360 lines
No EOL
17 KiB
JSON
360 lines
No EOL
17 KiB
JSON
{
|
|
"type": "bundle",
|
|
"id": "bundle--58d8fea3-e924-4905-9a11-4ea6950d210f",
|
|
"objects": [
|
|
{
|
|
"type": "identity",
|
|
"spec_version": "2.1",
|
|
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:05:52.000Z",
|
|
"modified": "2017-03-27T12:05:52.000Z",
|
|
"name": "CIRCL",
|
|
"identity_class": "organization"
|
|
},
|
|
{
|
|
"type": "report",
|
|
"spec_version": "2.1",
|
|
"id": "report--58d8fea3-e924-4905-9a11-4ea6950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:05:52.000Z",
|
|
"modified": "2017-03-27T12:05:52.000Z",
|
|
"name": "OSINT - Shamoon 2: Delivering Disttrack",
|
|
"published": "2017-03-27T12:23:11Z",
|
|
"object_refs": [
|
|
"observed-data--58d8feea-28d8-49b8-b606-40fa950d210f",
|
|
"url--58d8feea-28d8-49b8-b606-40fa950d210f",
|
|
"x-misp-attribute--58d8fef9-6938-4114-bac6-5fe0950d210f",
|
|
"indicator--58d8ff4a-fbe0-4f74-bb4f-1580950d210f",
|
|
"indicator--58d8ff4b-7820-403e-8f3e-1580950d210f",
|
|
"indicator--58d8ff4e-2c70-4874-abdc-1580950d210f",
|
|
"indicator--58d8ff50-6ea0-43a2-b2b8-1580950d210f",
|
|
"indicator--58d9002b-e568-418a-92c4-3aa902de0b81",
|
|
"indicator--58d9002d-0a30-4fd6-8140-3aa902de0b81",
|
|
"observed-data--58d9002f-0760-4a5f-af91-3aa902de0b81",
|
|
"url--58d9002f-0760-4a5f-af91-3aa902de0b81",
|
|
"indicator--58d90031-3a34-425b-810a-3aa902de0b81",
|
|
"indicator--58d90033-ba7c-4232-9d59-3aa902de0b81",
|
|
"observed-data--58d90034-4324-4c20-a8d6-3aa902de0b81",
|
|
"url--58d90034-4324-4c20-a8d6-3aa902de0b81"
|
|
],
|
|
"labels": [
|
|
"Threat-Report",
|
|
"misp:tool=\"MISP-STIX-Converter\"",
|
|
"misp-galaxy:tool=\"Shamoon\""
|
|
],
|
|
"object_marking_refs": [
|
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
|
]
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--58d8feea-28d8-49b8-b606-40fa950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:05:52.000Z",
|
|
"modified": "2017-03-27T12:05:52.000Z",
|
|
"first_observed": "2017-03-27T12:05:52Z",
|
|
"last_observed": "2017-03-27T12:05:52Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--58d8feea-28d8-49b8-b606-40fa950d210f"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"link\"",
|
|
"misp:category=\"External analysis\"",
|
|
"osint:source-type=\"blog-post\"",
|
|
"PAP:WHITE"
|
|
],
|
|
"object_marking_refs": [
|
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--58d8feea-28d8-49b8-b606-40fa950d210f",
|
|
"value": "http://researchcenter.paloaltonetworks.com/2017/03/unit42-shamoon-2-delivering-disttrack/"
|
|
},
|
|
{
|
|
"type": "x-misp-attribute",
|
|
"spec_version": "2.1",
|
|
"id": "x-misp-attribute--58d8fef9-6938-4114-bac6-5fe0950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:05:52.000Z",
|
|
"modified": "2017-03-27T12:05:52.000Z",
|
|
"labels": [
|
|
"misp:type=\"text\"",
|
|
"misp:category=\"External analysis\"",
|
|
"osint:source-type=\"blog-post\"",
|
|
"PAP:WHITE"
|
|
],
|
|
"object_marking_refs": [
|
|
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
|
|
],
|
|
"x_misp_category": "External analysis",
|
|
"x_misp_type": "text",
|
|
"x_misp_value": "Since late November 2016, the Shamoon 2 attack campaign has brought three waves of destructive attacks to organizations within Saudi Arabia. Our investigation into these attacks has unearthed more details into the method by which the threat actors delivered the Disttrack payload. We have found evidence that the actors use a combination of legitimate tools and batch scripts to deploy the Disttrack payload to hostnames known to the attackers to exist in the targeted network.\r\n\r\nOur analysis shows that the actors likely gathered the list of known hostnames directly from Active Directory or during their network reconnaissance activities conducted from a compromised host. This network reconnaissance, coupled with the credential theft needed to hardcode Disttrack payloads with legitimate username and password credentials, leads us to believe that it is highly likely the threat actors had sustained access to the targeted networks prior to Shamoon 2 attacks. Our research confirms that successful credential theft from targeted organizations was an integral part of the Shamoon 2 attackers\u00e2\u20ac\u2122 playbook, and they used these stolen credentials for remote access and lateral movement.\r\n\r\nOur analysis also shows an actor distributes Disttrack within the targeted network by first compromising a system that is used as the Disttrack distribution server on that network. The actor then uses this server to compromise other systems on the network by using the hostname to copy over and execute the Disttrack malware. On each of these named systems that are successfully compromised, the Disttrack malware will attempt to propagate itself to 256 additional IP addresses on the local network. This rudimentary, but effective, distribution system can enable Disttrack to propagate to additional systems from a single, initially compromised system in a semi-automated fashion.\r\n\r\nIn this posting we also explore a possible connection between Shamoon 2 and the Magic Hound campaign, where we outline evidence of a potential connection between these two attack campaigns. Furthermore, we explore a possible scenario on how these two attack campaigns could have worked in conjunction with each other to execute the Shamoon 2 attacks."
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--58d8ff4a-fbe0-4f74-bb4f-1580950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:05:52.000Z",
|
|
"modified": "2017-03-27T12:05:52.000Z",
|
|
"description": "exec-template.txt",
|
|
"pattern": "[file:hashes.SHA256 = '4919436d87d224f083c77228b48dadfc153ee7ad48dd7d22f0ba0d5090b5cf9b']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2017-03-27T12:05:52Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"sha256\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--58d8ff4b-7820-403e-8f3e-1580950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:05:52.000Z",
|
|
"modified": "2017-03-27T12:05:52.000Z",
|
|
"description": "ok.bat",
|
|
"pattern": "[file:hashes.SHA256 = '5475f35363e2f4b70d4367554f1691f3f849fb68570be1a580f33f98e7e4df4a']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2017-03-27T12:05:52Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"sha256\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--58d8ff4e-2c70-4874-abdc-1580950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:05:52.000Z",
|
|
"modified": "2017-03-27T12:05:52.000Z",
|
|
"description": "pa.exe",
|
|
"pattern": "[file:hashes.SHA256 = '01a461ad68d11b5b5096f45eb54df9ba62c5af413fa9eb544eacb598373a26bc']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2017-03-27T12:05:52Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"sha256\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--58d8ff50-6ea0-43a2-b2b8-1580950d210f",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:05:52.000Z",
|
|
"modified": "2017-03-27T12:05:52.000Z",
|
|
"description": "ntertmgr32.bat",
|
|
"pattern": "[file:hashes.SHA256 = 'c7f937375e8b21dca10ea125e644133de3afc7766a8ca4fc8376470277832d95']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2017-03-27T12:05:52Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"sha256\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--58d9002b-e568-418a-92c4-3aa902de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:06:03.000Z",
|
|
"modified": "2017-03-27T12:06:03.000Z",
|
|
"description": "ntertmgr32.bat - Xchecked via VT: c7f937375e8b21dca10ea125e644133de3afc7766a8ca4fc8376470277832d95",
|
|
"pattern": "[file:hashes.SHA1 = 'd6e98ff295345579e35d8ba21693a64dd80c03a2']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2017-03-27T12:06:03Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"sha1\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--58d9002d-0a30-4fd6-8140-3aa902de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:06:05.000Z",
|
|
"modified": "2017-03-27T12:06:05.000Z",
|
|
"description": "ntertmgr32.bat - Xchecked via VT: c7f937375e8b21dca10ea125e644133de3afc7766a8ca4fc8376470277832d95",
|
|
"pattern": "[file:hashes.MD5 = '271554cff73c3843b9282951f2ea7509']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2017-03-27T12:06:05Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"md5\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--58d9002f-0760-4a5f-af91-3aa902de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:06:07.000Z",
|
|
"modified": "2017-03-27T12:06:07.000Z",
|
|
"first_observed": "2017-03-27T12:06:07Z",
|
|
"last_observed": "2017-03-27T12:06:07Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--58d9002f-0760-4a5f-af91-3aa902de0b81"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"link\"",
|
|
"misp:category=\"External analysis\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--58d9002f-0760-4a5f-af91-3aa902de0b81",
|
|
"value": "https://www.virustotal.com/file/c7f937375e8b21dca10ea125e644133de3afc7766a8ca4fc8376470277832d95/analysis/1488902359/"
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--58d90031-3a34-425b-810a-3aa902de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:06:09.000Z",
|
|
"modified": "2017-03-27T12:06:09.000Z",
|
|
"description": "pa.exe - Xchecked via VT: 01a461ad68d11b5b5096f45eb54df9ba62c5af413fa9eb544eacb598373a26bc",
|
|
"pattern": "[file:hashes.SHA1 = '31754ee85d21ce9188394a939c15a271c2562f93']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2017-03-27T12:06:09Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"sha1\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "indicator",
|
|
"spec_version": "2.1",
|
|
"id": "indicator--58d90033-ba7c-4232-9d59-3aa902de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:06:11.000Z",
|
|
"modified": "2017-03-27T12:06:11.000Z",
|
|
"description": "pa.exe - Xchecked via VT: 01a461ad68d11b5b5096f45eb54df9ba62c5af413fa9eb544eacb598373a26bc",
|
|
"pattern": "[file:hashes.MD5 = '22e9853298c96b1ab89d8f71c4e82302']",
|
|
"pattern_type": "stix",
|
|
"pattern_version": "2.1",
|
|
"valid_from": "2017-03-27T12:06:11Z",
|
|
"kill_chain_phases": [
|
|
{
|
|
"kill_chain_name": "misp-category",
|
|
"phase_name": "Payload delivery"
|
|
}
|
|
],
|
|
"labels": [
|
|
"misp:type=\"md5\"",
|
|
"misp:category=\"Payload delivery\"",
|
|
"misp:to_ids=\"True\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "observed-data",
|
|
"spec_version": "2.1",
|
|
"id": "observed-data--58d90034-4324-4c20-a8d6-3aa902de0b81",
|
|
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
|
|
"created": "2017-03-27T12:06:12.000Z",
|
|
"modified": "2017-03-27T12:06:12.000Z",
|
|
"first_observed": "2017-03-27T12:06:12Z",
|
|
"last_observed": "2017-03-27T12:06:12Z",
|
|
"number_observed": 1,
|
|
"object_refs": [
|
|
"url--58d90034-4324-4c20-a8d6-3aa902de0b81"
|
|
],
|
|
"labels": [
|
|
"misp:type=\"link\"",
|
|
"misp:category=\"External analysis\"",
|
|
"osint:source-type=\"blog-post\""
|
|
]
|
|
},
|
|
{
|
|
"type": "url",
|
|
"spec_version": "2.1",
|
|
"id": "url--58d90034-4324-4c20-a8d6-3aa902de0b81",
|
|
"value": "https://www.virustotal.com/file/01a461ad68d11b5b5096f45eb54df9ba62c5af413fa9eb544eacb598373a26bc/analysis/1490509472/"
|
|
},
|
|
{
|
|
"type": "marking-definition",
|
|
"spec_version": "2.1",
|
|
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
|
|
"created": "2017-01-20T00:00:00.000Z",
|
|
"definition_type": "tlp",
|
|
"name": "TLP:WHITE",
|
|
"definition": {
|
|
"tlp": "white"
|
|
}
|
|
}
|
|
]
|
|
} |