2023-04-21 13:25:09 +00:00
|
|
|
{
|
2023-12-14 14:30:15 +00:00
|
|
|
"Event": {
|
|
|
|
"analysis": "2",
|
|
|
|
"date": "2016-09-26",
|
|
|
|
"extends_uuid": "",
|
|
|
|
"info": "OSINT - Sofacy\u00e2\u20ac\u2122s \u00e2\u20ac\u02dcKomplex\u00e2\u20ac\u2122 OS X Trojan by Palo Alto networks",
|
|
|
|
"publish_timestamp": "1493035298",
|
|
|
|
"published": true,
|
|
|
|
"threat_level_id": "1",
|
|
|
|
"timestamp": "1493024705",
|
|
|
|
"uuid": "57ea2a19-2e44-4f1b-b6f5-46bb950d210f",
|
|
|
|
"Orgc": {
|
|
|
|
"name": "CIRCL",
|
|
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
|
|
},
|
|
|
|
"Tag": [
|
|
|
|
{
|
|
|
|
"colour": "#ffffff",
|
2024-04-05 12:15:17 +00:00
|
|
|
"local": false,
|
2023-12-14 14:30:15 +00:00
|
|
|
"name": "tlp:white",
|
|
|
|
"relationship_type": ""
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"colour": "#3a7300",
|
2024-04-05 12:15:17 +00:00
|
|
|
"local": false,
|
2023-12-14 14:30:15 +00:00
|
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
|
|
"relationship_type": ""
|
|
|
|
}
|
|
|
|
],
|
|
|
|
"Attribute": [
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O 64- bit executable x86_64",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964170",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha256",
|
|
|
|
"uuid": "57ea2aca-d6b4-4a2a-8b7a-4835950d210f",
|
|
|
|
"value": "2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O executable i386",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964170",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha256",
|
|
|
|
"uuid": "57ea2aca-0c44-4905-8c5b-48ed950d210f",
|
|
|
|
"value": "c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O universal binary with 2 architectures",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964170",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha256",
|
|
|
|
"uuid": "57ea2aca-d254-4810-ad80-4723950d210f",
|
|
|
|
"value": "cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964171",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha256",
|
|
|
|
"uuid": "57ea2acb-0058-4cd4-ae6d-4b97950d210f",
|
|
|
|
"value": "96a19a90caa41406b632a2046f3a39b5579fbf730aca2357f84bf23f2cbc1fd3"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964586",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "filename|sha256",
|
|
|
|
"uuid": "57ea2acb-5ed8-4d17-8ef7-40f0950d210f",
|
|
|
|
"value": "/Users/Shared/.local/kextd|227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964171",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha256",
|
|
|
|
"uuid": "57ea2acb-a1a8-4c60-bc5f-4e46950d210f",
|
|
|
|
"value": "45a93e4b9ae5bece0d53a3a9a83186b8975953344d4dfb340e9de0015a247c54"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964171",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57ea2acb-c6a8-44ec-9129-420b950d210f",
|
|
|
|
"value": "appleupdate.org"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964171",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57ea2acb-84bc-4a82-96f9-4644950d210f",
|
|
|
|
"value": "apple-iclouds.net"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964172",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "domain",
|
|
|
|
"uuid": "57ea2acc-0ce0-4327-826f-4044950d210f",
|
|
|
|
"value": "itunes-helper.net"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Network activity",
|
|
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964172",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "ip-dst",
|
|
|
|
"uuid": "57ea2acc-af3c-47ff-95ff-4ba2950d210f",
|
|
|
|
"value": "185.10.58.170"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload installation",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964665",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "filename|sha256",
|
|
|
|
"uuid": "57ea2cb9-1050-4ac7-9fb2-4e90950d210f",
|
|
|
|
"value": "/Users/Shared/com.apple.updates.plist|1f22e8f489abff004a3c47210a9642798e1c53efc9d6f333a1072af4b11d71ef"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload installation",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964665",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "filename|sha256",
|
|
|
|
"uuid": "57ea2cb9-1b0c-4920-a874-4a2b950d210f",
|
|
|
|
"value": "/Users/Shared/start.sh|d494e9f885ad2d6a2686424843142ddc680bb5485414023976b4d15e3b6be800"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload installation",
|
|
|
|
"comment": "- Xchecked via VT: d494e9f885ad2d6a2686424843142ddc680bb5485414023976b4d15e3b6be800",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964772",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "57ea2d24-d840-41a4-9525-4bf502de0b81",
|
|
|
|
"value": "827af860549b041baf8fa6c7bfe127d0bb8b2477"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload installation",
|
|
|
|
"comment": "- Xchecked via VT: d494e9f885ad2d6a2686424843142ddc680bb5485414023976b4d15e3b6be800",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964772",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "57ea2d24-7208-4486-a21a-486402de0b81",
|
|
|
|
"value": "368c912ea5463ead2ad4d35e4d3db640"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "- Xchecked via VT: d494e9f885ad2d6a2686424843142ddc680bb5485414023976b4d15e3b6be800",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964772",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57ea2d24-6028-4d7a-8ace-4ac402de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/d494e9f885ad2d6a2686424843142ddc680bb5485414023976b4d15e3b6be800/analysis/1474941093/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload installation",
|
|
|
|
"comment": "- Xchecked via VT: 1f22e8f489abff004a3c47210a9642798e1c53efc9d6f333a1072af4b11d71ef",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964772",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "57ea2d24-5000-459d-812e-414102de0b81",
|
|
|
|
"value": "0aaeecdbf1add900a0821fa9b3267d579455e874"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload installation",
|
|
|
|
"comment": "- Xchecked via VT: 1f22e8f489abff004a3c47210a9642798e1c53efc9d6f333a1072af4b11d71ef",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964772",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "57ea2d24-a5a0-4ab8-900b-445f02de0b81",
|
|
|
|
"value": "636a4249104acaaf6d76d7409dc3cb2d"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "- Xchecked via VT: 1f22e8f489abff004a3c47210a9642798e1c53efc9d6f333a1072af4b11d71ef",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964773",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57ea2d25-ef80-4362-af8b-432902de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/1f22e8f489abff004a3c47210a9642798e1c53efc9d6f333a1072af4b11d71ef/analysis/1474941224/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: 96a19a90caa41406b632a2046f3a39b5579fbf730aca2357f84bf23f2cbc1fd3",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964773",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "57ea2d25-6524-490c-b6ea-4ced02de0b81",
|
|
|
|
"value": "d9bcd2f745acca38c403dd9131b3d2cdf23c2b3c"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: 96a19a90caa41406b632a2046f3a39b5579fbf730aca2357f84bf23f2cbc1fd3",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964773",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "57ea2d25-91fc-4efb-bdcc-4b7902de0b81",
|
|
|
|
"value": "4400ec9c4732a32149ca58e7c5806178"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: 96a19a90caa41406b632a2046f3a39b5579fbf730aca2357f84bf23f2cbc1fd3",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964773",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57ea2d25-ae24-489f-9b6c-423302de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/96a19a90caa41406b632a2046f3a39b5579fbf730aca2357f84bf23f2cbc1fd3/analysis/1474940749/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O universal binary with 2 architectures - Xchecked via VT: cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964774",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "57ea2d26-c478-42c2-b5c8-4c0802de0b81",
|
|
|
|
"value": "afb526cadb5370e1b78fa32e6310ecc97adc1a10"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O universal binary with 2 architectures - Xchecked via VT: cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964774",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "57ea2d26-b030-49e8-b586-4a3302de0b81",
|
|
|
|
"value": "dee4ea5abaa73916909e9b5a64c8b2d5"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "Mach-O universal binary with 2 architectures - Xchecked via VT: cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964774",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57ea2d26-b180-4bd1-8471-487502de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/cffa1d9fc336a1ad89af90443b15c98b71e679aeb03b3a68a5e9c3e7ecabc3d4/analysis/1474963608/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O executable i386 - Xchecked via VT: c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964774",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "57ea2d26-782c-4233-aeec-4ba402de0b81",
|
|
|
|
"value": "f5461c00de8bc819f86113f338e85470f5aae5ef"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O executable i386 - Xchecked via VT: c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964775",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "57ea2d27-e538-4cab-9d01-4e1a02de0b81",
|
|
|
|
"value": "e36e061f64536679fe48d2dcdb3ac4e6"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "Mach-O executable i386 - Xchecked via VT: c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964775",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57ea2d27-2b78-4a59-b7f9-4b2f02de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/c1b8fc00d815e777e39f34a520342d1942ebd29695c9453951a988c61875bcd7/analysis/1474922977/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O 64- bit executable x86_64 - Xchecked via VT: 2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964775",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "57ea2d27-3374-4f5a-a292-4f6702de0b81",
|
|
|
|
"value": "c7199fb8c605f4b76093cc88f1d80a59fac64ae2"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "Mach-O 64- bit executable x86_64 - Xchecked via VT: 2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964775",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "57ea2d27-d5d0-463e-a83b-426702de0b81",
|
|
|
|
"value": "81749e780d27ddd15973d19de77c9007"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "Mach-O 64- bit executable x86_64 - Xchecked via VT: 2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964775",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57ea2d27-d3f8-49b0-8bd6-4b0a02de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/2a06f142d87bd9b66621a30088683d6fcec019ba5cc9e5793e54f8d920ab0134/analysis/1474944485/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "- Xchecked via VT: 227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964776",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "sha1",
|
|
|
|
"uuid": "57ea2d28-53e0-41e1-8667-489402de0b81",
|
|
|
|
"value": "9e73b0457d28b0296befed65e2517ed7a9c1e61d"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Payload delivery",
|
|
|
|
"comment": "- Xchecked via VT: 227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964776",
|
|
|
|
"to_ids": true,
|
|
|
|
"type": "md5",
|
|
|
|
"uuid": "57ea2d28-2430-4650-a2a2-400902de0b81",
|
|
|
|
"value": "b09fe828904a38f37b7a6f6933188279"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "- Xchecked via VT: 227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1474964776",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57ea2d28-1634-49eb-b9dc-485102de0b81",
|
|
|
|
"value": "https://www.virustotal.com/file/227b7fe495ad9951aebf0aae3c317c1ac526cdd255953f111341b0b11be3bbc5/analysis/1474960828/"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Attribution",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1475474500",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "threat-actor",
|
|
|
|
"uuid": "57f1f444-2d50-4219-9306-6a21bce2ab96",
|
|
|
|
"value": "Sofacy"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Attribution",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1475474500",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "threat-actor",
|
|
|
|
"uuid": "57f1f444-e480-4b45-9f46-6a21bce2ab96",
|
|
|
|
"value": "APT28"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Attribution",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1475474500",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "threat-actor",
|
|
|
|
"uuid": "57f1f444-6d24-48ee-9246-6a21bce2ab96",
|
|
|
|
"value": "Pawn Storm"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Attribution",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1475474500",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "threat-actor",
|
|
|
|
"uuid": "57f1f444-9f18-4465-a66f-6a21bce2ab96",
|
|
|
|
"value": "Fancy Bear"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "Attribution",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1475474500",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "threat-actor",
|
|
|
|
"uuid": "57f1f444-7e9c-49ad-bed1-6a21bce2ab96",
|
|
|
|
"value": "Sednit"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "http://researchcenter.paloaltonetworks.com/2016/09/unit42-sofacys-komplex-os-x-trojan/",
|
|
|
|
"data": "JVBERi0xLjQKJdPr6eEKMSAwIG9iago8PC9DcmVhdG9yIChNb3ppbGxhLzUuMCBcKFdpbmRvd3MgTlQgNi4xOyBXT1c2NFwpIEFwcGxlV2ViS2l0LzUzNy4zNiBcKEtIVE1MLCBsaWtlIEdlY2tvXCkgQ2hyb21lLzUzLjAuMjc4NS4xMTMgU2FmYXJpLzUzNy4zNikKL1Byb2R1Y2VyIChTa2lhL1BERiBtNTMpCi9DcmVhdGlvbkRhdGUgKEQ6MjAxNjEwMDMwNTU4NTcrMDAnMDAnKQovTW9kRGF0ZSAoRDoyMDE2MTAwMzA1NTg1NyswMCcwMCcpPj4KZW5kb2JqCjIgMCBvYmoKPDwvVHlwZSAvWE9iamVjdAovU3VidHlwZSAvSW1hZ2UKL1dpZHRoIDIyMAovSGVpZ2h0IDIyMAovQ29sb3JTcGFjZSAvRGV2aWNlUkdCCi9TTWFzayAzIDAgUgovQml0c1BlckNvbXBvbmVudCA4Ci9GaWx0ZXIgL0ZsYXRlRGVjb2RlCi9MZW5ndGggMTMwOTI+PiBzdHJlYW0KeJztfQdYU9nW9rn3+/6597t97p25U9TpYxcbLQTU0bkz43RHsXeRloRQpdeE5OQkoQZI6EUEQhGwl7FiV+yCioioSBEQQen475MwzlyV7HO2AkHPft5nHqed5JzzZq31rrX22hj2XMvUSc7iSwDMHEiYOBBmPMLMASf/Se8/xLX/isHLAJ5E80IBCDb5tzgL/JkjA38lwQP/XGRpafl8nEJfZnyC5SAh4RTCcgQMBFSUsAf9oTEYBODA/pBM4OOAkCRveRJTDj6QbDTlESwe+R3MHKUs7bfia39BDF5RsH79A7CfBIsLbCZJCWA5+5uNbK4YmGuNxSY0JCTIv3XoNZIMXnWQNCC00RrJTIdeZlpwpf3Bxun2/mY8kpDmPJz92EeD78CwkcET+IUVWuM5jSs1Ix2r1NJS/QIJae5AsnGGfQBpFTXKhc2XDv69M9Bn8AmSJBo3CrwqICQZZDqJnp+NYy39SWEFzCNJSzJuZDvJGNvIgCr4hLmTXGPHCJaTGHDJlCfG/P2fh5MgRp1qrTLjA1pK2I5SxjwyQABgTu+fgeQJCGBxJaaWToiE5IrY6yTakNXCNWzQb43BEAafsHDRUIhHzFgJaImix005InM7sfaCFi6hGj012PfFYIjDwjXcTJsvWicx5dGILaev8GdxxFOttfUX3Nw5hCEkgxcFrcMl00ROIWwu1aIPCB1n8yK0LpshJIMXjt44kCcOCAgwd5BACWn+q4rRBgAMIRm8eExzCydzOJqi+TSdtJzODwX/jYaWhNb1M2DQPyC01nKapiA41VrVt9cmZjiGAgKTOaXB/9oMXmpos9yaZKMp99mm0rS3bk6WLH9NKDFg0G8g6y+amjgJ+2fUxMnOCk3F3NyZMZIMBgi9IpojYz1lKrX9FWyyM3PwvyeDVwi9HlxjDB1k/8XJ3uZhCeO1GQwwNJQjACEBLR8Tks0Xa1uFB/3rMXgV8bilR9Pk08tJB9zckSwjspmGHwaDAS3x2KRVJOvgZLOuA/5rj+5gfz0GryJ+JR6uNZJks+6gfysGDBzI/TtmXAlpJLUsZYwkg0GE1n2TuyTIjTyD/30YMNDily2xTE6SgR6BJ7Hgycg/MI6bgX7AgidiMWlJBnoDdm9GiAEDPQKLHFbAeG0GegZmzg8DfQKbmYTGQK+gnXxF/plx3wz0BUwwyUDvwKQlGegbmFwQAz0DixHdDPQOjO9moE/QDn8e9K/BgMFvwPhuBvoGhpMM9A+M72agT+AxdpKB3oHhJAN9A8NJBvoHJp5koF9g7CQD/QNjJxnoFxg7yUDfwHCSgb6B4SQDfQPDSQb6BoaTDPQLTK8aA/0DYycZ6BsYTjLQPzC+m4G+geHkyw3CmCedaC8bZysba0v+dbydbLK9jMXT3xNnGN/98oIwsA+ZYC9aJnQNTl6lyJyryPw2csO34RvmBcSt/dzdZ4ytXB8nTjA9vS8pjLjyUfbidQq+LOXb0DTD6MxxKvUnquwPAJRZnygyDGSpFpKUVVN4wSye3tGS4eTLBwP70O98fP1VlopMQ6X6vZist6Mzh0dnjniMmMxhMVnvKtXj5Gk/mfGFpnrGAYaTLxmmcEKWCryCE76NzgQm8W0NCd/rA8Pict4XJS2f5Sw21SdryXDyZQKID/+zzl+c9HVM1ghgCftm42MMj8sZNdfXU6/O/mA4+TJhEgcPip8fnfkh8M4UCElCmfW6j2rpf1yD9cdUMpx8acBykKwUrVOqDWKyhlMkpNaDK3M//9FTYMJwksGLBpAqoenfRmV+qDOGfIb7Ti4wnucdaMxlOMngxQL/3DVQpR4LIkk6hCQ5mVo4WY84yeQnBxXGXHyCnehja+EH1oKPrIVjbYONuIhaw5wvsZHaKzI+oWkkSd+dWGAx1ztIXzjJ2MlBwmR70WQu/oN3pHNYKp6QE5KykUjM9YhMn+OjmGAvNubRZuY0Pi5KXhqV+TFdTgJ5Hqn+5nt9iieZevcAw4SHT+VJVgtVeEr+1mPnqhqaHv2yGppbdx6/IIjP/sEr0oSmwZzuiMdkfxeT9SFNIwl099u+cYsZ3f3KArjmL11DnCI3XLtV+6jvBbg6309B64yYGU7i+Dx2dOYHtDmpftMKt53mJNKfc2AZTg4YTHk4iPpy9p1s6+jUQUjtOlpy/Rv3MBZlJz7TOTgm6xO6hARQqf/5k5c7kzN/NTHKVrjvdElHZxeUkNolzdw+w0lGxXyxHfA5Pm5RGbSNJEBC3offrBPoj+M2Yzg5UJjCEcduOdja3kGRkGA1tDxcHhhtxBVDLz7NUcwJsYnOfJ8+J0cA0f3NumA9a8PQox/IS4wpzvKWh63UCaldTmFpRjD3DQzpLGdRcPJCNE5Gqr//yo3h5CsHQJuic1c6u6h67cdLmFzA5hO63TfwdF+6ipQ5s9E4CUQ3oLT+CBwzxncPAHiSGS4hD9va6RISrNCs7dOcISEleINfuYqS8k0QgsnozOFrcDvg+lHvjjAl91ZIjHgSU83fvpAnxnCyv2HuSDhGqbu6uxE4ia/fYu4khXPSTRCbQ7d8o8U737j7INyUERfHlvljC3wwG/F076hZvjH/4hLYQh9sub/pCzjpmPHd/QgWmaWRZe090Y3ESY+oDFPYR7D54nl+bsqsfyNwMj53zOcuQlqOG3wfzNLT1FOx/+TFyqqamvrGu41NALX1jeBvNx88hXEkf1wZYP4c53gydrJfAR7vbLeQK7dqenp6EDjJIRIMObo0DqDTDGeRQ+jamKx36HPy/YSN02c5iylyEvxnBnYizA4/fu7yrdr69mcltdo6Okuu35Kmb8YWeSPTkuFkv8KUh//gEQbeFAIjW9s7VwmUujlpyiO+dAsWpVjGZFFt4v0NPojImjPTiRInAU8MufhKWerVyqqubsjdVNbU+8XnjLEVoT43xnf3I8DrXugfRZ+P5LpUUWXpE6m7HwNw8jt3oSr3S80uMLqc/NA3bsV0J0oCB3zQaiL5RnUdlW8OKHv5RhW2WoD40Bg72Z9g8yX2oWlonARR6JduobozhyY84kcPQVLBFPotau9FZX68Ssw158OrilM44vn+UeW3ddXon1itbe1ExtbJ9miKnrGT/QVNsCcjsrajcVKYunkaTHSb8CQ/evrF5yIInBGKjE+/XOcLvQtjLv6DZ/iWQ6dofXng34GpfHNNIMpzY+xkvwEEk7PXhW46fBaNk9ayJPicCr54UYCLSv0HBNGtVE+2cIQbSQN7sZdiQ2sH7YR/84OH2Cr6nGTmT/YnTHi4pY/i2h1KMdjTa6GvwkRnMAkYO8slmB++UqV+gy4hY7I+jM37jzkfcgsgcvjMVZ656zDC92952IpZoYWUDCf7C0ZcfLVQ2QlTqU+vnp5HLa3tP3qE6+YkCCa/9RDgKXOUWW/RddzRmZ+EZc6HBpMT7UV2ROKVWzUInGxueYBmJxnf3X8AkplDJCC8zZ6enjNlN2eTAkcXZ4y5xFzvQFXu5zGZdJOTIJgc6a1azYa1TX60Vo
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1475474459",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "attachment",
|
|
|
|
"uuid": "57f1f41b-6628-4deb-8451-69fcbce2ab96",
|
|
|
|
"value": "Sofacy\u00e2\u20ac\u2122s \u00e2\u20ac\u02dcKomplex\u00e2\u20ac\u2122 OS X Trojan - Palo Alto Networks Blog.pdf"
|
|
|
|
},
|
|
|
|
{
|
|
|
|
"category": "External analysis",
|
|
|
|
"comment": "",
|
|
|
|
"deleted": false,
|
|
|
|
"disable_correlation": false,
|
|
|
|
"timestamp": "1475474448",
|
|
|
|
"to_ids": false,
|
|
|
|
"type": "link",
|
|
|
|
"uuid": "57f1f410-54e4-4578-a9a0-0c95bce2ab96",
|
|
|
|
"value": "http://researchcenter.paloaltonetworks.com/2016/09/unit42-sofacys-komplex-os-x-trojan/"
|
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
]
|
2023-12-14 14:30:15 +00:00
|
|
|
}
|
2023-04-21 13:25:09 +00:00
|
|
|
}
|