269 lines
No EOL
11 KiB
JSON
269 lines
No EOL
11 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "2",
|
|
"date": "2017-03-23",
|
|
"extends_uuid": "",
|
|
"info": "OSINT - Hunt Case Study: Hunting Campaign Indicators on Privacy Protected Attack Infrastructure",
|
|
"publish_timestamp": "1490263329",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1490263277",
|
|
"uuid": "58d39c29-8244-4fcf-a48b-40db950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": false,
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#00223b",
|
|
"local": false,
|
|
"name": "osint:source-type=\"blog-post\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "58d39c3d-8908-4925-8b24-418c950d210f",
|
|
"value": "https://blog.domaintools.com/2017/03/hunt-case-study-hunting-campaign-indicators-on-privacy-protected-attack-infrastructure/",
|
|
"Tag": [
|
|
{
|
|
"colour": "#00223b",
|
|
"local": false,
|
|
"name": "osint:source-type=\"blog-post\"",
|
|
"relationship_type": ""
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "58d39c4e-1eec-4a83-96da-474c950d210f",
|
|
"value": "As a researcher, when I find an attacker working, one of the first places I start to pivot is the command and control infrastructure. I do this because I want to see if I can find additional binaries, indicators of attack, or additional infrastructure being used by an adversary.\r\n\r\nWhen looking at attacker infrastructure, one of the things that annoys analysts the most is attackers using Whois protection services for registering domains that are used as attack infrastructure. At first glance, many analysts will abandon an investigation when finding privacy protected domains. So, in this blog, I intend to show just how you can pivot on a privacy protected indicator of attack infrastructure, and ultimately find good intelligence data.\r\n\r\nPlease keep in mind, in this blog I will not be attributing this activity to any specific nation state. We have indicators that point to a specific actor group, but nation-state attribution is a tricky and near impossible endeavor, therefore we shy away from making any nation-state attribution claims.",
|
|
"Tag": [
|
|
{
|
|
"colour": "#00223b",
|
|
"local": false,
|
|
"name": "osint:source-type=\"blog-post\"",
|
|
"relationship_type": ""
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "58d39c5f-bb60-44f1-a30f-42f8950d210f",
|
|
"value": "212.199.61.51"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "ip-dst",
|
|
"uuid": "58d39c60-3e70-4d30-8732-41e4950d210f",
|
|
"value": "86.105.18.5"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "domain",
|
|
"uuid": "58d39c7e-32e0-4558-911b-4358950d210f",
|
|
"value": "primeminister-goverment-techcenter.tech"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "58d39c80-c7b4-44e7-9a70-4d03950d210f",
|
|
"value": "http://ssl.pmo.gov.il-dana-naauthurl1-welcome.cgi.primeminister-goverment-techcenter.tech"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "58d39c80-26d8-4afd-a1fa-444c950d210f",
|
|
"value": "static.dyn-usr.f-login-me.c19.a23.akamaitechnology.com"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "58d39c81-8f4c-443e-b5b8-4624950d210f",
|
|
"value": "212.199.61.51.static.012.net.il"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Annual Survey.docx and/or \u00d7\u00a1\u00d7\u00a7\u00d7\u00a8\u00d7\u00a9\u00d7\u00a0\u00d7\u00aa\u00d7\u2122.docx",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "58d39ca6-c634-4226-82c4-494e950d210f",
|
|
"value": "5fe0e156a308b48fb2f9577ed3e3b09768976fdd99f6b2d2db5658b138676902"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "PDFOPENER_CONSOLE.exe",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "58d39ca7-64c0-4cae-8562-45e9950d210f",
|
|
"value": "4d657793ddc9c49abe7e4afcf9abb43626e91a18a925223555070c53fd672b59"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "oleObject1.bin",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263277",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "58d39cb8-c2c8-4923-9ef1-4507950d210f",
|
|
"value": "7651f0d886e1c1054eb716352468ec6aedab06ed61e1eebd02bca4efbb974fb6"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "oleObject1.bin - Xchecked via VT: 7651f0d886e1c1054eb716352468ec6aedab06ed61e1eebd02bca4efbb974fb6",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263289",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "58d39cf9-44d0-4837-847e-4bb402de0b81",
|
|
"value": "59c448abaa6cd20ce7af33d6c0ae27e4a853d2bd"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "oleObject1.bin - Xchecked via VT: 7651f0d886e1c1054eb716352468ec6aedab06ed61e1eebd02bca4efbb974fb6",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263290",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "58d39cfa-8a84-40f4-8652-40d002de0b81",
|
|
"value": "b34721e53599286a1093c90a9dd0b789"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "oleObject1.bin - Xchecked via VT: 7651f0d886e1c1054eb716352468ec6aedab06ed61e1eebd02bca4efbb974fb6",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263291",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "58d39cfb-e1fc-4ef3-8864-45e002de0b81",
|
|
"value": "https://www.virustotal.com/file/7651f0d886e1c1054eb716352468ec6aedab06ed61e1eebd02bca4efbb974fb6/analysis/1480095398/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "PDFOPENER_CONSOLE.exe - Xchecked via VT: 4d657793ddc9c49abe7e4afcf9abb43626e91a18a925223555070c53fd672b59",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263292",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "58d39cfc-62b8-493e-bac9-450e02de0b81",
|
|
"value": "15cac8196cc1cec4d3909698fc5d8a5250d826b5"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "PDFOPENER_CONSOLE.exe - Xchecked via VT: 4d657793ddc9c49abe7e4afcf9abb43626e91a18a925223555070c53fd672b59",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263293",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "58d39cfd-4738-4014-ac84-413302de0b81",
|
|
"value": "62f8f45c5f10647af0040f965a3ea96d"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "PDFOPENER_CONSOLE.exe - Xchecked via VT: 4d657793ddc9c49abe7e4afcf9abb43626e91a18a925223555070c53fd672b59",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263294",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "58d39cfe-7a60-4250-b08d-480602de0b81",
|
|
"value": "https://www.virustotal.com/file/4d657793ddc9c49abe7e4afcf9abb43626e91a18a925223555070c53fd672b59/analysis/1480095399/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Annual Survey.docx and/or \u00d7\u00a1\u00d7\u00a7\u00d7\u00a8\u00d7\u00a9\u00d7\u00a0\u00d7\u00aa\u00d7\u2122.docx - Xchecked via VT: 5fe0e156a308b48fb2f9577ed3e3b09768976fdd99f6b2d2db5658b138676902",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263295",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "58d39cff-dbec-4aef-8012-4bd502de0b81",
|
|
"value": "341c920ec47efa4fd1bfcd1859a7fb98945f9d85"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Annual Survey.docx and/or \u00d7\u00a1\u00d7\u00a7\u00d7\u00a8\u00d7\u00a9\u00d7\u00a0\u00d7\u00aa\u00d7\u2122.docx - Xchecked via VT: 5fe0e156a308b48fb2f9577ed3e3b09768976fdd99f6b2d2db5658b138676902",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263296",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "58d39d00-7e14-464a-9970-455f02de0b81",
|
|
"value": "871efc9ecd8a446a7aa06351604a9bf4"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "Annual Survey.docx and/or \u00d7\u00a1\u00d7\u00a7\u00d7\u00a8\u00d7\u00a9\u00d7\u00a0\u00d7\u00aa\u00d7\u2122.docx - Xchecked via VT: 5fe0e156a308b48fb2f9577ed3e3b09768976fdd99f6b2d2db5658b138676902",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1490263298",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "58d39d02-b5d8-437e-9cf0-4ddc02de0b81",
|
|
"value": "https://www.virustotal.com/file/5fe0e156a308b48fb2f9577ed3e3b09768976fdd99f6b2d2db5658b138676902/analysis/1486642481/"
|
|
}
|
|
]
|
|
}
|
|
} |