXr+RP1knxOfDpw0QPS05rXQTLn1u2fGldDSgTHh71rTsvXHPuzG4VI2SkE0G+uNKvqWP6c215maWaZKlDISO3KZUIKpq5JjG2+y71rerSF6zK1fUYLTxJbpx5Nz1bsqHXLTTdrwmg+WAKWvzPygKpdUq/K2ravZc0rPIpWPKb0jjJukNUPSpy64bchUUcrStfOy8jsFiLW/pwr4acrpU9QmGWOx72rSjj17z1fxAx7CKMVOP75hULV4pIhdZOubqe2VM9q/IaDAPqCHmPRQISjArM+VTilpVgLQTNLAsIgy1sUdSGZWBNHU73vatKR+P3W2BKr3YFVj9w2L/guDr8QHMzrAj35hfab9Ak+vJs5C64Luug68NoiAyIaCGlpOaVs99yuhoYGe5lFLHy/tEtpmGIz+gsmD/qPCn+k1joA8S4ECLqvDI6Xoo6IfCqSf0jxL/oHG2F5G1oC1lXHniN/UZ8UOfUPfoNlc8KM/8AR0ddbtOsxdJT5XR/bdiPz4tqepTStZ8g/jJ19vKf2ffcH0iA0GhZUhNGlnR6Gdro2SWY0lgPoG1GVb6i+e5R3TIsAtdomcU9wK19owFjewAGVzPjm+0HReRur4ayqr4K7Ca/h9cquRthIxkNLGu00AxNnWWK9V0TYdc6ZLan05uPDp1zW2hZ8KXMoW0ftzQYOEwiDKVly9Z6hOIhm14/CPvuLVYpfPOAXsY96SNouEZEa0tW9OxiiGWL51OUQiJGOtI/SkVJ5Wta+Vw3FZc1DV7XOD32CeZte1aVJojiY0p4B0JO1GRjIN9w1rrYAbVvhZF6v57GbXIcg1O0tS/tV8MC6jAt7R+1virRYg2FVqmStT4OrWfWO0deP4Hha/8AK+KMxlZ+PF2Z0lTiZXZv1N5f/wCPaJxwUXuLmaCjIGwveG8lwrba2QolYarA49KdpNq0PB8m4yyu5aA51ghzcs2fwRKlp2p7a8iIjyLS4SCJQo+1yjuIgiUKPtdqsrzL7Jp6uiKibtDx5dQcE/Tgg5J5DIO89hbE+vLL+rDNYqsS3Qe13XKcZ0DBrS7V/Eq7qyeeRrSCBjREPILoH+So+0UuVp6FMZ9+i2fSltPTXO0tHh9h0uPbQcAf5AldsTLZERPsxoZ5maOIszqZzq/wHSaEA0c1q7gCuns6y/LONqNPi2mHzQ0po+4n1RyUy6U2OrZiw7vsEbZfMHirxpfHquHVtsMzmh
"deleted": false,
"disable_correlation": false,
"timestamp": "1570437775",
"to_ids": false,
"type": "attachment",
"uuid": "5d9afa8f-bf60-44be-97a6-4a85950d210f",
"value": "EF9924EW4AA9T0J.jpeg"
}
],
"Object": [
{
"comment": "",
"deleted": false,
"description": "Microblog post like a Twitter tweet or a post on a Facebook wall.",
"meta-category": "misc",
"name": "microblog",
"template_uuid": "8ec8c911-ddbe-4f5b-895b-fbff70c42a60",
"template_version": "8",
"timestamp": "1570437821",
"uuid": "5d9aeef4-0cb0-4799-8c8a-42a1950d210f",
"ObjectReference": [
{
"comment": "",
"object_uuid": "5d9aeef4-0cb0-4799-8c8a-42a1950d210f",
"referenced_uuid": "5d9afa8f-bf60-44be-97a6-4a85950d210f",
2023-04-21 13:25:09 +00:00
"relationship_type": "contains",
2023-12-14 14:30:15 +00:00
"timestamp": "1570437821",
"uuid": "5d9afabd-fc34-42e1-8c80-4a0a950d210f"
}
],
"Attribute": [
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "post",
"timestamp": "1570434804",
"to_ids": false,
"type": "text",
"uuid": "5d9aeef4-595c-414b-96ea-42a1950d210f",
"value": "#EmissaryPanda #APT older sample (2018). Signed by same company as my prior post \"Hangzhou Bianfeng Networking technology Co., Ltd.\" + previously unreported C2.\r\n \r\nIOCS:\r\n931017406b4718d81d2c776165e6ddf0\r\ntdjsyqty0takah2x[.]gitoos[.]com\r\n \r\n#threatintel #apt27"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "link",
"timestamp": "1570434804",
"to_ids": false,
"type": "link",
"uuid": "5d9aeef4-3d00-4b6c-9bc1-42a1950d210f",
"value": "https://mobile.twitter.com/MeltX0R/status/1179800013150527488"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "type",
"timestamp": "1570434804",
"to_ids": false,
"type": "text",
"uuid": "5d9aeef4-e134-43d2-904b-42a1950d210f",
"value": "Twitter"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "hashtag",
"timestamp": "1570434804",
"to_ids": false,
"type": "text",
"uuid": "5d9aeef4-8994-4fb6-8e1c-42a1950d210f",
"value": "#EmissaryPanda"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "hashtag",
"timestamp": "1570434804",
"to_ids": false,
"type": "text",
"uuid": "5d9aeef4-cfb0-4f85-a28d-42a1950d210f",
"value": "#APT"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "hashtag",
"timestamp": "1570434804",
"to_ids": false,
"type": "text",
"uuid": "5d9aeef4-bd70-468e-999e-42a1950d210f",
"value": "#threatintel"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "hashtag",
"timestamp": "1570434804",
"to_ids": false,
"type": "text",
"uuid": "5d9aeef4-11d0-4b0d-b4c7-42a1950d210f",
"value": "#apt27"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "username",
"timestamp": "1570434804",
"to_ids": false,
"type": "text",
"uuid": "5d9aeef4-acb8-44d2-aae7-42a1950d210f",
"value": "MeltX0R"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "state",
"timestamp": "1570434804",
"to_ids": false,
"type": "text",
"uuid": "5d9aeef4-7b80-42de-a564-42a1950d210f",
"value": "Informative"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "creation-date",
"timestamp": "1570434804",
"to_ids": false,
"type": "datetime",
"uuid": "5d9aeef4-fc20-46cb-a270-42a1950d210f",
"value": "2019-10-03T18:46:00"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "17",
"timestamp": "1570437487",
"uuid": "5d9af96f-24e0-4014-be2f-4265950d210f",
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1570437487",
"to_ids": true,
"type": "md5",
"uuid": "5d9af96f-ad84-4b6f-85db-4265950d210f",
"value": "931017406b4718d81d2c776165e6ddf0"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "17",
"timestamp": "1575970216",
"uuid": "5c1edbfb-5054-4688-9723-151cdf91c0b4",
"ObjectReference": [
{
"comment": "",
"object_uuid": "5c1edbfb-5054-4688-9723-151cdf91c0b4",
"referenced_uuid": "a76a6401-f89d-4551-9e72-8eb90b7478e0",
2023-04-21 13:25:09 +00:00
"relationship_type": "analysed-with",
2023-12-14 14:30:15 +00:00
"timestamp": "1575970217",
"uuid": "5def65a9-6e18-468a-9744-4c9e950d210f"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1570437487",
"to_ids": true,
"type": "md5",
"uuid": "4abd7370-d467-45be-9461-920951a77873",
"value": "931017406b4718d81d2c776165e6ddf0"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha1",
"timestamp": "1570437487",
"to_ids": true,
"type": "sha1",
"uuid": "65498071-fa1c-4173-817f-335497ca40d3",
"value": "6bfabe6eea3be2e59bc52bd69c64be7706e7a391"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1570437487",
"to_ids": true,
"type": "sha256",
"uuid": "e85b8ef7-423e-4b7d-9ebc-7e73fc8b331c",
"value": "ce3424524fd1f482a0339a3f92e440532cff97c104769837fa6ae52869013558"
}
]
},
{
"comment": "",
"deleted": false,
"description": "VirusTotal report",
"meta-category": "misc",
"name": "virustotal-report",
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
"template_version": "2",
"timestamp": "1575970216",
"uuid": "a76a6401-f89d-4551-9e72-8eb90b7478e0",
"Attribute": [
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "last-submission",
"timestamp": "1570437487",
"to_ids": false,
"type": "datetime",
"uuid": "dba6fe13-e310-4cfa-b4d7-abd86cd0949a",
"value": "2019-11-20T12:18:04"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "permalink",
"timestamp": "1570437487",
"to_ids": false,
"type": "link",
"uuid": "2ce963a0-7511-4b17-a435-b246d0c770ca",
"value": "https://www.virustotal.com/file/ce3424524fd1f482a0339a3f92e440532cff97c104769837fa6ae52869013558/analysis/1574252284/"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "detection-ratio",
"timestamp": "1570437487",
"to_ids": false,
"type": "text",
"uuid": "8489f7db-a48a-434f-b9c6-a93530e54137",
"value": "19/67"
}
]
}
2023-04-21 13:25:09 +00:00
]
2023-12-14 14:30:15 +00:00
}
2023-04-21 13:25:09 +00:00
}