misp-circl-feed/feeds/circl/misp/571de51c-4f04-491f-b34a-4567950d210f.json

577 lines
No EOL
145 KiB
JSON

{
"type": "bundle",
"id": "bundle--571de51c-4f04-491f-b34a-4567950d210f",
"objects": [
{
"type": "identity",
"spec_version": "2.1",
"id": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-05-17T16:17:00.000Z",
"modified": "2016-05-17T16:17:00.000Z",
"name": "CIRCL",
"identity_class": "organization"
},
{
"type": "report",
"spec_version": "2.1",
"id": "report--571de51c-4f04-491f-b34a-4567950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-05-17T16:17:00.000Z",
"modified": "2016-05-17T16:17:00.000Z",
"name": "OSINT - TWO BYTES TO $951M (SWIFT payment system abuse)",
"published": "2016-05-17T16:17:14Z",
"object_refs": [
"observed-data--571de55b-62c4-4164-a6b8-4912950d210f",
"url--571de55b-62c4-4164-a6b8-4912950d210f",
"x-misp-attribute--571de56d-9d20-4984-9f77-475b950d210f",
"indicator--571de5a5-b484-480f-bf60-4d4b950d210f",
"indicator--571de5a5-c824-4d41-a44b-43da950d210f",
"indicator--571de5a5-d18c-4a5a-b7d8-4b30950d210f",
"indicator--571de5a5-e3f8-46bb-a301-43ff950d210f",
"indicator--571de5be-0198-4c01-a9c7-4bd002de0b81",
"indicator--571de5be-2994-4d3e-ae5b-4aef02de0b81",
"observed-data--571de5be-97cc-48d7-b0df-432102de0b81",
"url--571de5be-97cc-48d7-b0df-432102de0b81",
"indicator--571de5be-8280-488c-a1bf-437502de0b81",
"indicator--571de5be-f358-4523-b8ee-41a202de0b81",
"observed-data--571de5be-941c-4514-b651-4a9202de0b81",
"url--571de5be-941c-4514-b651-4a9202de0b81",
"indicator--571de5bf-ad68-4e97-8c1b-412702de0b81",
"indicator--571de5bf-064c-4a4c-a302-4bdf02de0b81",
"observed-data--571de5bf-0df4-421c-bb52-4f7c02de0b81",
"url--571de5bf-0df4-421c-bb52-4f7c02de0b81",
"indicator--571de5bf-f638-4ae5-820f-473002de0b81",
"indicator--571de5bf-0b34-45ba-b14c-44fd02de0b81",
"observed-data--571de5bf-b9bc-48f8-9821-478602de0b81",
"url--571de5bf-b9bc-48f8-9821-478602de0b81",
"indicator--571de5ef-8fa8-4d8e-a3e1-4c79950d210f",
"indicator--571de60d-6454-4aa4-b4e7-4352950d210f",
"observed-data--571de6a3-4548-4238-8b4d-4396950d210f",
"file--571de6a3-4548-4238-8b4d-4396950d210f",
"artifact--571de6a3-4548-4238-8b4d-4396950d210f"
],
"labels": [
"Threat-Report",
"misp:tool=\"MISP-STIX-Converter\"",
"circl:topic=\"finance\"",
"type:OSINT"
],
"object_marking_refs": [
"marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9"
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--571de55b-62c4-4164-a6b8-4912950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:37:31.000Z",
"modified": "2016-04-25T09:37:31.000Z",
"first_observed": "2016-04-25T09:37:31Z",
"last_observed": "2016-04-25T09:37:31Z",
"number_observed": 1,
"object_refs": [
"url--571de55b-62c4-4164-a6b8-4912950d210f"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--571de55b-62c4-4164-a6b8-4912950d210f",
"value": "http://baesystemsai.blogspot.lu/2016/04/two-bytes-to-951m.html"
},
{
"type": "x-misp-attribute",
"spec_version": "2.1",
"id": "x-misp-attribute--571de56d-9d20-4984-9f77-475b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:37:49.000Z",
"modified": "2016-04-25T09:37:49.000Z",
"labels": [
"misp:type=\"comment\"",
"misp:category=\"External analysis\""
],
"x_misp_category": "External analysis",
"x_misp_type": "comment",
"x_misp_value": "In February 2016 one of the largest cyber heists was committed and subsequently disclosed. An unknown attacker gained access to the Bangladesh Bank\u00e2\u20ac\u2122s (BB) SWIFT payment system and reportedly instructed an American bank to transfer money from BB\u00e2\u20ac\u2122s account to accounts in The Philippines. The attackers attempted to steal $951m, of which $81m is still unaccounted for. \r\n\r\nThe technical details of the attack have yet to be made public, however we\u00e2\u20ac\u2122ve recently identified tools uploaded to online malware repositories that we believe are linked to the heist. The custom malware was submitted by a user in Bangladesh, and contains sophisticated functionality for interacting with local SWIFT Alliance Access software running in the victim infrastructure. \r\n\r\nThis malware appears to be just part of a wider attack toolkit, and would have been used to cover the attackers\u00e2\u20ac\u2122 tracks as they sent forged payment instructions to make the transfers. This would have hampered the detection and response to the attack, giving more time for the subsequent money laundering to take place. \r\n\r\nThe tools are highly configurable and given the correct access could feasibly be used for similar attacks in the future."
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5a5-b484-480f-bf60-4d4b950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:38:45.000Z",
"modified": "2016-04-25T09:38:45.000Z",
"description": "evtdiag.exe",
"pattern": "[file:hashes.SHA1 = '525a8e3ae4e3df8c9c61f2a49e38541d196e9228']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:38:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5a5-c824-4d41-a44b-43da950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:38:45.000Z",
"modified": "2016-04-25T09:38:45.000Z",
"description": "evtsys.exe",
"pattern": "[file:hashes.SHA1 = '76bab478dcc70f979ce62cd306e9ba50ee84e37e']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:38:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5a5-d18c-4a5a-b7d8-4b30950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:38:45.000Z",
"modified": "2016-04-25T09:38:45.000Z",
"description": "nroff_b.exe",
"pattern": "[file:hashes.SHA1 = '70bf16597e375ad691f2c1efa194dbe7f60e4eeb']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:38:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5a5-e3f8-46bb-a301-43ff950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:38:45.000Z",
"modified": "2016-04-25T09:38:45.000Z",
"description": "gpca.dat",
"pattern": "[file:hashes.SHA1 = '6207b92842b28a438330a2bf0ee8dcab7ef0a163']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:38:45Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha1\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5be-0198-4c01-a9c7-4bd002de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:10.000Z",
"modified": "2016-04-25T09:39:10.000Z",
"description": "gpca.dat - Xchecked via VT: 6207b92842b28a438330a2bf0ee8dcab7ef0a163",
"pattern": "[file:hashes.SHA256 = 'b07b37f0246bd436addbe5d702b12485d7bc8a9ef1475b54bff513a18e68fef7']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:10Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5be-2994-4d3e-ae5b-4aef02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:10.000Z",
"modified": "2016-04-25T09:39:10.000Z",
"description": "gpca.dat - Xchecked via VT: 6207b92842b28a438330a2bf0ee8dcab7ef0a163",
"pattern": "[file:hashes.MD5 = 'f7272bb1374bf3af193ea1d1845b27fd']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:10Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--571de5be-97cc-48d7-b0df-432102de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:10.000Z",
"modified": "2016-04-25T09:39:10.000Z",
"first_observed": "2016-04-25T09:39:10Z",
"last_observed": "2016-04-25T09:39:10Z",
"number_observed": 1,
"object_refs": [
"url--571de5be-97cc-48d7-b0df-432102de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--571de5be-97cc-48d7-b0df-432102de0b81",
"value": "https://www.virustotal.com/file/b07b37f0246bd436addbe5d702b12485d7bc8a9ef1475b54bff513a18e68fef7/analysis/1461049792/"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5be-8280-488c-a1bf-437502de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:10.000Z",
"modified": "2016-04-25T09:39:10.000Z",
"description": "nroff_b.exe - Xchecked via VT: 70bf16597e375ad691f2c1efa194dbe7f60e4eeb",
"pattern": "[file:hashes.SHA256 = '5b7c970fee7ebe08d50665f278d47d0e34c04acc19a91838de6a3fc63a8e5630']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:10Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5be-f358-4523-b8ee-41a202de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:10.000Z",
"modified": "2016-04-25T09:39:10.000Z",
"description": "nroff_b.exe - Xchecked via VT: 70bf16597e375ad691f2c1efa194dbe7f60e4eeb",
"pattern": "[file:hashes.MD5 = '1d0e79feb6d7ed23eb1bf7f257ce4fee']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:10Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--571de5be-941c-4514-b651-4a9202de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:10.000Z",
"modified": "2016-04-25T09:39:10.000Z",
"first_observed": "2016-04-25T09:39:10Z",
"last_observed": "2016-04-25T09:39:10Z",
"number_observed": 1,
"object_refs": [
"url--571de5be-941c-4514-b651-4a9202de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--571de5be-941c-4514-b651-4a9202de0b81",
"value": "https://www.virustotal.com/file/5b7c970fee7ebe08d50665f278d47d0e34c04acc19a91838de6a3fc63a8e5630/analysis/1460698377/"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5bf-ad68-4e97-8c1b-412702de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:11.000Z",
"modified": "2016-04-25T09:39:11.000Z",
"description": "evtsys.exe - Xchecked via VT: 76bab478dcc70f979ce62cd306e9ba50ee84e37e",
"pattern": "[file:hashes.SHA256 = 'ae086350239380f56470c19d6a200f7d251c7422c7bc5ce74730ee8bab8e6283']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:11Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5bf-064c-4a4c-a302-4bdf02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:11.000Z",
"modified": "2016-04-25T09:39:11.000Z",
"description": "evtsys.exe - Xchecked via VT: 76bab478dcc70f979ce62cd306e9ba50ee84e37e",
"pattern": "[file:hashes.MD5 = '5d0ffbc8389f27b0649696f0ef5b3cfe']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:11Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--571de5bf-0df4-421c-bb52-4f7c02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:11.000Z",
"modified": "2016-04-25T09:39:11.000Z",
"first_observed": "2016-04-25T09:39:11Z",
"last_observed": "2016-04-25T09:39:11Z",
"number_observed": 1,
"object_refs": [
"url--571de5bf-0df4-421c-bb52-4f7c02de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--571de5bf-0df4-421c-bb52-4f7c02de0b81",
"value": "https://www.virustotal.com/file/ae086350239380f56470c19d6a200f7d251c7422c7bc5ce74730ee8bab8e6283/analysis/1461067332/"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5bf-f638-4ae5-820f-473002de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:11.000Z",
"modified": "2016-04-25T09:39:11.000Z",
"description": "evtdiag.exe - Xchecked via VT: 525a8e3ae4e3df8c9c61f2a49e38541d196e9228",
"pattern": "[file:hashes.SHA256 = '4659dadbf5b07c8c3c36ae941f71b631737631bc3fded2fe2af250ceba98959a']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:11Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"sha256\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5bf-0b34-45ba-b14c-44fd02de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:11.000Z",
"modified": "2016-04-25T09:39:11.000Z",
"description": "evtdiag.exe - Xchecked via VT: 525a8e3ae4e3df8c9c61f2a49e38541d196e9228",
"pattern": "[file:hashes.MD5 = '24d76abbc0a10e4c977a28b33c879248']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:11Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Payload delivery"
}
],
"labels": [
"misp:type=\"md5\"",
"misp:category=\"Payload delivery\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--571de5bf-b9bc-48f8-9821-478602de0b81",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:11.000Z",
"modified": "2016-04-25T09:39:11.000Z",
"first_observed": "2016-04-25T09:39:11Z",
"last_observed": "2016-04-25T09:39:11Z",
"number_observed": 1,
"object_refs": [
"url--571de5bf-b9bc-48f8-9821-478602de0b81"
],
"labels": [
"misp:type=\"link\"",
"misp:category=\"External analysis\""
]
},
{
"type": "url",
"spec_version": "2.1",
"id": "url--571de5bf-b9bc-48f8-9821-478602de0b81",
"value": "https://www.virustotal.com/file/4659dadbf5b07c8c3c36ae941f71b631737631bc3fded2fe2af250ceba98959a/analysis/1461049613/"
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de5ef-8fa8-4d8e-a3e1-4c79950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:39:59.000Z",
"modified": "2016-04-25T09:39:59.000Z",
"description": "The configuration file contains a list of transaction IDs, some additional environment information, and the following IP address to be used for command-and-control (C&C):",
"pattern": "[network-traffic:dst_ref.type = 'ipv4-addr' AND network-traffic:dst_ref.value = '196.202.103.174']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-04-25T09:39:59Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Network activity"
}
],
"labels": [
"misp:type=\"ip-dst\"",
"misp:category=\"Network activity\"",
"misp:to_ids=\"True\""
]
},
{
"type": "indicator",
"spec_version": "2.1",
"id": "indicator--571de60d-6454-4aa4-b4e7-4352950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-05-17T16:17:00.000Z",
"modified": "2016-05-17T16:17:00.000Z",
"pattern": "[file:name = '\\\\Users\\\\Administrator\\\\AppData\\\\Local\\\\Allians\\\\gpca.dat']",
"pattern_type": "stix",
"pattern_version": "2.1",
"valid_from": "2016-05-17T16:17:00Z",
"kill_chain_phases": [
{
"kill_chain_name": "misp-category",
"phase_name": "Artifacts dropped"
}
],
"labels": [
"misp:type=\"filename\"",
"misp:category=\"Artifacts dropped\"",
"misp:to_ids=\"True\""
]
},
{
"type": "observed-data",
"spec_version": "2.1",
"id": "observed-data--571de6a3-4548-4238-8b4d-4396950d210f",
"created_by_ref": "identity--55f6ea5e-2c60-40e5-964f-47a8950d210f",
"created": "2016-04-25T09:42:59.000Z",
"modified": "2016-04-25T09:42:59.000Z",
"first_observed": "2016-04-25T09:42:59Z",
"last_observed": "2016-04-25T09:42:59Z",
"number_observed": 1,
"object_refs": [
"file--571de6a3-4548-4238-8b4d-4396950d210f",
"artifact--571de6a3-4548-4238-8b4d-4396950d210f"
],
"labels": [
"misp:type=\"attachment\"",
"misp:category=\"External analysis\""
]
},
{
"type": "file",
"spec_version": "2.1",
"id": "file--571de6a3-4548-4238-8b4d-4396950d210f",
"name": "http://baesystemsai.blogspot.lu/2016/04/two-bytes-to-951m.html",
"content_ref": "artifact--571de6a3-4548-4238-8b4d-4396950d210f"
},
{
"type": "artifact",
"spec_version": "2.1",
"id": "artifact--571de6a3-4548-4238-8b4d-4396950d210f",
"payload_bin": ""
},
{
"type": "marking-definition",
"spec_version": "2.1",
"id": "marking-definition--613f2e26-407d-48c7-9eca-b8e91df99dc9",
"created": "2017-01-20T00:00:00.000Z",
"definition_type": "tlp",
"name": "TLP:WHITE",
"definition": {
"tlp": "white"
}
}
]
}