2023-04-21 13:25:09 +00:00
{
2023-12-14 14:30:15 +00:00
"Event" : {
"analysis" : "0" ,
"date" : "2022-02-24" ,
"extends_uuid" : "56cb2bd3-5525-46bd-a454-ea895a5b4d0d" ,
"info" : "HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine" ,
"publish_timestamp" : "1664880606" ,
"published" : true ,
"threat_level_id" : "1" ,
"timestamp" : "1664880605" ,
"uuid" : "b9b6dcfa-0b11-40dc-9bf4-9a36a2c1a046" ,
"Orgc" : {
"name" : "Centre for Cyber security Belgium" ,
"uuid" : "5cf66e53-b5f8-43e7-be9a-49880a3b4631"
} ,
"Tag" : [
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:target-information=\"Ukraine\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Data Destruction - T1485\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Disk Structure Wipe - T1561.002\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Signed Binary Proxy Execution - T1218\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Group Policy Modification - T1484.001\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0088cc" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "misp-galaxy:mitre-attack-pattern=\"Inhibit System Recovery - T1490\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#ffffff" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "tlp:white" ,
"relationship_type" : ""
} ,
{
"colour" : "#054300" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "admiralty-scale:source-reliability=\"a\"" ,
"relationship_type" : ""
} ,
{
"colour" : "#0eb100" ,
2024-04-05 12:15:17 +00:00
"local" : false ,
2023-12-14 14:30:15 +00:00
"name" : "admiralty-scale:information-credibility=\"1\"" ,
"relationship_type" : ""
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1645686071" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "de0bd41d-ffac-4e5a-8ffd-63c0ba4c6979" ,
"value" : "231b3385ac17e41c5bb1b1fcb59599c4"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1645686071" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "dc288e70-bf4b-46cc-84aa-515e39f3b433" ,
"value" : "095a1678021b034903c85dd5acb447ad"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1645686071" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "e499240c-bfd1-4e5b-a70b-244c11d69053" ,
"value" : "eb845b7a16ed82bd248e395d9852f467"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1645688022" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "194c007c-eb84-4987-ae29-4dca3b02db47" ,
"value" : "https://www.sentinelone.com/labs/hermetic-wiper-ukraine-under-attack/"
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "Effectively disables crash dumps before the abused driver's execution starts" ,
"deleted" : false ,
"disable_correlation" : true ,
"timestamp" : "1645688123" ,
"to_ids" : false ,
"type" : "regkey|value" ,
"uuid" : "8c55aae8-9ee3-4488-93e8-ee3998518fce" ,
"value" : "SYSTEM\\CurrentControlSet\\Control\\CrashControl CrashDumpEnabled|0"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1645688459" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "85ca7a94-fcfb-4097-affc-0b102ae4dff5" ,
"value" : "empntdrv.sys"
}
] ,
"Object" : [
{
"comment" : "912342f1c840a42f6b74132f8a7c4ffe7d40fb77: Enriched via the virustotal module" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "4" ,
"timestamp" : "1645687145" ,
"uuid" : "d611f80f-3015-4e5a-ba28-a4219aae2114" ,
"Attribute" : [
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "permalink" ,
"timestamp" : "1645687142" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "df316954-b61d-436a-8804-d2f38a368eeb" ,
"value" : "https://www.virustotal.com/gui/file/0385eeab00e946a302b24a91dea4187c1210597b8e17cd9e2230450f5ece21da/detection/f-0385eeab00e946a302b24a91dea4187c1210597b8e17cd9e2230450f5ece21da-1645685791"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1645687145" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "8becd4d8-0f4c-429a-a3d4-9e33ac8f55c5" ,
"value" : "8/71"
}
]
} ,
{
"comment" : "912342f1c840a42f6b74132f8a7c4ffe7d40fb77: Enriched via the virustotal module" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"first_seen" : "2022-02-24T06:35:51+00:00" ,
"last_seen" : "2022-02-24T06:35:51+00:00" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "24" ,
"timestamp" : "1645687295" ,
"uuid" : "f6a02b6b-91df-4a01-9115-798e59bc7023" ,
"ObjectReference" : [
{
"comment" : "" ,
"object_uuid" : "f6a02b6b-91df-4a01-9115-798e59bc7023" ,
"referenced_uuid" : "d611f80f-3015-4e5a-ba28-a4219aae2114" ,
2023-04-21 13:25:09 +00:00
"relationship_type" : "analysed-with" ,
2023-12-14 14:30:15 +00:00
"timestamp" : "1664880605" ,
"uuid" : "dcd014f8-ccb2-4885-8563-6f2799ffd2a2"
}
] ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1645687295" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "ec4a3df5-9479-4468-a990-a3f97ff69a1b" ,
"value" : "84ba0197920fd3e2b7dfa719fee09d2f"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1645687295" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "27637845-3dbd-4454-ad6c-51b7d05e22e9" ,
"value" : "912342f1c840a42f6b74132f8a7c4ffe7d40fb77"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1645687295" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "2b89b426-8ae3-483c-8a10-46acc4b9a441" ,
"value" : "0385eeab00e946a302b24a91dea4187c1210597b8e17cd9e2230450f5ece21da"
}
]
} ,
{
"comment" : "61b25d11392172e587d8da3045812a66c3385451: Enriched via the virustotal module" ,
"deleted" : false ,
"description" : "VirusTotal report" ,
"meta-category" : "misc" ,
"name" : "virustotal-report" ,
"template_uuid" : "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4" ,
"template_version" : "4" ,
"timestamp" : "1645687548" ,
"uuid" : "d9a1332e-3511-4417-97c8-f30621513106" ,
"Attribute" : [
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "permalink" ,
"timestamp" : "1645687548" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "bafabadb-48ca-48a7-b192-ed30a1ffc57c" ,
"value" : "https://www.virustotal.com/gui/file/1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591/detection/f-1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591-1645686225"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "detection-ratio" ,
"timestamp" : "1645687545" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "fecf0286-1c32-478d-93e3-507253b34c26" ,
"value" : "28/71"
}
]
} ,
{
"comment" : "61b25d11392172e587d8da3045812a66c3385451: Enriched via the virustotal module" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "24" ,
"timestamp" : "1645687557" ,
"uuid" : "df7db285-8f67-49a0-a570-360c55604d2c" ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1645687557" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "b5d4be4e-d2cf-479b-90bf-6ad348b213dd" ,
"value" : "3f4a16b29f2f0532b7ce3e7656799125"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha1" ,
"timestamp" : "1645687554" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "6f40134d-c3f6-45b0-bea8-10bcb3b68b1e" ,
"value" : "61b25d11392172e587d8da3045812a66c3385451"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "sha256" ,
"timestamp" : "1645687551" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "127e284e-9f47-46f6-a14d-118e7e59309a" ,
"value" : "1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "File object describing a file with meta-information" ,
"meta-category" : "file" ,
"name" : "file" ,
"template_uuid" : "688c46fb-5edb-40a3-8273-1af7923e2215" ,
"template_version" : "24" ,
"timestamp" : "1645687512" ,
"uuid" : "6e410e9b-426b-49ce-a8b9-4efdf1656f24" ,
"Attribute" : [
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "md5" ,
"timestamp" : "1645687512" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "104e8a29-d087-4540-bcaa-ee455e21a157" ,
"value" : "a952e288a1ead66490b3275a807f52e5"
}
]
} ,
{
"comment" : "" ,
"deleted" : false ,
"description" : "An object describing a YARA rule (or a YARA rule name) along with its version." ,
"meta-category" : "misc" ,
"name" : "yara" ,
"template_uuid" : "b5acf82e-ecca-4868-82fe-9dbdf4d808c3" ,
"template_version" : "5" ,
"timestamp" : "1645688599" ,
"uuid" : "c908378a-8f2a-49e1-b592-306424bd139b" ,
"Attribute" : [
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "comment" ,
"timestamp" : "1645688599" ,
"to_ids" : false ,
"type" : "comment" ,
"uuid" : "f596d739-c866-436a-9f94-f0694db7a401" ,
"value" : "HermeticWiper - broad hunting rule"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : true ,
"object_relation" : "context" ,
"timestamp" : "1645688599" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "d47e6fda-a832-4855-8c6f-f2d3dc912138" ,
"value" : "disk"
} ,
{
"category" : "Payload installation" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "yara" ,
"timestamp" : "1645688599" ,
"to_ids" : true ,
"type" : "yara" ,
"uuid" : "87bdab8d-c1f2-4996-86b6-b0c9ef9536eb" ,
"value" : "rule MAL_HERMETIC_WIPER {\r\n meta:\r\n desc = \"HermeticWiper - broad hunting rule\"\r\n author = \"Friends @ SentinelLabs\"\r\n version = \"1.0\"\r\n last_modified = \"02.23.2022\"\r\n hash = \"1bc44eef75779e3ca1eefb8ff5a64807dbc942b1e4a2672d77b9f6928d292591\"\r\n strings:\r\n $string1 = \"DRV_XP_X64\" wide ascii nocase\r\n $string2 = \"EPMNTDRV\\\\%u\" wide ascii nocase\r\n $string3 = \"PhysicalDrive%u\" wide ascii nocase\r\n $cert1 = \"Hermetica Digital Ltd\" wide ascii nocase\r\n condition:\r\n uint16(0) == 0x5A4D and\r\n all of them\r\n}"
} ,
{
"category" : "Other" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"object_relation" : "yara-rule-name" ,
"timestamp" : "1645688599" ,
"to_ids" : false ,
"type" : "text" ,
"uuid" : "045e7288-a031-4613-bd58-6b839f4fd53a" ,
"value" : "MAL_HERMETIC_WIPER"
}
]
}
] ,
"EventReport" : [
{
"name" : "HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine" ,
"content" : "# HermeticWiper | New Destructive Malware Used In Cyber Attacks on Ukraine\r\n\r\n Juan Andr\u00e9s Guerrero-Saade / February 23, 2022\r\n\r\n## Executive Summary\r\n\r\n * On February 23rd, the threat intelligence community began observing a new wiper malware sample circulating in Ukrainian organizations.\r\n * Our analysis shows a signed driver is being used to deploy a wiper that erases Windows devices, after deleting shadow copies and manipulating MBR after rebooting.\r\n * This blog includes the technical details of the wiper, dubbed @[tag](HermeticWiper), and includes IOCs to allow organizations to stay protected from this attack.\r\n * This sample is actively being used against Ukrainian organizations, and this blog will be updated as more information becomes available.\r\n * @[tag](SentinelOne) customers are protected from this threat, no action is needed.\r\n \r\n ## Background\r\n\r\n On February 23rd, our friends at @[tag](Symantec) and @[tag](ESET) research tweeted hashes associated with a wiper attack in Ukraine, including one which is not publicly available as of this writing.\r\n\r\n We started analyzing this new wiper malware, calling it \u2018@[tag](HermeticWiper)\u2019 in reference to the digital certificate used to sign the sample. The digital certificate is issued under the company name \u2018Hermetica Digital Ltd\u2019 and valid as of April 2021. At this time, we haven\u2019t seen any legitimate files signed with this certificate. It\u2019s possible that the attackers used a shell company or appropriated a defunct company to issue this digital certificate.\r\n\r\n @[tag](HermeticWiper) Digital Signature This is an early effort to analyze the first available sample of @[tag](HermeticWiper). We recognize that the situation on the ground in Ukraine is evolving rapidly and hope that we can contribute our small part to the collective analysis effort.\r\n\r\n ## Technical Analysis\r\n\r\n At first glance, @[tag](HermeticWiper) appears to be a custom-written application with very few standard functions. The malware sample is 114KBs in size and roughly 70% of that is composed of resources. The developers are using a tried and tested technique of wiper malware, abusing a benign partition management driver, in order to carry out the more damaging components of their attacks. Both the @[tag](misp-galaxy:mitre-enterprise-attack-intrusion-set=\"Lazarus Group - G0032\") (Destover) and @[tag](misp-galaxy:mitre-enterprise-attack-intrusion-set=\"APT33 - G0064\" ) ( S h a m o o n ) t o o k a d v a n t a g e o f E l d o s R a w d i s k i n o r d e r t o g e t d i r e c t u s e r l a n d a c c e s s t o t h e f i l e s y s t e m w i t h o u t c a l l i n g W i n d o w s A P I s . @ [ t a g ] ( H e r m e t i c W i p e r ) u s e s a s i m i l a r t e c h n i q u e b y a b u s i n g a d i f f e r e n t d r i v e r , @ [ a t t r i b u t e ] ( 85 c a 7 a 94 - f c f b -4097 - a f f c -0 b 102 a e 4 d f f 5 ) . \ r \ n \ r \ n @ [ t a g ] ( H e r m e t i c W i p e r ) r e s o u r c e s c o n t a i n i n g E a s e U S P a r t i t i o n M a n a g e r d r i v e r s T h e c o p i e s o f t h e d r i v e r a r e m s - c o m p r e s s e d r e s o u r c e s . T h e m a l w a r e d e p l o y s o n e o f t h e s e d e p e n d i n g o n t h e O S v e r s i o n , b i t n e s s , a n d S y s W o w 64 r e d i r e c t i o n . \ r \ n \ r \ n E a s e U S d r i v e r r e s o u r c e s e l e c t i o n T h e b e n i g n E a s e U S d r i v e r i s a b u s e d t o d o a f a i r s h a r e o f t h e h e a v y - l i f t i n g w h e n i t c o m e s t o a c c e s s i n g P h y s i c a l D r i v e s d i r e c t l y a s w e l l a s g e t t i n g p a r t i t i o n i n f o r m a t i o n . T h i s a d d s t o t h e d i f f i c u l t y o f a n a l y z i n g @ [ t a g ] ( H e r m e t i c W i p e r ) , a s a l o t o f f u n c t i o n a l i t y i s d e f e r r e d t o D e v i c e I o C o n t r o l c a l l s w i t h s p e c i f i c I O C T L s . \ r \ n \ r \ n # # M B R a n d P a r t i t i o n C o r r u p t i o n \ r \ n \ r \ n @ [ t a g ] ( H e r m e t i c W i p e r ) e n u m e r a t e s a r a n g e o f P h y s i c a l D r i v e s m u l t i p l e t i m e s , f r o m 0 -100 . F o r e a c h P h y s i c a l D r i v e , t h e \ \ \ \ . \ \ E P M N T D R V \ \ d e v i c e i s c a l l e d f o r a d e v i c e n u m b e r . \ r \ n \ r \ n T h e m a l w a r e t h e n f o c u s e s o n c o r r u p t i n g t h e f i r s t 512 b y t e s , t h e M a s t e r B o o t R e c o r d ( M B R ) f o r e v e r y P h y s i c a l D r i v e . W h i l e t h a t s h o u l d b e e n o u g h f o r t h e d e v i c e n o t t o b o o t a g a i n , @ [ t a g ] ( H e r m e t i c W i p e r ) p r o c e e d s t o e n u m e r a t e t h e p a r t i t i o n s f o r a l l p o s s i b l e d r i v e s . \ r \ n \ r \ n T h e y t h e n d i f f e r e n t i a t e b e t w e e n F A T a n d N T F S p a r t i t i o n s . I n t h e c a s e o f a F A T p a r t i t i o n , t h e m a l w a r e c a l l s t h e s a m e \ u 2018 b i t f i d d l e r \ u 2019 t o c o r r u p t t h e p a r t i t i o n . F o r N T F S , t h e @ [ t a g ] ( H e r m e t i c W i p e r )
"id" : "93" ,
"event_id" : "98258" ,
"timestamp" : "1645688536" ,
"uuid" : "9f27b900-e658-4a75-854e-4a3e0f2d3899" ,
"deleted" : false
}
2023-04-21 13:25:09 +00:00
]
2023-12-14 14:30:15 +00:00
}
2023-04-21 13:25:09 +00:00
}