Export from MISP
Threat Report
Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans (MISP Event #11)
Threat Report
Payload type: FakeM (MISP Attribute #1875)
FakeM
Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans
11
2016-03-10T00:00:00+00:00
2016-11-10T16:15:08+00:00
Closed
Artifacts dropped
Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873)
Malware Artifacts
File Hash Watchlist
Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873)
MD5
ea45265fe98b25e719d5a9cc3b412d66
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Attribution
Attribution: Scarlet Mimic (MISP Attribute #1874)
Malware Artifacts
Attribution: Scarlet Mimic (MISP Attribute #1874)
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499)
Malware Artifacts
Domain Watchlist
Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499)
filegoogle.firewall-gateway.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500)
Malware Artifacts
Domain Watchlist
Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500)
accountgoogle.firewall-gateway.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: sys.firewall-gateway.net (MISP Attribute #501)
Malware Artifacts
Domain Watchlist
Network activity: sys.firewall-gateway.net (MISP Attribute #501)
sys.firewall-gateway.net
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: news.firewall-gateway.com (MISP Attribute #502)
Malware Artifacts
Domain Watchlist
Network activity: news.firewall-gateway.com (MISP Attribute #502)
news.firewall-gateway.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503)
Malware Artifacts
Domain Watchlist
Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503)
accountsgoogle.firewall-gateway.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504)
Malware Artifacts
Domain Watchlist
Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504)
accounts-google.firewall-gateway.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505)
Malware Artifacts
Domain Watchlist
Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505)
accountsgoogles.firewall-gateway.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: googlefile.firewall-gateway.net (MISP Attribute #506)
Malware Artifacts
Domain Watchlist
Network activity: googlefile.firewall-gateway.net (MISP Attribute #506)
googlefile.firewall-gateway.net
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507)
Malware Artifacts
Domain Watchlist
Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507)
firewallupdate.firewall-gateway.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508)
Malware Artifacts
Domain Watchlist
Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508)
firewallupdate.firewall-gateway.net
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509)
Malware Artifacts
Domain Watchlist
Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509)
drivgoogle.firewall-gateway.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: detail43.myfirewall.org (MISP Attribute #510)
Malware Artifacts
Domain Watchlist
Network activity: detail43.myfirewall.org (MISP Attribute #510)
detail43.myfirewall.org
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 95.154.195.159 (MISP Attribute #512)
Malware Artifacts
IP Watchlist
Network activity: 95.154.195.159 (MISP Attribute #512)
95.154.195.159
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 95.154.195.171 (MISP Attribute #513)
Malware Artifacts
IP Watchlist
Network activity: 95.154.195.171 (MISP Attribute #513)
95.154.195.171
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 5.54.19.17 (MISP Attribute #514)
Malware Artifacts
IP Watchlist
Network activity: 5.54.19.17 (MISP Attribute #514)
5.54.19.17
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 78.129.252.159 (MISP Attribute #515)
Malware Artifacts
IP Watchlist
Network activity: 78.129.252.159 (MISP Attribute #515)
78.129.252.159
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 87.117.229.109 (MISP Attribute #516)
Malware Artifacts
IP Watchlist
Network activity: 87.117.229.109 (MISP Attribute #516)
87.117.229.109
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 109.169.40.172 (MISP Attribute #517)
Malware Artifacts
IP Watchlist
Network activity: 109.169.40.172 (MISP Attribute #517)
109.169.40.172
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 46.127.56.109 (MISP Attribute #518)
Malware Artifacts
IP Watchlist
Network activity: 46.127.56.109 (MISP Attribute #518)
46.127.56.109
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 192.253.251.118 (MISP Attribute #519)
Malware Artifacts
IP Watchlist
Network activity: 192.253.251.118 (MISP Attribute #519)
192.253.251.118
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 109.169.77.230 (MISP Attribute #511)
Malware Artifacts
IP Watchlist
Network activity: 109.169.77.230 (MISP Attribute #511)
109.169.77.230
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520)
Malware Artifacts
URL Watchlist
Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520)
http://filegoogle.firewall-gateway.com/servicelogin
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521)
Malware Artifacts
URL Watchlist
Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521)
http://accountgoogle.firewall-gateway.com/serviclogin
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522)
Malware Artifacts
URL Watchlist
Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522)
http://accountgoogle.firewall-gateway.com/servicclogin
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530)
Malware Artifacts
Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530)
None
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531)
Malware Artifacts
File Hash Watchlist
Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531)
MD5
5c030802ad411fea059cc9cc4c118125
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532)
Malware Artifacts
File Hash Watchlist
Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532)
MD5
7735e571d0450e2a31e97e4f8e0f66fa
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533)
Malware Artifacts
File Hash Watchlist
Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533)
MD5
d2e9412428c3bcf3ec98dba8a78adb7b
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534)
Malware Artifacts
File Hash Watchlist
Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534)
MD5
1bf438b5744db73eea58379a3b9f30e5
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535)
Malware Artifacts
File Hash Watchlist
Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535)
MD5
3b869c8e23d66ad0527882fc79ff7237
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536)
Malware Artifacts
File Hash Watchlist
Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536)
MD5
fef27f432e0ae8218143bc410fda340e
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537)
Malware Artifacts
File Hash Watchlist
Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537)
MD5
8b83fc5d3a6a80281269f9e337fe3fff
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload type
Event Threat Level: Medium
MISP Tag: TLP:GREEN
MISP Tag: SOURCE:CITIZENLAB
MISP Tag: DETECT
MISP Tag: PUBLISHED
MISP Tag: TARGET:TIBETAN
citizenlab
https://citizenlab.org/2016/03/shifting-tactics/
../../../descendant-or-self::node()