misp-circl-feed/feeds/circl/stix-2.1/59e4c923-a6e0-4894-a6a8-994d950d210f.json

261 lines
No EOL
13 KiB
JSON

{
"type": "bundle",
"id": "bundle--59e4c923-a6e0-4894-a6a8-994d950d210f",
"objects": [
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:04:11.000Z",
"modified": "2017-10-16T15:04:11.000Z",
"name": "CIRCL",
"identity_class": "organization"
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--59e4c923-a6e0-4894-a6a8-994d950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:04:11.000Z",
"modified": "2017-10-16T15:04:11.000Z",
"name": "OSINT - BlackOasis APT and new targeted attacks leveraging zero-day exploit",
"published": "2017-10-16T15:04:25Z",
"object_refs": [
"vulnerability--59e4c942-4eb8-44f5-b7cc-9449950d210f",
"indicator--59e4c96e-85bc-46cd-bec2-9448950d210f",
"indicator--59e4c96e-0c9c-4cfe-9482-9448950d210f",
"indicator--59e4c983-e064-4473-b9bc-9375950d210f",
"observed-data--59e4c9b1-358c-47f4-9435-4fe0950d210f",
"url--59e4c9b1-358c-47f4-9435-4fe0950d210f",
"x-misp-attribute--59e4c9e5-ff50-466e-bf41-931b950d210f",
"indicator--59e4ca2c-86f4-49eb-aafb-4a1a02de0b81",
"indicator--59e4ca2c-e124-45a7-bf3d-4c7802de0b81",
"observed-data--59e4ca2c-7160-47d4-9589-463a02de0b81",
"url--59e4ca2c-7160-47d4-9589-463a02de0b81"
],
"labels": [
"Threat-Report",
"misp:tool=\"MISP-STIX-Converter\"",
"misp-galaxy:tool=\"FINSPY\""
],
"object_marking_refs": [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
},
{
"type": "vulnerability",
"spec_version": "2.1",
"id": "vulnerability--59e4c942-4eb8-44f5-b7cc-9449950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"name": "CVE-2017-11292",
"labels": [
"misp:type=\"vulnerability\"",
"misp:category=\"Payload delivery\""
],
"external_references": [
{
"source_name": "cve",
"external_id": "CVE-2017-11292"
}
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--59e4c96e-85bc-46cd-bec2-9448950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"description": "As mentioned earlier, the \u00e2\u20ac\u0153mo.exe\u00e2\u20ac\u009d payload (MD5: 4a49135d2ecc07085a8b7c5925a36c0a) is the newest version of Gamma International\u00e2\u20ac\u2122s FinSpy malware, typically sold to nation states and other law enforcement agencies to use in lawful surveillance operations.",
"pattern": "[file:hashes.MD5 = '4a49135d2ecc07085a8b7c5925a36c0a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2017-10-16T15:03:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--59e4c96e-0c9c-4cfe-9482-9448950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"description": "Download the final payload (FinSpy) from",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '89.45.67.107']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2017-10-16T15:03:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--59e4c983-e064-4473-b9bc-9375950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"description": "Download the final payload (FinSpy) from",
"pattern": "[url:value = 'http://89.45.67.107/rss/mo.exe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2017-10-16T15:03:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"url\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--59e4c9b1-358c-47f4-9435-4fe0950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"first_observed": "2017-10-16T15:03:08Z",
"last_observed": "2017-10-16T15:03:08Z",
"number_observed": 1,
"object_refs": [
"url--59e4c9b1-358c-47f4-9435-4fe0950d210f"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\"",
"osint:source-type=\"blog-post\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--59e4c9b1-358c-47f4-9435-4fe0950d210f",
"value": "https://securelist.com/blackoasis-apt-and-new-targeted-attacks-leveraging-zero-day-exploit/82732/"
},
{
"type": "x-misp-attribute",
"spec_version": "2.1",
"id": "x-misp-attribute--59e4c9e5-ff50-466e-bf41-931b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"labels": [
"misp:type=\"text\"",
"misp:category=\"External analysis\"",
"osint:source-type=\"blog-post\""
],
"x_misp_category": "External analysis",
"x_misp_type": "text",
"x_misp_value": "Kaspersky Lab has always worked closely with vendors to protect users. As soon as we find new vulnerabilities we immediately inform the vendor in a responsible manner and provide all the details required for a fix.\r\n\r\nOn October 10, 2017, Kaspersky Lab\u00e2\u20ac\u2122s advanced exploit prevention systems identified a new Adobe Flash zero day exploit used in the wild against our customers. The exploit was delivered through a Microsoft Office document and the final payload was the latest version of FinSpy malware. We have reported the bug to Adobe who assigned it CVE-2017-11292 and released a patch earlier today:\r\n\r\nSo far only one attack has been observed in our customer base, leading us to believe the number of attacks are minimal and highly targeted.\r\n\r\nAnalysis of the payload allowed us to confidently link this attack to an actor we track as \u00e2\u20ac\u0153BlackOasis\u00e2\u20ac\u009d. We are also highly confident that BlackOasis was also responsible for another zero day exploit (CVE-2017-8759) discovered by FireEye in September 2017. The FinSpy payload used in the current attacks (CVE-2017-11292) shares the same command and control (C2) server as the payload used with CVE-2017-8759 uncovered by FireEye."
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--59e4ca2c-86f4-49eb-aafb-4a1a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"description": "As mentioned earlier, the \u00e2\u20ac\u0153mo.exe\u00e2\u20ac\u009d payload (MD5: 4a49135d2ecc07085a8b7c5925a36c0a) is the newest version of Gamma International\u00e2\u20ac\u2122s FinSpy malware, typically sold to nation states and other law enforcement agencies to use in lawful surveillance operations. - Xchecked via VT: 4a49135d2ecc07085a8b7c5925a36c0a",
"pattern": "[file:hashes.SHA256 = '16070014b86f2254dcf273bbce78fb6eca43df9a6fc3c6ab85ec8f06a4063b06']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2017-10-16T15:03:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--59e4ca2c-e124-45a7-bf3d-4c7802de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"description": "As mentioned earlier, the \u00e2\u20ac\u0153mo.exe\u00e2\u20ac\u009d payload (MD5: 4a49135d2ecc07085a8b7c5925a36c0a) is the newest version of Gamma International\u00e2\u20ac\u2122s FinSpy malware, typically sold to nation states and other law enforcement agencies to use in lawful surveillance operations. - Xchecked via VT: 4a49135d2ecc07085a8b7c5925a36c0a",
"pattern": "[file:hashes.SHA1 = '949da212307259f53b17eb19b353e7c1051fba82']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2017-10-16T15:03:08Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--59e4ca2c-7160-47d4-9589-463a02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2017-10-16T15:03:08.000Z",
"modified": "2017-10-16T15:03:08.000Z",
"first_observed": "2017-10-16T15:03:08Z",
"last_observed": "2017-10-16T15:03:08Z",
"number_observed": 1,
"object_refs": [
"url--59e4ca2c-7160-47d4-9589-463a02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--59e4ca2c-7160-47d4-9589-463a02de0b81",
"value": "https://www.virustotal.com/file/16070014b86f2254dcf273bbce78fb6eca43df9a6fc3c6ab85ec8f06a4063b06/analysis/1508127395/"
},
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
"created": "2017-01-20T00:00:00.000Z",
"definition_type": "tlp",
"name": "TLP:WHITE",
"definition": {
"tlp": "white"
}
}
]
}