misp-circl-feed/feeds/circl/misp/5948c00e-8440-4137-9952-a922950d210f.json

335 lines
No EOL
14 KiB
JSON

{
"Event": {
"analysis": "2",
"date": "2017-06-20",
"extends_uuid": "",
"info": "OSINT - McAfee Discovers Pinkslipbot Exploiting Infected Machines as Control Servers; Releases Free Tool to Detect, Disable Trojan",
"publish_timestamp": "1497945803",
"published": true,
"threat_level_id": "3",
"timestamp": "1497941046",
"uuid": "5948c00e-8440-4137-9952-a922950d210f",
"Orgc": {
"name": "CIRCL",
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
},
"Tag": [
{
"colour": "#ffffff",
"local": false,
"name": "tlp:white",
"relationship_type": ""
},
{
"colour": "#0ead00",
"local": false,
"name": "misp-galaxy:tool=\"Akbot\"",
"relationship_type": ""
}
],
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": false,
"type": "text",
"uuid": "5948c01e-5cd4-40b5-ac70-41e5950d210f",
"value": "McAfee Labs has discovered that banking malware Pinkslipbot (also known as QakBot/QBot) has used infected machines as control servers since April 2016, even after its capability to steal personal and financial data from the infected machine has been removed by a security product. These include home users whose computers are usually behind a network address translation router. To do so, Pinkslipbot uses universal plug and play (UPnP) to open ports, allowing incoming connections from anyone on the Internet to communicate with the infected machine. As far as we know, Pinkslipbot is the first malware to use infected machines as HTTPS-based control servers and the second executable-based malware to use UPnP for port forwarding after the infamous W32/Conficker worm in 2008.\r\nPinkslipbot is a notorious banking-credential harvester that has been active since 2007. It primarily targets users and enterprises located within the United States and includes components for password stealers, keyloggers, and man-in-the-browser attacks that are used as vectors to steal various kinds of information\u00e2\u20ac\u201dincluding credit cards, social security numbers, online account credentials, email passwords, digital certificates, etc. Pinkslipbot controls a large botnet of more than 500,000 infected machines and steals over a half-million records every day. As a result, this malware has been documented extensively by the antimalware industry. The malware authors are clearly benefiting from Pinkslipbot; they have maintained the code base since 2007 and regularly add new features to it.",
"Tag": [
{
"colour": "#00223b",
"local": false,
"name": "osint:source-type=\"blog-post\"",
"relationship_type": ""
}
]
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": false,
"type": "link",
"uuid": "5948c02a-1448-47b2-a635-a8a6950d210f",
"value": "https://securingtomorrow.mcafee.com/mcafee-labs/mcafee-discovers-pinkslipbot-exploiting-infected-machines-as-control-servers-releases-free-tool-to-detect-disable-trojan/",
"Tag": [
{
"colour": "#00223b",
"local": false,
"name": "osint:source-type=\"blog-post\"",
"relationship_type": ""
}
]
},
{
"category": "Payload delivery",
"comment": "Proxy component droppers",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha256",
"uuid": "5948c03c-c7b0-4892-a21a-4510950d210f",
"value": "22cf76f92aad53db1304dec026b834ad77d2272c7f2eaaabf299e953b98d570e"
},
{
"category": "Payload delivery",
"comment": "Proxy component droppers",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha256",
"uuid": "5948c03c-9cb4-4ad8-8426-4e9b950d210f",
"value": "c23fe9f3a3035edb6fa306c7545cfd05bb310d85983dda5914cd9650c13b41d3"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha256",
"uuid": "5948c048-b978-4ded-8d45-a8a6950d210f",
"value": "730e9864795ed8d6538064551ab95505dff3e92dd67888bee323cb341b2420c6"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha256",
"uuid": "5948c048-4fbc-4cfc-9656-a8a6950d210f",
"value": "af25c5bed96e046ba1e25749ff51f0d8437a1ef66e469b4fd0348e372abc2f7f"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll)",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha256",
"uuid": "5948c048-d744-4618-aefa-a8a6950d210f",
"value": "6d174dd4f29da814170e8f7c40ecd80794e1c27d8d94741a79bd1bd6eb75ea62"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "filename",
"uuid": "5948c080-02e0-41ff-8840-43e6950d210f",
"value": "%APPDATA%\\HardwareMonitor\\hardwaremonitor.dll"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "filename",
"uuid": "5948c080-f950-44f1-bd9e-460b950d210f",
"value": "%ALLUSERSPROFILE%\\HardwareMonitor\\hardwaremonitor.dll"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "filename",
"uuid": "5948c080-3e10-492e-a85b-4b99950d210f",
"value": "%APPDATA%\\HardwareMonitor\\hardwaremonitor.ini"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "filename",
"uuid": "5948c080-7620-4a6f-a9c1-4916950d210f",
"value": "%ALLUSERSPROFILE%\\HardwareMonitor\\hardwaremonitor.ini"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: 6d174dd4f29da814170e8f7c40ecd80794e1c27d8d94741a79bd1bd6eb75ea62",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha1",
"uuid": "5948c1df-8824-4967-96d5-40d902de0b81",
"value": "61979d13bb058424ce585a867148a4cda91c0998"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: 6d174dd4f29da814170e8f7c40ecd80794e1c27d8d94741a79bd1bd6eb75ea62",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "md5",
"uuid": "5948c1df-c12c-42db-b424-46f002de0b81",
"value": "cebfd6d9b0290f933d95be059ea9342c"
},
{
"category": "External analysis",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: 6d174dd4f29da814170e8f7c40ecd80794e1c27d8d94741a79bd1bd6eb75ea62",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": false,
"type": "link",
"uuid": "5948c1df-9fa4-4268-a4f1-45f802de0b81",
"value": "https://www.virustotal.com/file/6d174dd4f29da814170e8f7c40ecd80794e1c27d8d94741a79bd1bd6eb75ea62/analysis/1497765996/"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: af25c5bed96e046ba1e25749ff51f0d8437a1ef66e469b4fd0348e372abc2f7f",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha1",
"uuid": "5948c1df-2078-4d5e-9b04-436302de0b81",
"value": "8fb933995998728aa86da88f7a3b9189412abcdf"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: af25c5bed96e046ba1e25749ff51f0d8437a1ef66e469b4fd0348e372abc2f7f",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "md5",
"uuid": "5948c1df-2cd0-4953-9158-4f4202de0b81",
"value": "91e7262e72ba0cb3e71e00f540ab9f73"
},
{
"category": "External analysis",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: af25c5bed96e046ba1e25749ff51f0d8437a1ef66e469b4fd0348e372abc2f7f",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": false,
"type": "link",
"uuid": "5948c1df-80d0-4d6c-95b3-486e02de0b81",
"value": "https://www.virustotal.com/file/af25c5bed96e046ba1e25749ff51f0d8437a1ef66e469b4fd0348e372abc2f7f/analysis/1497666460/"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: 730e9864795ed8d6538064551ab95505dff3e92dd67888bee323cb341b2420c6",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha1",
"uuid": "5948c1df-fb74-4e22-8fa4-447902de0b81",
"value": "48e7f341d2a887fcbb2974c57f7269ec00c29c85"
},
{
"category": "Payload delivery",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: 730e9864795ed8d6538064551ab95505dff3e92dd67888bee323cb341b2420c6",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "md5",
"uuid": "5948c1df-5098-4512-9ecc-4cb802de0b81",
"value": "72e300fd8a27d1d8afc42dd4b47f7a42"
},
{
"category": "External analysis",
"comment": "Proxy component DLL (internal name: supernode_con.dll) - Xchecked via VT: 730e9864795ed8d6538064551ab95505dff3e92dd67888bee323cb341b2420c6",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": false,
"type": "link",
"uuid": "5948c1df-bb38-4800-8ceb-464002de0b81",
"value": "https://www.virustotal.com/file/730e9864795ed8d6538064551ab95505dff3e92dd67888bee323cb341b2420c6/analysis/1497666456/"
},
{
"category": "Payload delivery",
"comment": "Proxy component droppers - Xchecked via VT: c23fe9f3a3035edb6fa306c7545cfd05bb310d85983dda5914cd9650c13b41d3",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha1",
"uuid": "5948c1df-bad0-4298-9deb-47bd02de0b81",
"value": "56d9dfe06b3847d99c30ce0a8b527e2572eb8d06"
},
{
"category": "Payload delivery",
"comment": "Proxy component droppers - Xchecked via VT: c23fe9f3a3035edb6fa306c7545cfd05bb310d85983dda5914cd9650c13b41d3",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "md5",
"uuid": "5948c1df-c0a8-417d-9604-44eb02de0b81",
"value": "e8e32892204adc612fdcfbc73abd60a0"
},
{
"category": "External analysis",
"comment": "Proxy component droppers - Xchecked via VT: c23fe9f3a3035edb6fa306c7545cfd05bb310d85983dda5914cd9650c13b41d3",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": false,
"type": "link",
"uuid": "5948c1df-b440-4f96-a30d-498c02de0b81",
"value": "https://www.virustotal.com/file/c23fe9f3a3035edb6fa306c7545cfd05bb310d85983dda5914cd9650c13b41d3/analysis/1497316605/"
},
{
"category": "Payload delivery",
"comment": "Proxy component droppers - Xchecked via VT: 22cf76f92aad53db1304dec026b834ad77d2272c7f2eaaabf299e953b98d570e",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "sha1",
"uuid": "5948c1df-1810-4198-81c6-4b3102de0b81",
"value": "c60a05988932f64e60e8482523043f9aded610c7"
},
{
"category": "Payload delivery",
"comment": "Proxy component droppers - Xchecked via VT: 22cf76f92aad53db1304dec026b834ad77d2272c7f2eaaabf299e953b98d570e",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": true,
"type": "md5",
"uuid": "5948c1df-261c-4bd6-857c-400d02de0b81",
"value": "80b6422d6edd2efb3bdc8751ae94efe9"
},
{
"category": "External analysis",
"comment": "Proxy component droppers - Xchecked via VT: 22cf76f92aad53db1304dec026b834ad77d2272c7f2eaaabf299e953b98d570e",
"deleted": false,
"disable_correlation": false,
"timestamp": "1497940447",
"to_ids": false,
"type": "link",
"uuid": "5948c1df-85cc-494c-9319-435e02de0b81",
"value": "https://www.virustotal.com/file/22cf76f92aad53db1304dec026b834ad77d2272c7f2eaaabf299e953b98d570e/analysis/1497898598/"
}
]
}
}