Export from MISP
Threat Report
Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites (MISP Event #4)
Threat Report
Payload type: 9002 (MISP Attribute #87)
9002
Payload type: 3102 (MISP Attribute #88)
The variant is labeled 3102, because it always uses the string “3102” in its first communications with a C2 server
3102
Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites
4
2015-10-16T00:00:00+00:00
2016-11-10T16:26:30+00:00
New
Artifacts dropped
Artifacts dropped: c4c147bdfddffec2eea6bf99661e69ee (MISP Attribute #93)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: c4c147bdfddffec2eea6bf99661e69ee (MISP Attribute #93)
MD5
c4c147bdfddffec2eea6bf99661e69ee
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 884d46c01c762ad6ddd2759fd921bf71 (MISP Attribute #94)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 884d46c01c762ad6ddd2759fd921bf71 (MISP Attribute #94)
MD5
884d46c01c762ad6ddd2759fd921bf71
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 56f0e67d981024ddcc215543698f44fb (MISP Attribute #95)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 56f0e67d981024ddcc215543698f44fb (MISP Attribute #95)
MD5
56f0e67d981024ddcc215543698f44fb
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 7e0081fba718fcd71753d3199a290f03 (MISP Attribute #96)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 7e0081fba718fcd71753d3199a290f03 (MISP Attribute #96)
MD5
7e0081fba718fcd71753d3199a290f03
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 5710d567d98a8f4a6682859ce3a35336 (MISP Attribute #97)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 5710d567d98a8f4a6682859ce3a35336 (MISP Attribute #97)
MD5
5710d567d98a8f4a6682859ce3a35336
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: cec071424d417a095221bf8992819388 (MISP Attribute #98)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: cec071424d417a095221bf8992819388 (MISP Attribute #98)
MD5
cec071424d417a095221bf8992819388
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Artifacts dropped
Artifacts dropped: 49ceba3347d39870f15f2ab0391af234 (MISP Attribute #99)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: 49ceba3347d39870f15f2ab0391af234 (MISP Attribute #99)
MD5
49ceba3347d39870f15f2ab0391af234
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Attribution
Attribution: wojiaojilao2@sohu.com (MISP Attribute #1876)
Malware Artifacts
Attribution: wojiaojilao2@sohu.com (MISP Attribute #1876)
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: usafbi.websecexp.com (MISP Attribute #83)
Malware Artifacts
Domain Watchlist
Network activity: usafbi.websecexp.com (MISP Attribute #83)
usafbi.websecexp.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: usacia.websecexp.com (MISP Attribute #84)
Malware Artifacts
Domain Watchlist
Network activity: usacia.websecexp.com (MISP Attribute #84)
usacia.websecexp.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: webhttps.websecexp.com (MISP Attribute #85)
Malware Artifacts
Domain Watchlist
Network activity: webhttps.websecexp.com (MISP Attribute #85)
webhttps.websecexp.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: iyouthen.com (MISP Attribute #1877)
Malware Artifacts
Domain Watchlist
Network activity: iyouthen.com (MISP Attribute #1877)
iyouthen.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: appeur.gnway.cc (MISP Attribute #86)
Malware Artifacts
Domain Watchlist
Network activity: appeur.gnway.cc (MISP Attribute #86)
appeur.gnway.cc
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: t1.mailsecurityservice.com (MISP Attribute #100)
Malware Artifacts
Domain Watchlist
Network activity: t1.mailsecurityservice.com (MISP Attribute #100)
t1.mailsecurityservice.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: t2.mailsecurityservice.com (MISP Attribute #101)
Malware Artifacts
Domain Watchlist
Network activity: t2.mailsecurityservice.com (MISP Attribute #101)
t2.mailsecurityservice.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 198.44.190.85 (MISP Attribute #89)
Malware Artifacts
IP Watchlist
Network activity: 198.44.190.85 (MISP Attribute #89)
198.44.190.85
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 53f81415ccedf453d6e3ebcdc142b966 (MISP Attribute #90)
Malware Artifacts
File Hash Watchlist
Payload delivery: 53f81415ccedf453d6e3ebcdc142b966 (MISP Attribute #90)
MD5
53f81415ccedf453d6e3ebcdc142b966
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 6701662097e274f3cd089ceec35471d2 (MISP Attribute #91)
Malware Artifacts
File Hash Watchlist
Payload delivery: 6701662097e274f3cd089ceec35471d2 (MISP Attribute #91)
MD5
6701662097e274f3cd089ceec35471d2
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 699b3d90b050cae37f65c855ec7f616a (MISP Attribute #92)
Malware Artifacts
File Hash Watchlist
Payload delivery: 699b3d90b050cae37f65c855ec7f616a (MISP Attribute #92)
MD5
699b3d90b050cae37f65c855ec7f616a
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe (MISP Attribute #1878)
Malware Artifacts
URL Watchlist
Payload delivery: http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe (MISP Attribute #1878)
http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload type
Payload type
Event Threat Level: High
MISP Tag: TLP:GREEN
MISP Tag: SOURCE:CITIZENLAB
MISP Tag: DETECT
MISP Tag: PUBLISHED
citizenlab
https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/
../../../descendant-or-self::node()