143 lines
No EOL
5.2 KiB
JSON
143 lines
No EOL
5.2 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "2",
|
|
"date": "2017-07-30",
|
|
"extends_uuid": "",
|
|
"info": "OSINT - CowerSnail, from the creators of SambaCry",
|
|
"publish_timestamp": "1501433690",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1501433663",
|
|
"uuid": "597e0ba4-29e0-4ae1-a8a3-ae4f02de0b81",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": false,
|
|
"name": "misp-galaxy:tool=\"CowerSnail\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": false,
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#00223b",
|
|
"local": false,
|
|
"name": "osint:source-type=\"blog-post\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Antivirus detection",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1501433305",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "597e0bba-9014-4e8e-b49d-48e4950d210f",
|
|
"value": "Backdoor.Win32.CowerSnail"
|
|
},
|
|
{
|
|
"category": "Artifacts dropped",
|
|
"comment": "Backdoor.Win32.CowerSnail",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1501433305",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "597e0bd7-c6f8-4476-b5fb-4b8902de0b81",
|
|
"value": "5460ac43725997798bab3eb6474d391f"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "On port 20480",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1501433305",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "597e0beb-d978-430e-9a7b-425302de0b81",
|
|
"value": "cl.ezreal.space"
|
|
},
|
|
{
|
|
"category": "Artifacts dropped",
|
|
"comment": "Backdoor.Win32.CowerSnail - Xchecked via VT: 5460ac43725997798bab3eb6474d391f",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1501433305",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "597e0dd9-2cc0-4c1d-a9e9-43a502de0b81",
|
|
"value": "3fb8a4d2ed4f662a4cb4270bb5f488b79c8758aa6fc5c8b119c78fba38d6b7d1"
|
|
},
|
|
{
|
|
"category": "Artifacts dropped",
|
|
"comment": "Backdoor.Win32.CowerSnail - Xchecked via VT: 5460ac43725997798bab3eb6474d391f",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1501433305",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "597e0dd9-6f90-4623-a8a2-4fba02de0b81",
|
|
"value": "08f423dd9ec9c03320377161f7d73cdac647a765"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "Backdoor.Win32.CowerSnail - Xchecked via VT: 5460ac43725997798bab3eb6474d391f",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1501433305",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "597e0dd9-3114-47d0-ad5f-4e9b02de0b81",
|
|
"value": "https://www.virustotal.com/file/3fb8a4d2ed4f662a4cb4270bb5f488b79c8758aa6fc5c8b119c78fba38d6b7d1/analysis/1501280093/"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1501433663",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "597e0f02-b4dc-4fcf-8e30-466d02de0b81",
|
|
"value": "We recently reported about SambaCry, a new family of Linux Trojans exploiting a vulnerability in the Samba protocol. A week later, Kaspersky Lab analysts managed to detect a malicious program for Windows that was apparently created by the same group responsible for SambaCry. It was the common C&C server that both programs used \u00e2\u20ac\u201c cl.ezreal.space:20480 \u00e2\u20ac\u201c that suggested a relationship between them.\r\n\r\nKaspersky Lab products detect the new malicious program as Backdoor.Win32.CowerSnail. MD5: 5460AC43725997798BAB3EB6474D391F\r\n\r\nCowerSnail was compiled using Qt and linked with various libraries. This framework provides benefits such as cross-platform capability and transferability of the source code between different operating systems. This, however, has an effect on the resulting file size: the user code ends up as a small proportion of a large 3 MB file.",
|
|
"Tag": [
|
|
{
|
|
"colour": "#00223b",
|
|
"local": false,
|
|
"name": "osint:source-type=\"blog-post\"",
|
|
"relationship_type": ""
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1501433663",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "597e0f19-a7f4-49b1-af72-4d2602de0b81",
|
|
"value": "https://securelist.com/cowersnail-from-the-creators-of-sambacry/79087/",
|
|
"Tag": [
|
|
{
|
|
"colour": "#00223b",
|
|
"local": false,
|
|
"name": "osint:source-type=\"blog-post\"",
|
|
"relationship_type": ""
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
} |