{ "Event": { "analysis": "2", "date": "2016-04-25", "extends_uuid": "", "info": "OSINT - New FAREIT Strain Abuses PowerShell", "publish_timestamp": "1461592904", "published": true, "threat_level_id": "3", "timestamp": "1461589772", "uuid": "571de8da-be78-4d1d-851f-448d950d210f", "Orgc": { "name": "CIRCL", "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f" }, "Tag": [ { "colour": "#ffffff", "local": "0", "name": "tlp:white", "relationship_type": "" }, { "colour": "#004646", "local": "0", "name": "type:OSINT", "relationship_type": "" }, { "colour": "#6bd600", "local": "0", "name": "circl:topic=\"finance\"", "relationship_type": "" } ], "Attribute": [ { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461577960", "to_ids": false, "type": "comment", "uuid": "571de8e8-be8c-4f59-b5b2-4aad950d210f", "value": "In 2014, we began seeing attacks that abused the Windows PowerShell. Back then, it was uncommon for malware to use this particular feature of Windows. However, there are several good reasons for an attacker to use this particular feature.\r\n\r\nFirst, users cannot easily spot any malicious behavior since PowerShell runs in the background. Secondly, PowerShell can be used to steal usernames, passwords, and other system information without an executable file being present. This makes it a powerful tool for attackers.\r\n\r\nLast March 2016, we noted that PowerWare crypto-ransomware also abused PowerShell. Recently, we spotted a new attack where PowerShell was abused to deliver a FAREIT variant. This particular family of information stealers has been around since 2011." }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461577978", "to_ids": false, "type": "link", "uuid": "571de8fa-f540-4df1-ab19-460a950d210f", "value": "http://blog.trendmicro.com/trendlabs-security-intelligence/new-fareit-strain-delivered-abusing-powershell/" }, { "category": "Payload delivery", "comment": "Imported via the freetext import.", "deleted": false, "disable_correlation": false, "timestamp": "1461578517", "to_ids": true, "type": "sha1", "uuid": "571deb15-7a84-4ad5-99fe-4804950d210f", "value": "acaeb29abf2458b862646366917f44e987176ec9" }, { "category": "Payload delivery", "comment": "Imported via the freetext import.", "deleted": false, "disable_correlation": false, "timestamp": "1461578517", "to_ids": true, "type": "sha1", "uuid": "571deb15-4824-409d-86e8-4692950d210f", "value": "cfd1a77155b9af917e22a8ac0fe16eeb26e00c6e" }, { "category": "Payload delivery", "comment": "Imported via the freetext import.", "deleted": false, "disable_correlation": false, "timestamp": "1461578517", "to_ids": true, "type": "sha1", "uuid": "571deb15-6290-4e20-8792-4738950d210f", "value": "da3b7c89ec9ca4157af52d40db76b2c23a62a15e" }, { "category": "Payload delivery", "comment": "Imported via the freetext import.", "deleted": false, "disable_correlation": false, "timestamp": "1461578517", "to_ids": true, "type": "sha1", "uuid": "571deb15-b778-4440-acbf-4bf6950d210f", "value": "03798dc7221efdcec95b991735f38b49dff29542" }, { "category": "Payload delivery", "comment": "Imported via the freetext import.", "deleted": false, "disable_correlation": false, "timestamp": "1461578517", "to_ids": true, "type": "sha1", "uuid": "571deb15-a658-458b-95f5-4654950d210f", "value": "04fffc28bed615d7da50c0286290d452b9c5ee50" }, { "category": "Payload delivery", "comment": "Imported via the freetext import.", "deleted": false, "disable_correlation": false, "timestamp": "1461578517", "to_ids": true, "type": "sha1", "uuid": "571deb15-7dfc-44be-896f-43ff950d210f", "value": "125156e24958f18ad86cc406868948dc100791d4" }, { "category": "Payload delivery", "comment": "Imported via the freetext import.", "deleted": false, "disable_correlation": false, "timestamp": "1461578517", "to_ids": true, "type": "sha1", "uuid": "571deb15-6974-4675-9e90-43bf950d210f", "value": "4f739261372d4adce7f152f16fbf20a5c18b8903" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: 4f739261372d4adce7f152f16fbf20a5c18b8903", "deleted": false, "disable_correlation": false, "timestamp": "1461578530", "to_ids": true, "type": "sha256", "uuid": "571deb22-78c0-40ea-8d6c-4e3502de0b81", "value": "6dceceeb1aff7b613f7bdf9259173d30cabda4a1d142af5f52e03c291c8adb9f" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: 4f739261372d4adce7f152f16fbf20a5c18b8903", "deleted": false, "disable_correlation": false, "timestamp": "1461578530", "to_ids": true, "type": "md5", "uuid": "571deb22-ca5c-4862-80cc-48e002de0b81", "value": "b3dbdb86a443be3d6e310ceb84bb4c2c" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461578530", "to_ids": false, "type": "link", "uuid": "571deb22-9160-47d9-9637-408002de0b81", "value": "https://www.virustotal.com/file/6dceceeb1aff7b613f7bdf9259173d30cabda4a1d142af5f52e03c291c8adb9f/analysis/1461305595/" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: 125156e24958f18ad86cc406868948dc100791d4", "deleted": false, "disable_correlation": false, "timestamp": "1461578530", "to_ids": true, "type": "sha256", "uuid": "571deb22-1348-4179-ab26-444502de0b81", "value": "658b0994a6ccfde063293ffbc3f2b85c4cdab2489ed5351f85011e3957e1e143" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: 125156e24958f18ad86cc406868948dc100791d4", "deleted": false, "disable_correlation": false, "timestamp": "1461578530", "to_ids": true, "type": "md5", "uuid": "571deb22-f794-4e33-9143-49f502de0b81", "value": "1eeb67994aae158dc8486269728fc177" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461578530", "to_ids": false, "type": "link", "uuid": "571deb22-4568-49b2-a586-425902de0b81", "value": "https://www.virustotal.com/file/658b0994a6ccfde063293ffbc3f2b85c4cdab2489ed5351f85011e3957e1e143/analysis/1461303615/" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: 04fffc28bed615d7da50c0286290d452b9c5ee50", "deleted": false, "disable_correlation": false, "timestamp": "1461578530", "to_ids": true, "type": "sha256", "uuid": "571deb22-fe80-4838-a1b4-41c702de0b81", "value": "30bcc5a700e08c91095c3a8e6c52495a6b60f9ff07ac3c0b96e75befc44b1f5a" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: 04fffc28bed615d7da50c0286290d452b9c5ee50", "deleted": false, "disable_correlation": false, "timestamp": "1461578531", "to_ids": true, "type": "md5", "uuid": "571deb23-9980-4ec2-9c3f-498e02de0b81", "value": "8ce49433b0442f3d9d81662f9f3c9342" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461578531", "to_ids": false, "type": "link", "uuid": "571deb23-cbf0-45dd-8657-40bd02de0b81", "value": "https://www.virustotal.com/file/30bcc5a700e08c91095c3a8e6c52495a6b60f9ff07ac3c0b96e75befc44b1f5a/analysis/1461393556/" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: 03798dc7221efdcec95b991735f38b49dff29542", "deleted": false, "disable_correlation": false, "timestamp": "1461578531", "to_ids": true, "type": "sha256", "uuid": "571deb23-3e40-4959-9562-462202de0b81", "value": "300a50991cb2c6eb16b7e14ba5ef72a3a83c9f2b7d6cd7da259b866fbc527985" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: 03798dc7221efdcec95b991735f38b49dff29542", "deleted": false, "disable_correlation": false, "timestamp": "1461578531", "to_ids": true, "type": "md5", "uuid": "571deb23-19c0-4d9c-af16-487902de0b81", "value": "f43c1178362caf94e7670208b054d285" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461578531", "to_ids": false, "type": "link", "uuid": "571deb23-512c-4434-a828-48f002de0b81", "value": "https://www.virustotal.com/file/300a50991cb2c6eb16b7e14ba5ef72a3a83c9f2b7d6cd7da259b866fbc527985/analysis/1460188306/" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: da3b7c89ec9ca4157af52d40db76b2c23a62a15e", "deleted": false, "disable_correlation": false, "timestamp": "1461578531", "to_ids": true, "type": "sha256", "uuid": "571deb23-a7f0-4248-b820-46d502de0b81", "value": "5f6cfc97884476c469b11ef2c22d0d181879ba9ac1d26176f9f1b35b009a6646" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: da3b7c89ec9ca4157af52d40db76b2c23a62a15e", "deleted": false, "disable_correlation": false, "timestamp": "1461578531", "to_ids": true, "type": "md5", "uuid": "571deb23-3eec-43fe-b73a-4f7802de0b81", "value": "c04d18f4e9e8fd4ffba04a9ced5c27bc" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461578532", "to_ids": false, "type": "link", "uuid": "571deb24-d2c8-4866-9b32-448802de0b81", "value": "https://www.virustotal.com/file/5f6cfc97884476c469b11ef2c22d0d181879ba9ac1d26176f9f1b35b009a6646/analysis/1461206794/" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: cfd1a77155b9af917e22a8ac0fe16eeb26e00c6e", "deleted": false, "disable_correlation": false, "timestamp": "1461578532", "to_ids": true, "type": "sha256", "uuid": "571deb24-b0c8-4bdc-9b40-443c02de0b81", "value": "933e8206dd259578c14ffecf9166ac937c6f2c49f0fb8a126283f7211a442fe5" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: cfd1a77155b9af917e22a8ac0fe16eeb26e00c6e", "deleted": false, "disable_correlation": false, "timestamp": "1461578532", "to_ids": true, "type": "md5", "uuid": "571deb24-4c08-4a14-a26b-498402de0b81", "value": "10492d71bf833499217c0a3f48278dc0" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461578532", "to_ids": false, "type": "link", "uuid": "571deb24-2ce8-44f5-9c39-442302de0b81", "value": "https://www.virustotal.com/file/933e8206dd259578c14ffecf9166ac937c6f2c49f0fb8a126283f7211a442fe5/analysis/1461238630/" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: acaeb29abf2458b862646366917f44e987176ec9", "deleted": false, "disable_correlation": false, "timestamp": "1461578532", "to_ids": true, "type": "sha256", "uuid": "571deb24-d6e8-4a42-81a0-483f02de0b81", "value": "c8ec0981f22303b81f5463dce7e9bb3d34f9c162710be9fb766ecaad86a9afa3" }, { "category": "Payload delivery", "comment": "Imported via the freetext import. - Xchecked via VT: acaeb29abf2458b862646366917f44e987176ec9", "deleted": false, "disable_correlation": false, "timestamp": "1461578532", "to_ids": true, "type": "md5", "uuid": "571deb24-2bd8-4613-a160-40fc02de0b81", "value": "f0e55995b81e974e9df4d1c060bc4bcc" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1461578532", "to_ids": false, "type": "link", "uuid": "571deb25-dc48-496f-9cb9-401d02de0b81", "value": "https://www.virustotal.com/file/c8ec0981f22303b81f5463dce7e9bb3d34f9c162710be9fb766ecaad86a9afa3/analysis/1461421373/" }, { "category": "External analysis", "comment": "Imported via the freetext import. - Xchecked via VT: 04fffc28bed615d7da50c0286290d452b9c5ee50 - Xchecked via VT: 30bcc5a700e08c91095c3a8e6c52495a6b60f9ff07ac3c0b96e75befc44b1f5a", "deleted": false, "disable_correlation": false, "timestamp": "1461589773", "to_ids": false, "type": "link", "uuid": "571e170d-e06c-4485-9a7a-40e802de0b81", "value": "https://www.virustotal.com/file/30bcc5a700e08c91095c3a8e6c52495a6b60f9ff07ac3c0b96e75befc44b1f5a/analysis/1461585661/" } ] } }