2023-04-21 13:25:09 +00:00
{
2023-12-14 14:30:15 +00:00
"Event" : {
"analysis" : "2" ,
"date" : "2017-12-29" ,
"extends_uuid" : "" ,
"info" : "Threat Analysis: Malicious Microsoft Word Documents Being Used in Targeted Attack Campaigns" ,
"publish_timestamp" : "1524609534" ,
"published" : true ,
"threat_level_id" : "3" ,
"timestamp" : "1514549711" ,
"uuid" : "5a462890-bb44-47c7-ba3b-21bda5fe7088" ,
"Orgc" : {
"name" : "Crimeware" ,
"uuid" : "569f692d-b290-40cc-ae1a-2c48ff32448e"
} ,
"Tag" : [
{
"colour" : "#ffffff" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "tlp:white" ,
"relationship_type" : ""
} ,
{
"colour" : "#00223b" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "osint:source-type=\"blog-post\"" ,
"relationship_type" : ""
}
] ,
"Attribute" : [
{
"category" : "External analysis" ,
"comment" : "" ,
"data" : " / 9 j / 4 Q A Y R X h p Z g A A S U k q A A g A A A A A A A A A A A A A A P / s A B F E d W N r e Q A B A A Q A A A A 8 A A D / 4 Q M q a H R 0 c D o v L 25 z L m F k b 2 J l L m N v b S 94 Y X A v M S 4 w L w A 8 P 3 h w Y W N r Z X Q g Y m V n a W 49 I u + 7 v y I g a W Q 9 I l c 1 T T B N c E N l a G l I e n J l U 3 p O V G N 6 a 2 M 5 Z C I / P i A 8 e D p 4 b X B t Z X R h I H h t b G 5 z O n g 9 I m F k b 2 J l O m 5 z O m 1 l d G E v I i B 4 O n h t c H R r P S J B Z G 9 i Z S B Y T V A g Q 29 y Z S A 1 L j Y t Y z E 0 M i A 3 O S 4 x N j A 5 M j Q s I D I w M T c v M D c v M T M t M D E 6 M D Y 6 M z k g I C A g I C A g I C I + I D x y Z G Y 6 U k R G I H h t b G 5 z O n J k Z j 0 i a H R 0 c D o v L 3 d 3 d y 53 M y 5 v c m c v M T k 5 O S 8 w M i 8 y M i 1 y Z G Y t c 3 l u d G F 4 L W 5 z I y I + I D x y Z G Y 6 R G V z Y 3 J p c H R p b 24 g c m R m O m F i b 3 V 0 P S I i I H h t b G 5 z O n h t c D 0 i a H R 0 c D o v L 25 z L m F k b 2 J l L m N v b S 94 Y X A v M S 4 w L y I g e G 1 s b n M 6 e G 1 w T U 0 9 I m h 0 d H A 6 L y 9 u c y 5 h Z G 9 i Z S 5 j b 20 v e G F w L z E u M C 9 t b S 8 i I H h t b G 5 z O n N 0 U m V m P S J o d H R w O i 8 v b n M u Y W R v Y m U u Y 29 t L 3 h h c C 8 x L j A v c 1 R 5 c G U v U m V z b 3 V y Y 2 V S Z W Y j I i B 4 b X A 6 Q 3 J l Y X R v c l R v b 2 w 9 I k F k b 2 J l I F B o b 3 R v c 2 h v c C B D Q y A o V 2 l u Z G 93 c y k i I H h t c E 1 N O k l u c 3 R h b m N l S U Q 9 I n h t c C 5 p a W Q 6 R T N B Q k E 4 M D B F N E U z M T F F N 0E3 O D B G N 0 U y Q j U x Q j l B M z U i I H h t c E 1 N O k R v Y 3 V t Z W 50 S U Q 9 I n h t c C 5 k a W Q 6 R T N B Q k E 4 M D F F N E U z M T F F N 0E3 O D B G N 0 U y Q j U x Q j l B M z U i P i A 8 e G 1 w T U 0 6 R G V y a X Z l Z E Z y b 20 g c 3 R S Z W Y 6 a W 5 z d G F u Y 2 V J R D 0 i e G 1 w L m l p Z D p F M 0 F C Q T d G R U U 0 R T M x M U U 3 Q T c 4 M E Y 3 R T J C N T F C O U E z N S I g c 3 R S Z W Y 6 Z G 9 j d W 1 l b n R J R D 0 i e G 1 w L m R p Z D p F M 0 F C Q T d G R k U 0 R T M x M U U 3 Q T c 4 M E Y 3 R T J C N T F C O U E z N S I v P i A 8 L 3 J k Z j p E Z X N j c m l w d G l v b j 4 g P C 9 y Z G Y 6 U k R G P i A 8 L 3 g 6 e G 1 w b W V 0 Y T 4 g P D 94 c G F j a 2 V 0 I G V u Z D 0 i c i I / P v / u A A 5 B Z G 9 i Z Q B k w A A A A A H / 2 w C E A A Y E B A Q F B A Y F B Q Y J B g U G C Q s I B g Y I C w w K C g s K C g w Q D A w M D A w M E A w O D x A P D g w T E x Q U E x M c G x s b H B 8 f H x 8 f H x 8 f H x 8 B B w c H D Q w N G B A Q G B o V E R U a H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H x 8 f H //AABEIAZMEAAMBEQACEQEDEQH/xADIAAEAAgMBAQEAAAAAAAAAAAAAAwQBAgUGBwgBAQADAQEBAAAAAAAAAAAAAAACAwQBBQYQAAICAQMCAgUFCQoLBwMEAwECAAMEERIFIQYxE0FRIjIUYXEzFQeBkaFCUmKyIxax0XKConOTs3S0kkNTY4PTJDQ1VgjBwkSEVXU28OEl8dLDN1RFRhEBAAIAAgUJBQYFBAIDAQAAAAECEQMhMUESBFFhcYGRwdETFKGxMlIF8OEiQnKSgqKy0jPxwuIjYrPyQzRT/9oADAMBAAIRAxEAPwD9UwEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQOXR3V2zfyzcPTyuLZyqsyNgpchuDVgl12A66qAdR6JCMyuOGOlotwmbFN+a23OXDQ6kmzkBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBA53cHOY/B8TfyeRRfk1Ubd1OLWbbTvYKNqDT8rrI3tuxiv4fInNvFImImeWcIfPew+38HuTtjmeUxmfis7l+WzcjF5ShUTkMepsgN5ZfqyEhSrLu8D8szZVItWZ1YzPS9r6hxNsjOpSfx1pl1iaz8Ezu6+d3/sr5DkL+F5DD5DOs5C/jOUzMGvIvIa5qqLNFLnxJ6yzh5mYmJnHCZY/q+XSuZW1a7sXpW2EasZjY9pL3lEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBA+b8Bm9wdo8lza85xlWL2vk8nmZ7dwvl1BUXKs1pU0DWz2mKr85mWk2pM4x+HGdOL3eIplcTSnl2mc6KVrubs/ljTp1c6D7Ju3+3c/N5nvFKRdyd3L8guLyAeza2O7+ztTcKyCGPXbOcPSszNtuMp/WOJzaVpkTOFIy6Y10a8O19Pmt8+QEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQK2ZRl3GoY+ScZUdXsZVViwVgSntAjay6g+n1QPJ8p2r35nYmTi/tJSara6a6hdg49oDVZptax1ZdrM+Kq1kabQ+rqF6AcmMUq3ms4xOEunw3A9w4KW1W8rW2N8ZfbjY1GNTSleHbYrVUeyo9qtAw3ektqfCIjAtabTjM4y9FOokBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAjyWyFxrWxlV8gIxpRzopfT2Qx9AJgeeyr+9HKmnHVRWpsGq16u20AKyjI095m1XdpoAd2vswNsm/vGyy0V4y0pTajUsprbzE2WiwaGwa+0E267fHr6dAl5S3nclt3EeYKLanWxrE8l6ragXr2LcFLeczBGOmgAgVRld0jt74VKbH5wecLGdFGiEv5TK4auhm619BYSBrrqQYFrKyu66ccPXRU5Flm4bdxWpWUISBZq25NzEqCddBsMCGvke8muSv4KrXy2sbeuxeptCBmFr7T7KdF3+PXb6AtYOfzleJddzGP5be7RRiVm2w+zrrqrWD5Oug19PWBBx690eZgHIFi1nc2TWxpYoC1p2WMpbftU1KjJ46EtprpAkxE5spx1mWcinyFusz9TU5fYdK62SrfuZ927VPydPEwJcm7lLr8h8RL/hnwm8g6V1kZAYgAJbtcMR+UNsDTKzu4KqcBcfDNltoCZIs2kq4rFpbVH2gfq2r6/jsvo1gT8Fb3BbVa/MVVUMGK01VjUlQSNzMHce
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514548004" ,
"to_ids" : false ,
"type" : "attachment" ,
"uuid" : "5a462b24-9d10-4f02-afce-24b9a5fe7088" ,
"value" : "Figure_10_fixed_for_release.jpg"
} ,
{
"category" : "External analysis" ,
"comment" : "Payload" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547847" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "5a462a87-dd74-4356-be5c-21c0a5fe7088" ,
"value" : "https://www.cobaltstrike.com/"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547489" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "5a462921-ae28-47ba-b058-24b8a5fe7088" ,
"value" : "https://www.carbonblack.com/2017/12/19/threat-analysis-malicious-microsoft-word-documents-used-targeted-attack-campaigns/"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547517" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "5a46293d-1dd0-4aa8-b2dc-24cea5fe7088" ,
"value" : "A Microsoft Word document (.doc) believed to be malicious was recently submitted to Carbon Black\u00e2\u20ac\u2122s Threat Analysis Unit (TAU). The submitting organization did not feel that that document (and subsequent payload) was fully executing in their analysis environment, and questioned whether or not it was actually malicious.\r\n\r\nThe submitted file was part of a targeted attack against an organization, and would not properly run unless the infected system configured for a domain that matched a hard coded pattern. The malicious carrier file contained embedded macros which would launch a series of VB scripts. Ultimately the scripts would inject a Cobalt Strike payload into a running process. While researching this variant TAU discovered numerous other variants (both .doc and .docx formats), which were written in the same manner. Only one instance contained the portion of code to ensure the script would only run at a targeted domain. All of these variants had very low coverage when run through an analysis engine, and as this technique emerges it will continue to be used in targeted attacks and eventually commoditized."
} ,
{
"category" : "Network activity" ,
"comment" : "Cobalt Strike C2" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547712" ,
"to_ids" : true ,
"type" : "domain" ,
"uuid" : "5a462a00-89c8-449f-8cee-24c3a5fe7088" ,
"value" : "carbon-copy-marketing.com"
} ,
{
"category" : "Network activity" ,
"comment" : "Cobalt Strike C2" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547713" ,
"to_ids" : true ,
"type" : "domain" ,
"uuid" : "5a462a01-69f8-4ee8-b0ce-24c3a5fe7088" ,
"value" : "free-clipart-archive.com"
} ,
{
"category" : "Network activity" ,
"comment" : "Cobalt Strike C2" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547713" ,
"to_ids" : true ,
"type" : "domain" ,
"uuid" : "5a462a01-04d0-4bb8-ae2e-24c3a5fe7088" ,
"value" : "stationmovil.com"
} ,
{
"category" : "Network activity" ,
"comment" : "Cobalt Strike C2" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547713" ,
"to_ids" : true ,
"type" : "domain" ,
"uuid" : "5a462a01-f43c-4d17-8f06-24c3a5fe7088" ,
"value" : "www.bankingandfinanceexpert.com"
} ,
{
"category" : "Network activity" ,
"comment" : "Cobalt Strike C2" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547713" ,
"to_ids" : true ,
"type" : "domain" ,
"uuid" : "5a462a01-40a8-4652-9457-24c3a5fe7088" ,
"value" : "www.themediaeducation.com"
} ,
{
"category" : "Network activity" ,
"comment" : "Cobalt Strike C2" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547712" ,
"to_ids" : true ,
"type" : "ip-dst" ,
"uuid" : "5a462a00-2338-4071-b27e-24c3a5fe7088" ,
"value" : "212.83.58.231"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Embedded payload" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547603" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "5a462993-bad8-4de5-bc25-21bea5fe7088" ,
"value" : "Cobalt_Strike.dll"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5a462a39-a918-4393-9c0f-21c0a5fe7088" ,
"value" : "3f06c23c4119d720b2a627ab5454a3e0"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5a462a39-b014-485d-858b-21c0a5fe7088" ,
"value" : "376396fceb8e52425780459c41ac3ab4"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5a462a39-9690-4c69-96a4-21c0a5fe7088" ,
"value" : "d79a8e0a9e8c7294351657f7897fd121"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5a462a39-bc88-4dd8-99ef-21c0a5fe7088" ,
"value" : "c17cfcab0d115732a262da8a58dcf318"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5a462a39-971c-44eb-8fac-21c0a5fe7088" ,
"value" : "81af1f218c0a44ea39aa3eca78f24bc0"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Embedded payload" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547604" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5a462994-0180-478c-950f-21bea5fe7088" ,
"value" : "f2f52c78d594c37b546f6c09207cb481"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "5a462a39-041c-420e-84fc-21c0a5fe7088" ,
"value" : "c916685d48dec5891e92c09e18300381"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Embedded payload" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547604" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "5a462994-4a3c-4344-a383-21bea5fe7088" ,
"value" : "12bc1affe86327d9f78684cde46cfff4dee57149"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5a462a39-9f74-4044-ba5f-21c0a5fe7088" ,
"value" : "277226cb5f59de6f4493a42e42f7ea575d65da7a033ae343166ad4fa96db8654"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5a462a39-c24c-450f-acd2-21c0a5fe7088" ,
"value" : "76e2277c63303df6c5b32fdacffcf37c8657ec263070a533eba100d83cade81e"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5a462a39-85fc-4ac2-ad5d-21c0a5fe7088" ,
"value" : "2519e09e54ccc18c7dfc938760b48b559b7e4fb8465e12d8144083d2178789e2"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5a462a39-4008-4bbb-85cc-21c0a5fe7088" ,
"value" : "c10ee375a841fd537ede2afa9e68817ddaaaf2e6587a519c267aac6c1fe8d081"
} ,
{
"category" : "Payload delivery" ,
"comment" : "Embedded payload" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547604" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5a462994-4cd4-4f75-b09a-21bea5fe7088" ,
"value" : "fa405c36d82b264568219b521886d2e7ef589674874983c7db1d67928003489e"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5a462a39-905c-4cb6-bb25-21c0a5fe7088" ,
"value" : "9416893eb0b8b1e7b4afd342887fa358d1ea7dbd56d4a51a25a801715c761356"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1514547769" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "5a462a39-99e0-4dd8-bf3d-21c0a5fe7088" ,
"value" : "2a31a24ce994ae3465e77d4ec190882804233209b7f67bd4ef03375bd9b5f9ed"
}
2023-04-21 13:25:09 +00:00
]
2023-12-14 14:30:15 +00:00
}
2023-04-21 13:25:09 +00:00
}