{ "Event": { "analysis": "1", "date": "2019-05-16", "extends_uuid": "", "info": "Targeted phishing - PDF documents / phishkit", "publish_timestamp": "1622024256", "published": true, "threat_level_id": "3", "timestamp": "1621850122", "uuid": "5cdd3938-7134-4908-9552-173cc0a8016e", "Orgc": { "name": "EUROLEA", "uuid": "5cdc2cdd-bca4-4a76-8955-03cdc0a8016e" }, "Tag": [ { "colour": "#0088cc", "local": false, "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Attachment - T1193\"", "relationship_type": "" }, { "colour": "#0088cc", "local": false, "name": "misp-galaxy:mitre-attack-pattern=\"Spearphishing Link - T1192\"", "relationship_type": "" }, { "colour": "#3bb800", "local": false, "name": "enisa:nefarious-activity-abuse=\"spear-phishing-attacks\"", "relationship_type": "" }, { "colour": "#004646", "local": false, "name": "type:OSINT", "relationship_type": "" }, { "colour": "#0071c3", "local": false, "name": "osint:lifetime=\"perpetual\"", "relationship_type": "" }, { "colour": "#0087e8", "local": false, "name": "osint:certainty=\"50\"", "relationship_type": "" }, { "colour": "#33FF00", "local": false, "name": "tlp:green", "relationship_type": "" }, { "colour": "#ffffff", "local": false, "name": "tlp:white", "relationship_type": "" } ], "Attribute": [ { "category": "Artifacts dropped", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1558002233", "to_ids": false, "type": "yara", "uuid": "5cdd3a39-84f0-4179-b3ea-173cc0a8016e", "value": "rule PDF_LIFT {\r\nstrings:\r\n\t$a = \"Rect[ 195.05 428.59 411.79 489.67]\"\r\ncondition:\r\n\tall of them\r\n}" }, { "category": "Artifacts dropped", "comment": "Generic yara rule to find the common JAT author.", "deleted": false, "disable_correlation": false, "timestamp": "1558012404", "to_ids": true, "type": "yara", "uuid": "5cdd3a5b-3448-49d1-b35e-12a4c0a8016e", "value": "rule PDF_JAT_AUTHOR {\r\nstrings:\r\n$a = \"<" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "language", "timestamp": "1558012668", "to_ids": false, "type": "text", "uuid": "5cdd62fc-e698-486a-b877-4563950d210f", "value": "PHP" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "filename", "timestamp": "1558012668", "to_ids": true, "type": "filename", "uuid": "5cdd62fc-8010-4377-97b3-46ae950d210f", "value": "sendmail.php" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "state", "timestamp": "1558012668", "to_ids": false, "type": "text", "uuid": "5cdd62fc-0494-426e-96d5-4de9950d210f", "value": "Malicious" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1558013351", "uuid": "d9bdc42c-191f-49a2-8cbe-2604f5462df6", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1558002051", "to_ids": false, "type": "datetime", "uuid": "f1c90675-0c32-40f1-af8f-f90a06993120", "value": "2019-05-16T08:54:33" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1558002051", "to_ids": false, "type": "link", "uuid": "f8eb37d5-1ef7-4e7c-b97c-7fcab9d7e00e", "value": "https://www.virustotal.com/file/f2676b94952018c220ee352b9857bc5ad62195b2d15cdfaf54fa5c5985d6934a/analysis/1557996873/" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1558002051", "to_ids": false, "type": "text", "uuid": "fb7fe45e-a16c-44c4-9a4b-7b6b0018fd43", "value": "1/56" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1558013351", "uuid": "dcd9ca51-3194-44ee-86a2-5f0cf9b923f8", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1558002047", "to_ids": false, "type": "datetime", "uuid": "ac5c453a-e980-47a2-9a84-5d37cf392471", "value": "2019-05-13T02:37:30" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1558002047", "to_ids": false, "type": "link", "uuid": "2b1914f7-d429-496f-b76b-dd9ea4ae34f2", "value": "https://www.virustotal.com/file/56a73192c75130550294b327b36c051841d3780bd3732b410e0c190db6f9d936/analysis/1557715050/" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1558002047", "to_ids": false, "type": "text", "uuid": "c092edd1-d209-4fc1-8b59-cc68ea535499", "value": "0/58" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1558013351", "uuid": "76f9b382-c58e-46f8-b174-42275f764d3e", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1558002045", "to_ids": false, "type": "datetime", "uuid": "15b0df6f-7808-4a07-a743-33883c247a54", "value": "2019-05-13T02:37:43" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1558002045", "to_ids": false, "type": "link", "uuid": "15db416c-93ca-4af3-bc7e-aa8af7ad332e", "value": "https://www.virustotal.com/file/28f73ae365bde8c03d0f93ef73f71c086a026ac58f72b82bb2384c3a5ab42d02/analysis/1557715063/" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1558002045", "to_ids": false, "type": "text", "uuid": "0c2fc5a0-15f4-432a-90c6-c3a49b54266e", "value": "2/59" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1558013352", "uuid": "c22ccebe-e72f-4b92-9c63-a196b4959c43", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1558002049", "to_ids": false, "type": "datetime", "uuid": "829ba8b8-a820-487f-9199-96b13a032e7b", "value": "2019-05-15T17:45:13" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1558002049", "to_ids": false, "type": "link", "uuid": "77e038db-79c1-487f-8193-f857970cfd08", "value": "https://www.virustotal.com/file/0fb825db2262d98e29846fa67171e3450666af9c0a6c31eaf8d7c84539be9132/analysis/1557942313/" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1558002049", "to_ids": false, "type": "text", "uuid": "17e94734-ed26-449a-b1fe-768b881c6f83", "value": "1/54" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1558013352", "uuid": "c3b36005-d35f-4540-bf78-cd09e2ac5e3d", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1558011890", "to_ids": false, "type": "datetime", "uuid": "823fdaca-bb79-49fd-b865-e3e9d8dd86e3", "value": "2019-05-16T09:42:04" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1558011890", "to_ids": false, "type": "link", "uuid": "3f1e2085-c793-4bb9-8022-5d037641c73e", "value": "https://www.virustotal.com/file/9c4f9755fc183f6ad4ad4d600a0a3ed9230900152245f924b9106202ce543c58/analysis/1557999724/" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1558011890", "to_ids": false, "type": "text", "uuid": "2c1f9f4d-f9bb-442e-84f8-0f06c1b28d5f", "value": "10/61" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1558013352", "uuid": "f5647ba0-86e7-40fa-92a2-7d0fe024a7c2", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1558002050", "to_ids": false, "type": "datetime", "uuid": "e2e51a40-0e8a-41df-a238-3176befa0d6d", "value": "2019-05-15T20:41:35" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1558002050", "to_ids": false, "type": "link", "uuid": "2e637413-a76f-4b89-a5f1-1fb99c942c20", "value": "https://www.virustotal.com/file/c052025b442995f04a68b1b6b2007c36dbf47448c08dc249219a7f3eebd369c2/analysis/1557952895/" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1558002050", "to_ids": false, "type": "text", "uuid": "a84ca298-e8e4-4048-becf-05c209cfaa19", "value": "1/60" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1558013352", "uuid": "9156df9c-4067-422e-bd38-8c3908e8ea5f", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1558002048", "to_ids": false, "type": "datetime", "uuid": "f1406b9a-3d0d-4419-96dc-6400f3a9bbb1", "value": "2019-05-13T02:37:29" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1558002048", "to_ids": false, "type": "link", "uuid": "69ee832e-72d0-4b4b-a11c-f57e0452a076", "value": "https://www.virustotal.com/file/ddcf49145d8c78198138a488b7f99bb4f760777be41b293138e4d5b531cebc73/analysis/1557715049/" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1558002048", "to_ids": false, "type": "text", "uuid": "7d4b7e4e-98b2-4840-92ea-7f22911f5603", "value": "0/58" } ] } ] } }