199 lines
No EOL
7.4 KiB
JSON
199 lines
No EOL
7.4 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "2",
|
|
"date": "2016-08-30",
|
|
"extends_uuid": "",
|
|
"info": "OSINT - German Speakers Targeted by SPAM Leading to Ozone RAT",
|
|
"publish_timestamp": "1472540292",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1472540179",
|
|
"uuid": "57c52bbb-6a08-4121-951c-417c950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#3a7300",
|
|
"local": false,
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#440055",
|
|
"local": false,
|
|
"name": "ms-caro-malware:malware-type=\"RemoteAccess\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": false,
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#004646",
|
|
"local": false,
|
|
"name": "type:OSINT",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539633",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "57c52bf1-4f04-4466-9c0e-4404950d210f",
|
|
"value": "https://blog.fortinet.com/2016/08/29/german-speakers-targeted-by-spam-leading-to-ozone-rat"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539655",
|
|
"to_ids": false,
|
|
"type": "comment",
|
|
"uuid": "57c52c07-b4c0-4e66-82f0-4cce950d210f",
|
|
"value": "Remote Administration Tools (RAT) have been around for a long time. They provide users and administrators with the convenience of being able to take full control of their systems without needing to be physically in front of a device. In this age of global operations, that\u00e2\u20ac\u2122s a huge deal. From troubleshooting machines across countries to observing employees across rooms, RAT solutions have become widely used tools for remote maintenance and monitoring.\r\n\r\nUnfortunately, malware authors often utilize these same capabilities to compromise systems. Full remote access capabilities is a dream tool for the black hat community, and are highly sought after.\r\n\r\nAs a case in point, we recently discovered a SPAM campaign targeting German-speaking users that involves a relatively new commercialized RAT called Ozone."
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "W32/OzoneRAT.A!tr",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539688",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "57c52c28-a71c-4e6e-820c-47c7950d210f",
|
|
"value": "70ece9b44f54fa5ac525908da412bf707ce7fae08a8f2b8134f34133df43e982"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "-JS/Nemucod.C060!tr.dldr",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539689",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "57c52c29-5318-4609-a82d-45d2950d210f",
|
|
"value": "71f1073d0b8aabaf0a2481e9b7c1cd0ca906fee719b45f7d4722d01884c75a17"
|
|
},
|
|
{
|
|
"category": "Antivirus detection",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539778",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "57c52c82-fc9c-4129-9ee1-411b950d210f",
|
|
"value": "W32/OzoneRAT"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "-JS/Nemucod.C060!tr.dldr - Xchecked via VT: 71f1073d0b8aabaf0a2481e9b7c1cd0ca906fee719b45f7d4722d01884c75a17",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539863",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "57c52cd7-b104-4683-befc-493902de0b81",
|
|
"value": "e118c60fbe73cdf3144ecadf97e8a79d3e3f2d4f"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "-JS/Nemucod.C060!tr.dldr - Xchecked via VT: 71f1073d0b8aabaf0a2481e9b7c1cd0ca906fee719b45f7d4722d01884c75a17",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539864",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "57c52cd8-e704-4998-9eac-465602de0b81",
|
|
"value": "e49ae5faaf3b2cdef6d55481f55c3819"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "-JS/Nemucod.C060!tr.dldr - Xchecked via VT: 71f1073d0b8aabaf0a2481e9b7c1cd0ca906fee719b45f7d4722d01884c75a17",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539864",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "57c52cd8-d17c-41eb-99e3-462902de0b81",
|
|
"value": "https://www.virustotal.com/file/71f1073d0b8aabaf0a2481e9b7c1cd0ca906fee719b45f7d4722d01884c75a17/analysis/1471782216/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "W32/OzoneRAT.A!tr - Xchecked via VT: 70ece9b44f54fa5ac525908da412bf707ce7fae08a8f2b8134f34133df43e982",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539864",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "57c52cd8-13bc-4cd7-b5c1-451d02de0b81",
|
|
"value": "9723f64aa74b32ffe86cef380f3e8397fe754c9e"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "W32/OzoneRAT.A!tr - Xchecked via VT: 70ece9b44f54fa5ac525908da412bf707ce7fae08a8f2b8134f34133df43e982",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539864",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "57c52cd8-d148-4252-897d-453f02de0b81",
|
|
"value": "01e438effb7eb350308ffc0c2d0a60b4"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "W32/OzoneRAT.A!tr - Xchecked via VT: 70ece9b44f54fa5ac525908da412bf707ce7fae08a8f2b8134f34133df43e982",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472539865",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "57c52cd9-b02c-4f91-b14e-407a02de0b81",
|
|
"value": "https://www.virustotal.com/file/70ece9b44f54fa5ac525908da412bf707ce7fae08a8f2b8134f34133df43e982/analysis/1471603833/"
|
|
},
|
|
{
|
|
"category": "Attribution",
|
|
"comment": "ciboryn (Skype account)",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472540106",
|
|
"to_ids": false,
|
|
"type": "threat-actor",
|
|
"uuid": "57c52dca-2844-4603-828f-4905950d210f",
|
|
"value": "ciboryn"
|
|
},
|
|
{
|
|
"category": "Attribution",
|
|
"comment": "XMPP account of the RAT seller",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472540153",
|
|
"to_ids": false,
|
|
"type": "threat-actor",
|
|
"uuid": "57c52df9-af58-4f21-917b-4379950d210f",
|
|
"value": "cibor@jabbim.com"
|
|
},
|
|
{
|
|
"category": "Attribution",
|
|
"comment": "Email of the RAT seller",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1472540179",
|
|
"to_ids": false,
|
|
"type": "threat-actor",
|
|
"uuid": "57c52e13-6bd8-4b73-96f2-46c7950d210f",
|
|
"value": "cibosales@gmail.com"
|
|
}
|
|
]
|
|
}
|
|
} |