Export from MISP Threat Report Familiar Feeling: A Malware Campaign Targeting the Tibetan Diaspora Resurfaces Threat Report Familiar Feeling: A Malware Campaign Targeting the Tibetan Diaspora Resurfaces 133 2018-01-31T00:00:00+00:00 2018-08-04T06:25:10+00:00 Closed Artifacts dropped Artifacts dropped: 91e976f76cc027931fed4cf70702efff (MISP Attribute #18346) Malware Artifacts File Hash Watchlist Artifacts dropped: 91e976f76cc027931fed4cf70702efff (MISP Attribute #18346) MD5 91e976f76cc027931fed4cf70702efff None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 57ffde3504934e25904bcc57d27f9217 (MISP Attribute #18347) Malware Artifacts File Hash Watchlist Artifacts dropped: 57ffde3504934e25904bcc57d27f9217 (MISP Attribute #18347) MD5 57ffde3504934e25904bcc57d27f9217 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 75b86a01196854919626e87d5bd45a38 (MISP Attribute #18348) Malware Artifacts File Hash Watchlist Artifacts dropped: 75b86a01196854919626e87d5bd45a38 (MISP Attribute #18348) MD5 75b86a01196854919626e87d5bd45a38 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: c25acaa45b0cf65a39c8413fa99e1fe8 (MISP Attribute #18349) Malware Artifacts File Hash Watchlist Artifacts dropped: c25acaa45b0cf65a39c8413fa99e1fe8 (MISP Attribute #18349) MD5 c25acaa45b0cf65a39c8413fa99e1fe8 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 4d85904b15c0adc8664f71bc2c5496bf (MISP Attribute #18350) Malware Artifacts File Hash Watchlist Artifacts dropped: 4d85904b15c0adc8664f71bc2c5496bf (MISP Attribute #18350) MD5 4d85904b15c0adc8664f71bc2c5496bf None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 88e85fb6074ae50a3ccc9b410805ffe5 (MISP Attribute #18351) Malware Artifacts File Hash Watchlist Artifacts dropped: 88e85fb6074ae50a3ccc9b410805ffe5 (MISP Attribute #18351) MD5 88e85fb6074ae50a3ccc9b410805ffe5 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 058a5d47f8834fccfff8971f0544e387 (MISP Attribute #18352) Malware Artifacts File Hash Watchlist Artifacts dropped: 058a5d47f8834fccfff8971f0544e387 (MISP Attribute #18352) MD5 058a5d47f8834fccfff8971f0544e387 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 124c475d67aa8391f5220efcc64ca5b3 (MISP Attribute #18353) Malware Artifacts File Hash Watchlist Artifacts dropped: 124c475d67aa8391f5220efcc64ca5b3 (MISP Attribute #18353) MD5 124c475d67aa8391f5220efcc64ca5b3 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 054bad7ec0e19cec931078d45382fee6 (MISP Attribute #18354) Malware Artifacts File Hash Watchlist Artifacts dropped: 054bad7ec0e19cec931078d45382fee6 (MISP Attribute #18354) MD5 054bad7ec0e19cec931078d45382fee6 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: b1c114ae9172a3bacc5c6b30c410f354 (MISP Attribute #18355) Malware Artifacts File Hash Watchlist Artifacts dropped: b1c114ae9172a3bacc5c6b30c410f354 (MISP Attribute #18355) MD5 b1c114ae9172a3bacc5c6b30c410f354 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 72c88c4a9d2316b266a6702374411a99 (MISP Attribute #18356) Malware Artifacts File Hash Watchlist Artifacts dropped: 72c88c4a9d2316b266a6702374411a99 (MISP Attribute #18356) MD5 72c88c4a9d2316b266a6702374411a99 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 67e866c461c285853b225d2b2c850c4f (MISP Attribute #18357) Malware Artifacts File Hash Watchlist Artifacts dropped: 67e866c461c285853b225d2b2c850c4f (MISP Attribute #18357) MD5 67e866c461c285853b225d2b2c850c4f None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: e1b03f5837533ecc9a05e19650d68e1d (MISP Attribute #18358) Malware Artifacts File Hash Watchlist Artifacts dropped: e1b03f5837533ecc9a05e19650d68e1d (MISP Attribute #18358) MD5 e1b03f5837533ecc9a05e19650d68e1d None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 11e0f3e1c7d8855ed7f1dcfce4b7702a (MISP Attribute #18359) Malware Artifacts File Hash Watchlist Artifacts dropped: 11e0f3e1c7d8855ed7f1dcfce4b7702a (MISP Attribute #18359) MD5 11e0f3e1c7d8855ed7f1dcfce4b7702a None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Attribution Attribution: bqfkdrmnhh0623@gmail.com (MISP Attribute #18343) Malware Artifacts Attribution: bqfkdrmnhh0623@gmail.com (MISP Attribute #18343) None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Attribution Attribution: huang ning (MISP Attribute #18344) Malware Artifacts Attribution: huang ning (MISP Attribute #18344) None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Attribution Attribution: 8677687877 (MISP Attribute #18345) Malware Artifacts Attribution: 8677687877 (MISP Attribute #18345) None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: commail.co (MISP Attribute #18048) Malware Artifacts Domain Watchlist Network activity: commail.co (MISP Attribute #18048) commail.co High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: tibetfrum.info (MISP Attribute #18049) Malware Artifacts Domain Watchlist Network activity: tibetfrum.info (MISP Attribute #18049) tibetfrum.info High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: tibethouse.info (MISP Attribute #18050) Malware Artifacts Domain Watchlist Network activity: tibethouse.info (MISP Attribute #18050) tibethouse.info High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: tibetnews.info (MISP Attribute #18051) Malware Artifacts Domain Watchlist Network activity: tibetnews.info (MISP Attribute #18051) tibetnews.info High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: daynew.today (MISP Attribute #18052) Malware Artifacts Domain Watchlist Network activity: daynew.today (MISP Attribute #18052) daynew.today High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: daynews.today (MISP Attribute #18053) Malware Artifacts Domain Watchlist Network activity: daynews.today (MISP Attribute #18053) daynews.today High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: tibetnews.today (MISP Attribute #18054) Malware Artifacts Domain Watchlist Network activity: tibetnews.today (MISP Attribute #18054) tibetnews.today High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: comemails.email (MISP Attribute #18055) Malware Artifacts Domain Watchlist Network activity: comemails.email (MISP Attribute #18055) comemails.email High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: comemail.email (MISP Attribute #18056) Malware Artifacts Domain Watchlist Network activity: comemail.email (MISP Attribute #18056) comemail.email High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: google.comemail.email (MISP Attribute #18336) Malware Artifacts Domain Watchlist Network activity: google.comemail.email (MISP Attribute #18336) google.comemail.email High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: google.comemails.email (MISP Attribute #18337) Malware Artifacts Domain Watchlist Network activity: google.comemails.email (MISP Attribute #18337) google.comemails.email High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: google.commail.co (MISP Attribute #18338) Malware Artifacts Domain Watchlist Network activity: google.commail.co (MISP Attribute #18338) google.commail.co High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: google.commail.email (MISP Attribute #18339) Malware Artifacts Domain Watchlist Network activity: google.commail.email (MISP Attribute #18339) google.commail.email High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: mail.google.commail.co (MISP Attribute #18340) Malware Artifacts Domain Watchlist Network activity: mail.google.commail.co (MISP Attribute #18340) mail.google.commail.co High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: www.comemail.email (MISP Attribute #18341) Malware Artifacts Domain Watchlist Network activity: www.comemail.email (MISP Attribute #18341) www.comemail.email High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: www.google.comemails.email (MISP Attribute #18342) Malware Artifacts Domain Watchlist Network activity: www.google.comemails.email (MISP Attribute #18342) www.google.comemails.email High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 27.126.186.222 (MISP Attribute #18330) Malware Artifacts IP Watchlist Network activity: 27.126.186.222 (MISP Attribute #18330) 27.126.186.222 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 103.55.24.196 (MISP Attribute #18331) Malware Artifacts IP Watchlist Network activity: 103.55.24.196 (MISP Attribute #18331) 103.55.24.196 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 203.189.232.207 (MISP Attribute #18332) Malware Artifacts IP Watchlist Network activity: 203.189.232.207 (MISP Attribute #18332) 203.189.232.207 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 45.127.97.222 (MISP Attribute #18333) Malware Artifacts IP Watchlist Network activity: 45.127.97.222 (MISP Attribute #18333) 45.127.97.222 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 115.126.86.151 (MISP Attribute #18334) Malware Artifacts IP Watchlist Network activity: 115.126.86.151 (MISP Attribute #18334) 115.126.86.151 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 27.126.176.169 (MISP Attribute #18335) Malware Artifacts IP Watchlist Network activity: 27.126.176.169 (MISP Attribute #18335) 27.126.176.169 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #18360) Malware Artifacts Malicious E-mail Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #18360) tibetanparliarnent@yahoo.com None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Event Threat Level: Medium MISP Tag: TLP:RED MISP Tag: SOURCE:CITIZENLAB MISP Tag: NOTPUBLISHED MISP Tag: DETECT MISP Tag: TARGET:TIBETAN citizenlab ../../../descendant-or-self::node()