1 line
No EOL
11 KiB
JSON
1 line
No EOL
11 KiB
JSON
{"Event": {"info": "OSINT - Malware Used by \u201cRocke\u201d Group Evolves to Evade Detection by Cloud Security Products", "Tag": [{"colour": "#0088cc", "exportable": true, "name": "misp-galaxy:tool=\"Xbash\""}, {"colour": "#004646", "exportable": true, "name": "type:OSINT"}, {"colour": "#0071c3", "exportable": true, "name": "osint:lifetime=\"perpetual\""}, {"colour": "#0087e8", "exportable": true, "name": "osint:certainty=\"50\""}, {"colour": "#ffffff", "exportable": true, "name": "tlp:white"}], "publish_timestamp": "0", "timestamp": "1547935810", "analysis": "0", "Attribute": [{"comment": "", "category": "External analysis", "uuid": "5c439eef-3ac4-4434-80cd-439402de0b81", "timestamp": "1547935471", "to_ids": false, "value": "https://unit42.paloaltonetworks.com/malware-used-by-rocke-group-evolves-to-evade-detection-by-cloud-security-products/", "disable_correlation": false, "object_relation": null, "type": "link"}, {"comment": "", "category": "External analysis", "uuid": "5c439f03-fadc-4d85-b07d-45f902de0b81", "timestamp": "1547935491", "to_ids": false, "value": "Palo Alto Networks Unit 42 recently captured and investigated new samples of the Linux coin mining malware used by the Rocke group. The family was suspected to be developed by the Iron cybercrime group and it\u2019s also associated with the Xbash malware we reported on in September of 2018. The threat actor Rocke was originally revealed by Talos in August of 2018 and many remarkable behaviors were disclosed in their blog post. The samples described in this report were collected in October of 2018, and since that time the command and control servers they use have been shut down.\r\n\r\nDuring our analysis, we realized that these samples used by the Rocke group adopted new code to uninstall five different cloud security protection and monitoring products from compromised Linux servers. In our analysis, these attacks did not compromise these security products: rather, the attacks first gained full administrative control over the hosts and then abused that full administrative control to uninstall these products in the same way a legitimate administrator would.\r\n\r\nThese products were developed by Tencent Cloud and Alibaba Cloud (Aliyun), the two leading cloud providers in China that are expanding their business globally. To the best of our knowledge, this is the first malware family that developed the unique capability to target and remove cloud security products. This also highlights a new challenge for products in the Cloud Workload Protection Platforms market defined by Gartner.", "disable_correlation": false, "object_relation": null, "type": "text"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd1-ece0-421c-90e3-43ea02de0b81", "timestamp": "1547935697", "to_ids": true, "value": "2e3e8f980fde5757248e1c72ab8857eb2aea9ef4a37517261a1b013e3dc9e3c4", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd2-77e4-4abd-b606-43bc02de0b81", "timestamp": "1547935698", "to_ids": true, "value": "2f603054dda69c2ac1e49c916ea4a4b1ae6961ec3c01d65f16929d445a564355", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd2-d5b8-4f82-8273-4f0f02de0b81", "timestamp": "1547935698", "to_ids": true, "value": "28ea5d2e44538cd7fec11a28cce7c86fe208b2e8f53d57bf8a18957adb90c5ab", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd3-fa2c-45d9-9b5e-42fe02de0b81", "timestamp": "1547935699", "to_ids": true, "value": "232c771f38da79d5b8f7c6c57ddb4f7a8d6d44f8bca41be4407ed4923096c700", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd3-c2dc-4594-9f10-4bf102de0b81", "timestamp": "1547935699", "to_ids": true, "value": "893bdc6b7d2d7134b1ceb5445dbb97ad9c731a427490d59f6858a835525d8417", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd4-1124-4102-9368-4ed302de0b81", "timestamp": "1547935700", "to_ids": true, "value": "9300f1aa56a73887d05672bfb9862bd786230142c949732c208e5e019d14f83a", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd4-01f8-4ac0-a5b4-459b02de0b81", "timestamp": "1547935700", "to_ids": true, "value": "27611b92d31289d023d962d3eb7c6abd194dbdbbe4e6977c42d94883553841e8", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd5-8420-4ab4-a273-44bc02de0b81", "timestamp": "1547935701", "to_ids": true, "value": "d341e3a9133e534ca35d5ccc54b8a79f93ff0c917790e7d5f73fedaa480a6b93", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd5-4654-4d2d-9b36-487302de0b81", "timestamp": "1547935701", "to_ids": true, "value": "ed038e9ea922af9f0bf5e8be42b394650fa808982d5d555e6c50c715ff2cca0c", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd5-e8dc-473b-86e5-4d9002de0b81", "timestamp": "1547935701", "to_ids": true, "value": "4b74c4d66387c70658238ac5ab392e2fe5557f98fe09eadda9259ada0d87c0f1", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd6-49f4-4d06-931c-485502de0b81", "timestamp": "1547935702", "to_ids": true, "value": "e391963f496ba056e9a9f750cbd28ca7a08ac4cfc434bee4fc57a292b11941e6", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Sample with the evasion behavior", "category": "Payload delivery", "uuid": "5c439fd6-a2b0-4338-9f59-47b902de0b81", "timestamp": "1547935702", "to_ids": true, "value": "017dee32e287f37a82cf6e249f8a85b5c9d4f090e5452118ccacaf147e88dc66", "disable_correlation": false, "object_relation": null, "type": "sha256"}, {"comment": "Domain for C2 Communication", "category": "Network activity", "uuid": "5c439fed-0420-461c-be55-4cc602de0b81", "timestamp": "1547935725", "to_ids": true, "value": "dwn.rundll32.ml", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "Domain for C2 Communication", "category": "Network activity", "uuid": "5c439fed-0f38-4a14-9132-4dcd02de0b81", "timestamp": "1547935725", "to_ids": true, "value": "www.aybc.so", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "Domain for C2 Communication", "category": "Network activity", "uuid": "5c439fee-e698-4576-9069-454102de0b81", "timestamp": "1547935726", "to_ids": true, "value": "a.ssvs.space", "disable_correlation": false, "object_relation": null, "type": "hostname"}, {"comment": "Domain for C2 Communication", "category": "Network activity", "uuid": "5c439fee-06d0-4e50-8088-4ceb02de0b81", "timestamp": "1547935726", "to_ids": true, "value": "sydwzl.cn", "disable_correlation": false, "object_relation": null, "type": "domain"}, {"comment": "Tencent Cloud", "category": "Network activity", "uuid": "5c43a015-95b0-4b2a-b150-448302de0b81", "timestamp": "1547935765", "to_ids": true, "value": "118.24.150.172", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "Alibaba Cloud", "category": "Network activity", "uuid": "5c43a016-bbc4-44a7-a771-421a02de0b81", "timestamp": "1547935766", "to_ids": true, "value": "120.55.54.65", "disable_correlation": false, "object_relation": null, "type": "ip-dst"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a03b-da28-4e4a-b608-4cb602de0b81", "timestamp": "1547935803", "to_ids": true, "value": "https://pastebin.com/raw/CnPtQ2tM", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a03c-3e34-4c34-8eaf-40b302de0b81", "timestamp": "1547935804", "to_ids": true, "value": "https://pastebin.com/raw/rjPGgXQE", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a03d-9e9c-4070-bdb5-483402de0b81", "timestamp": "1547935805", "to_ids": true, "value": "https://pastebin.com/raw/1NtRkBc3", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a03d-d640-4185-8c14-436602de0b81", "timestamp": "1547935805", "to_ids": true, "value": "https://pastebin.com/raw/tRxfvbYN", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a03e-2ef8-40e2-b263-477002de0b81", "timestamp": "1547935806", "to_ids": true, "value": "https://pastebin.com/raw/SSCy7mY7", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a03e-d06c-45b0-a1cd-468a02de0b81", "timestamp": "1547935806", "to_ids": true, "value": "https://pastebin.com/raw/VVt27LeH", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a03f-a594-4b47-8297-409d02de0b81", "timestamp": "1547935807", "to_ids": true, "value": "https://pastebin.com/raw/Fj2YdETv", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a03f-bb10-4b78-af31-41a102de0b81", "timestamp": "1547935807", "to_ids": true, "value": "https://pastebin.com/raw/JNPewK6r", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a040-7a9c-4f70-883a-454e02de0b81", "timestamp": "1547935808", "to_ids": true, "value": "https://pastebin.com/raw/TzBeq3AM", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a040-18f0-4b07-b271-4c0602de0b81", "timestamp": "1547935808", "to_ids": true, "value": "https://pastebin.com/raw/eRkrSQfE", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a041-e7dc-4a6e-963e-4c6702de0b81", "timestamp": "1547935809", "to_ids": true, "value": "https://pastebin.com/raw/5bjpjvLP", "disable_correlation": false, "object_relation": null, "type": "url"}, {"comment": "URL for Code Update", "category": "Network activity", "uuid": "5c43a041-ed20-466a-a65c-458202de0b81", "timestamp": "1547935809", "to_ids": true, "value": "https://pastebin.com/raw/Gw7mywhC", "disable_correlation": false, "object_relation": null, "type": "url"}], "extends_uuid": "", "published": false, "date": "2019-01-19", "Orgc": {"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f", "name": "CIRCL"}, "threat_level_id": "3", "uuid": "5c439ed9-0028-4c97-b3a2-4cea02de0b81"}} |