263 lines
No EOL
12 KiB
JSON
263 lines
No EOL
12 KiB
JSON
{
|
|
"type": "bundle",
|
|
"id": "bundle--56f419c3-e67c-45fc-b3a6-40d5950d210f",
|
|
"objects": [
|
|
{
|
|
"type": "identity",
|
|
"spec_version": "2.1",
|
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:49:37.000Z",
|
|
"modified": "2016-03-24T16:49:37.000Z",
|
|
"name": "CIRCL",
|
|
"identity_class": "organization"
|
|
},
|
|
{
|
|
"type": "report",
|
|
"spec_version": "2.1",
|
|
"id": "report--56f419c3-e67c-45fc-b3a6-40d5950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:49:37.000Z",
|
|
"modified": "2016-03-24T16:49:37.000Z",
|
|
"name": "OSINT - Malware is being signed with multiple digital certificates to evade detection",
|
|
"published": "2016-03-24T16:49:24Z",
|
|
"object_refs": [
|
|
"observed-data--56f419fb-886c-4e3f-bfcc-4d88950d210f",
|
|
"url--56f419fb-886c-4e3f-bfcc-4d88950d210f",
|
|
"x-misp-attribute--56f41a14-78c0-4c47-b903-4b78950d210f",
|
|
"indicator--56f41a2f-d8bc-40a5-abe2-448a950d210f",
|
|
"indicator--56f41a58-31a4-42b8-9407-4d8f950d210f",
|
|
"indicator--56f41a63-ff4c-4fba-a9b7-4160950d210f",
|
|
"observed-data--56f41a7f-6e54-4ef5-92ee-fc04950d210f",
|
|
"url--56f41a7f-6e54-4ef5-92ee-fc04950d210f",
|
|
"indicator--56f41aa1-e91c-4c04-8da7-409102de0b81",
|
|
"indicator--56f41aa1-686c-4afa-b06a-4b4502de0b81",
|
|
"observed-data--56f41aa2-3ca4-422b-8b7a-4b3502de0b81",
|
|
"url--56f41aa2-3ca4-422b-8b7a-4b3502de0b81"
|
|
],
|
|
"labels": [
|
|
"Threat-Report",
|
|
"misp:tool=\"MISP-STIX-Converter\"",
|
|
"type:OSINT"
|
|
],
|
|
"object_marking_refs": [
|
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
|
]
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--56f419fb-886c-4e3f-bfcc-4d88950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:46:51.000Z",
|
|
"modified": "2016-03-24T16:46:51.000Z",
|
|
"first_observed": "2016-03-24T16:46:51Z",
|
|
"last_observed": "2016-03-24T16:46:51Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--56f419fb-886c-4e3f-bfcc-4d88950d210f"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"link\"",
|
|
"misp:category=\"External analysis\""
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--56f419fb-886c-4e3f-bfcc-4d88950d210f",
|
|
"value": "http://www.symantec.com/connect/blogs/malware-being-signed-multiple-digital-certificates-evade-detection"
|
|
},
|
|
{
|
|
"type": "x-misp-attribute",
|
|
"spec_version": "2.1",
|
|
"id": "x-misp-attribute--56f41a14-78c0-4c47-b903-4b78950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:47:16.000Z",
|
|
"modified": "2016-03-24T16:47:16.000Z",
|
|
"labels": [
|
|
"misp:type=\"comment\"",
|
|
"misp:category=\"External analysis\""
|
|
],
|
|
"x_misp_category": "External analysis",
|
|
"x_misp_type": "comment",
|
|
"x_misp_value": "Symantec has recently observed various malware families seen in the wild signed with multiple digital certificates. As seen with Suckfly, valid, legitimate certificates can be stolen from an organization, often without their knowledge, and then used to sign malware to evade detection. In this case, attackers have used multiple digital certificates together to increase the chance that the targeted computer considers their malware safe. The attacker's ultimate goal is that their attack goes completely undetected.\r\n\r\nHistorically, attacks have focused on the SHA1 algorithm. This prompted businesses and IT departments at various organizations to distrust SHA1 certificates and gradually move to SHA2. Microsoft\u00e2\u20ac\u2122s discontinuation of support for files signed with SHA1, may indicate a paradigm shift in the digital certificate space.\r\n\r\nEarlier last year, Microsoft announced the discontinuation of support for files digitally signed with a SHA1 signature after January 1, 2016 in certain scenarios. According to the new enforcement details, code signing certificates signed after January 1, 2016 will not be honored by Microsoft Windows (version dependent). These new restrictions have started to force attackers to move away from SHA1 and to figure out new ways to use SHA2 digitally signed certificates.\r\n\r\nWhile this change may have slowed down attackers, malware authors have been looking for ways to adapt to this new policy.\r\n\r\nEarlier this week we came across a spam campaign using a malicious Word document that downloads a payload to compromise the computer. In this case, the payload is Trojan.Carberp.B, a well-known financial Trojan that targets financial institutions and their customers. Our current telemetry reports that the attacks are contained to the following countries:"
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--56f41a2f-d8bc-40a5-abe2-448a950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:47:43.000Z",
|
|
"modified": "2016-03-24T16:47:43.000Z",
|
|
"pattern": "[file:hashes.SHA256 = '9758aa737004fc3fc6bc7d535e604324b6e42c7c19459f575083a411a4774b18']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2016-03-24T16:47:43Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"sha256\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--56f41a58-31a4-42b8-9407-4d8f950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:48:24.000Z",
|
|
"modified": "2016-03-24T16:48:24.000Z",
|
|
"description": "Imported via the freetext import.",
|
|
"pattern": "[url:value = '154.16.138.74/sexit.exe']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2016-03-24T16:48:24Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"url\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--56f41a63-ff4c-4fba-a9b7-4160950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:48:35.000Z",
|
|
"modified": "2016-03-24T16:48:35.000Z",
|
|
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '154.16.138.74']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2016-03-24T16:48:35Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Network activity"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"ip-dst\"",
|
|
"misp:category=\"Network activity\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--56f41a7f-6e54-4ef5-92ee-fc04950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:49:03.000Z",
|
|
"modified": "2016-03-24T16:49:03.000Z",
|
|
"first_observed": "2016-03-24T16:49:03Z",
|
|
"last_observed": "2016-03-24T16:49:03Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--56f41a7f-6e54-4ef5-92ee-fc04950d210f"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"link\"",
|
|
"misp:category=\"External analysis\""
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--56f41a7f-6e54-4ef5-92ee-fc04950d210f",
|
|
"value": "https://malwr.com/analysis/NmFmNzhhYjYyODIwNGUxMzliMGRlMWM5NjYwNzUxNzk/"
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--56f41aa1-e91c-4c04-8da7-409102de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:49:37.000Z",
|
|
"modified": "2016-03-24T16:49:37.000Z",
|
|
"description": "- Xchecked via VT: 9758aa737004fc3fc6bc7d535e604324b6e42c7c19459f575083a411a4774b18",
|
|
"pattern": "[file:hashes.SHA1 = '9155973df9080ce996ae372e20d56795b58e2eeb']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2016-03-24T16:49:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"sha1\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--56f41aa1-686c-4afa-b06a-4b4502de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:49:37.000Z",
|
|
"modified": "2016-03-24T16:49:37.000Z",
|
|
"description": "- Xchecked via VT: 9758aa737004fc3fc6bc7d535e604324b6e42c7c19459f575083a411a4774b18",
|
|
"pattern": "[file:hashes.MD5 = 'a06bf47c5147ad1b336633112a4a42a8']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2016-03-24T16:49:37Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"md5\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\""
|
|
]
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--56f41aa2-3ca4-422b-8b7a-4b3502de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2016-03-24T16:49:38.000Z",
|
|
"modified": "2016-03-24T16:49:38.000Z",
|
|
"first_observed": "2016-03-24T16:49:38Z",
|
|
"last_observed": "2016-03-24T16:49:38Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--56f41aa2-3ca4-422b-8b7a-4b3502de0b81"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"link\"",
|
|
"misp:category=\"External analysis\""
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--56f41aa2-3ca4-422b-8b7a-4b3502de0b81",
|
|
"value": "https://www.virustotal.com/file/9758aa737004fc3fc6bc7d535e604324b6e42c7c19459f575083a411a4774b18/analysis/1458837563/"
|
|
},
|
|
{
|
|
"type": "marking-definition",
|
|
"spec_version": "2.1",
|
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
|
"created": "2017-01-20T00:00:00.000Z",
|
|
"definition_type": "tlp",
|
|
"name": "TLP:WHITE",
|
|
"definition": {
|
|
"tlp": "white"
|
|
}
|
|
}
|
|
]
|
|
} |