{"Event": {"info": "OSINT - Attack on Critical Infrastructure Leverages Template Injection", "Tag": [{"colour": "#ffffff", "exportable": true, "name": "tlp:white"}, {"colour": "#ff8e41", "exportable": true, "name": "certsi:critical-sector=\"energy\""}, {"colour": "#00223b", "exportable": true, "name": "osint:source-type=\"blog-post\""}], "publish_timestamp": "1499463607", "timestamp": "1511418228", "analysis": "2", "Attribute": [{"comment": "", "category": "External analysis", "uuid": "595ffec5-ab90-496e-8edf-41bc02de0b81", "timestamp": "1499463588", "to_ids": false, "value": "http://blog.talosintelligence.com/2017/07/template-injection.html", "Tag": [{"colour": "#00223b", "exportable": true, "name": "osint:source-type=\"blog-post\""}], "disable_correlation": false, "object_relation": null, "type": "link"}, {"comment": "", "category": "External analysis", "uuid": "595ffed7-8f20-4ae7-839f-419c02de0b81", "timestamp": "1499463588", "to_ids": false, "value": "Attackers are continually trying to find new ways to target users with malware sent via email. Talos has identified an email-based attack targeting the energy sector, including nuclear power, that puts a new spin on the classic word document attachment phish. Typically, malicious Word documents that are sent as attachments to phishing emails will themselves contain a script or macro that executes malicious code. In this case, there is no malicious code in the attachment itself. The attachment instead tries to download a template file over an SMB connection so that the user's credentials can be silently harvested. In addition, this template file could also potentially be used to download other malicious payloads to the victim's computer.", "Tag": [{"colour": "#00223b", "exportable": true, "name": "osint:source-type=\"blog-post\""}], "disable_correlation": false, "object_relation": null, "type": "text"}, {"comment": "Related IP Address", "category": "Network activity", "uuid": "595fff2d-3c18-4ae2-98c6-46f902de0b81", "timestamp": "1499463555", "to_ids": true, "value": "184.154.150.66", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "Related IP Address", "category": "Network activity", "uuid": "595fff2d-b108-4f78-bd75-437a02de0b81", "timestamp": "1499463555", "to_ids": true, "value": "5.153.58.45", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "Related IP Address", "category": "Network activity", "uuid": "595fff2d-e9fc-439a-b74a-417c02de0b81", "timestamp": "1499463555", "to_ids": true, "value": "62.8.193.206", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "Controls Engineer.docx", "category": "Payload delivery", "uuid": "595fff43-ea00-4f5c-b80d-478f02de0b81", "timestamp": "1499463555", "to_ids": true, "value": "b02508baf8567e62f3c0fd14833c82fb24e8ba4f0dc84aeb7690d9ea83385baa", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Controls Engineer.docx", "category": "Payload delivery", "uuid": "595fff43-ef64-46c8-a17f-42e302de0b81", "timestamp": "1499463555", "to_ids": true, "value": "3d6eadf0f0b3fb7f996e6eb3d540945c2d736822df1a37dcd0e25371fa2d75a0", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Controls Engineer.docx", "category": "Payload delivery", "uuid": "595fff43-90e4-4bab-896b-41df02de0b81", "timestamp": "1499463555", "to_ids": true, "value": "ac6c1df3895af63b864bb33bf30cb31059e247443ddb8f23517849362ec94f08", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "", "category": "Payload delivery", "uuid": "595fff5c-5e24-4630-851a-4a4b02de0b81", "timestamp": "1499463555", "to_ids": true, "value": "Report03-23-2017.docx", "disable_correlation": false, "object_relation": null, "type": "filename"}, {"comment": "Report03-23-2017.docx", "category": "Payload delivery", "uuid": "595fff5c-89b0-40fc-83ce-498702de0b81", "timestamp": "1499463555", "to_ids": true, "value": "93cd6696e150caf6106e6066b58107372dcf43377bf4420c848007c10ff80bc9", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Report03-23-2017.docx - Xchecked via VT: 93cd6696e150caf6106e6066b58107372dcf43377bf4420c848007c10ff80bc9", "category": "Payload delivery", "uuid": "595fff83-90dc-49bb-adfb-474102de0b81", "timestamp": "1499463555", "to_ids": true, "value": "67175f1de3a911958e4c075336160462df3ea7b1", "disable_correlation": false, "object_relation": null, "type": "sha1"}, {"comment": "Report03-23-2017.docx - Xchecked via VT: 93cd6696e150caf6106e6066b58107372dcf43377bf4420c848007c10ff80bc9", "category": "Payload delivery", "uuid": "595fff83-4b40-4ca6-b436-4b7b02de0b81", "timestamp": "1499463555", "to_ids": true, "value": "3c432a21cfd05f976af8c47a007928f7", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "Report03-23-2017.docx - Xchecked via VT: 93cd6696e150caf6106e6066b58107372dcf43377bf4420c848007c10ff80bc9", "category": "External analysis", "uuid": "595fff83-6fa4-4702-8563-40cf02de0b81", "timestamp": "1499463555", "to_ids": false, "value": "https://www.virustotal.com/file/93cd6696e150caf6106e6066b58107372dcf43377bf4420c848007c10ff80bc9/analysis/1499449645/", "disable_correlation": false, "object_relation": null, "type": "link"}, {"comment": "Controls Engineer.docx - Xchecked via VT: ac6c1df3895af63b864bb33bf30cb31059e247443ddb8f23517849362ec94f08", "category": "Payload delivery", "uuid": "595fff83-099c-4d69-8fd3-4ff202de0b81", "timestamp": "1499463555", "to_ids": true, "value": "2872dcdf108563d16b6cf2ed383626861fc541d2", "disable_correlation": false, "object_relation": null, "type": "sha1"}, {"comment": "Controls Engineer.docx - Xchecked via VT: ac6c1df3895af63b864bb33bf30cb31059e247443ddb8f23517849362ec94f08", "category": "Payload delivery", "uuid": "595fff83-6c80-4097-a592-449902de0b81", "timestamp": "1499463555", "to_ids": true, "value": "722154a36f32ba10e98020a8ad758a7a", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "Controls Engineer.docx - Xchecked via VT: ac6c1df3895af63b864bb33bf30cb31059e247443ddb8f23517849362ec94f08", "category": "External analysis", "uuid": "595fff83-28d8-4599-ab7e-411a02de0b81", "timestamp": "1499463555", "to_ids": false, "value": "https://www.virustotal.com/file/ac6c1df3895af63b864bb33bf30cb31059e247443ddb8f23517849362ec94f08/analysis/1499451984/", "disable_correlation": false, "object_relation": null, "type": "link"}, {"comment": "Controls Engineer.docx - Xchecked via VT: 3d6eadf0f0b3fb7f996e6eb3d540945c2d736822df1a37dcd0e25371fa2d75a0", "category": "Payload delivery", "uuid": "595fff83-f46c-47e4-9a96-45d202de0b81", "timestamp": "1499463555", "to_ids": true, "value": "421eecdfe4f6987bb9ff7a6d65827563e53eafbb", "disable_correlation": false, "object_relation": null, "type": "sha1"}, {"comment": "Controls Engineer.docx - Xchecked via VT: 3d6eadf0f0b3fb7f996e6eb3d540945c2d736822df1a37dcd0e25371fa2d75a0", "category": "Payload delivery", "uuid": "595fff83-bab4-47da-ae9a-492602de0b81", "timestamp": "1499463555", "to_ids": true, "value": "4e4e9aac289f1c55e50227e2de66463b", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "Controls Engineer.docx - Xchecked via VT: 3d6eadf0f0b3fb7f996e6eb3d540945c2d736822df1a37dcd0e25371fa2d75a0", "category": "External analysis", "uuid": "595fff83-9aa8-4361-bf50-42a502de0b81", "timestamp": "1499463555", "to_ids": false, "value": "https://www.virustotal.com/file/3d6eadf0f0b3fb7f996e6eb3d540945c2d736822df1a37dcd0e25371fa2d75a0/analysis/1499463315/", "disable_correlation": false, "object_relation": null, "type": "link"}, {"comment": "Controls Engineer.docx - Xchecked via VT: b02508baf8567e62f3c0fd14833c82fb24e8ba4f0dc84aeb7690d9ea83385baa", "category": "Payload delivery", "uuid": "595fff83-72e0-4302-9540-494302de0b81", "timestamp": "1499463555", "to_ids": true, "value": "5df2cb4b3a29adad4ba0a8f0b7eab5b6ae633977", "disable_correlation": false, "object_relation": null, "type": "sha1"}, {"comment": "Controls Engineer.docx - Xchecked via VT: b02508baf8567e62f3c0fd14833c82fb24e8ba4f0dc84aeb7690d9ea83385baa", "category": "Payload delivery", "uuid": "595fff83-5cac-4e37-8a69-447502de0b81", "timestamp": "1499463555", "to_ids": true, "value": "4909db36f71106379832c8ca57ba5be8", "disable_correlation": false, "object_relation": null, "type": "md5"}, {"comment": "Controls Engineer.docx - Xchecked via VT: b02508baf8567e62f3c0fd14833c82fb24e8ba4f0dc84aeb7690d9ea83385baa", "category": "External analysis", "uuid": "595fff83-fbdc-41f5-b908-47cf02de0b81", "timestamp": "1499463555", "to_ids": false, "value": "https://www.virustotal.com/file/b02508baf8567e62f3c0fd14833c82fb24e8ba4f0dc84aeb7690d9ea83385baa/analysis/1499445440/", "disable_correlation": false, "object_relation": null, "type": "link"}], "extends_uuid": "", "published": false, "date": "2017-07-07", "Orgc": {"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f", "name": "CIRCL"}, "threat_level_id": "3", "uuid": "595ffeba-0eac-4c22-953c-c6c402de0b81"}}