Export from MISP Threat Report Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites (MISP Event #4) Threat Report Payload type: 9002 (MISP Attribute #87) 9002 Payload type: 3102 (MISP Attribute #88) The variant is labeled 3102, because it always uses the string “3102” in its first communications with a C2 server 3102 Targeted Malware Attacks against NGO Linked to Attacks on Burmese Government Websites 4 2015-10-16T00:00:00+00:00 2016-11-10T16:26:30+00:00 New Artifacts dropped Artifacts dropped: c4c147bdfddffec2eea6bf99661e69ee (MISP Attribute #93) Malware Artifacts File Hash Watchlist Artifacts dropped: c4c147bdfddffec2eea6bf99661e69ee (MISP Attribute #93) MD5 c4c147bdfddffec2eea6bf99661e69ee High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 884d46c01c762ad6ddd2759fd921bf71 (MISP Attribute #94) Malware Artifacts File Hash Watchlist Artifacts dropped: 884d46c01c762ad6ddd2759fd921bf71 (MISP Attribute #94) MD5 884d46c01c762ad6ddd2759fd921bf71 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 56f0e67d981024ddcc215543698f44fb (MISP Attribute #95) Malware Artifacts File Hash Watchlist Artifacts dropped: 56f0e67d981024ddcc215543698f44fb (MISP Attribute #95) MD5 56f0e67d981024ddcc215543698f44fb High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 7e0081fba718fcd71753d3199a290f03 (MISP Attribute #96) Malware Artifacts File Hash Watchlist Artifacts dropped: 7e0081fba718fcd71753d3199a290f03 (MISP Attribute #96) MD5 7e0081fba718fcd71753d3199a290f03 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 5710d567d98a8f4a6682859ce3a35336 (MISP Attribute #97) Malware Artifacts File Hash Watchlist Artifacts dropped: 5710d567d98a8f4a6682859ce3a35336 (MISP Attribute #97) MD5 5710d567d98a8f4a6682859ce3a35336 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: cec071424d417a095221bf8992819388 (MISP Attribute #98) Malware Artifacts File Hash Watchlist Artifacts dropped: cec071424d417a095221bf8992819388 (MISP Attribute #98) MD5 cec071424d417a095221bf8992819388 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 49ceba3347d39870f15f2ab0391af234 (MISP Attribute #99) Malware Artifacts File Hash Watchlist Artifacts dropped: 49ceba3347d39870f15f2ab0391af234 (MISP Attribute #99) MD5 49ceba3347d39870f15f2ab0391af234 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Attribution Attribution: wojiaojilao2@sohu.com (MISP Attribute #1876) Malware Artifacts Attribution: wojiaojilao2@sohu.com (MISP Attribute #1876) None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: usafbi.websecexp.com (MISP Attribute #83) Malware Artifacts Domain Watchlist Network activity: usafbi.websecexp.com (MISP Attribute #83) usafbi.websecexp.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: usacia.websecexp.com (MISP Attribute #84) Malware Artifacts Domain Watchlist Network activity: usacia.websecexp.com (MISP Attribute #84) usacia.websecexp.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: webhttps.websecexp.com (MISP Attribute #85) Malware Artifacts Domain Watchlist Network activity: webhttps.websecexp.com (MISP Attribute #85) webhttps.websecexp.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: iyouthen.com (MISP Attribute #1877) Malware Artifacts Domain Watchlist Network activity: iyouthen.com (MISP Attribute #1877) iyouthen.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: appeur.gnway.cc (MISP Attribute #86) Malware Artifacts Domain Watchlist Network activity: appeur.gnway.cc (MISP Attribute #86) appeur.gnway.cc High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: t1.mailsecurityservice.com (MISP Attribute #100) Malware Artifacts Domain Watchlist Network activity: t1.mailsecurityservice.com (MISP Attribute #100) t1.mailsecurityservice.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: t2.mailsecurityservice.com (MISP Attribute #101) Malware Artifacts Domain Watchlist Network activity: t2.mailsecurityservice.com (MISP Attribute #101) t2.mailsecurityservice.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 198.44.190.85 (MISP Attribute #89) Malware Artifacts IP Watchlist Network activity: 198.44.190.85 (MISP Attribute #89) 198.44.190.85 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 53f81415ccedf453d6e3ebcdc142b966 (MISP Attribute #90) Malware Artifacts File Hash Watchlist Payload delivery: 53f81415ccedf453d6e3ebcdc142b966 (MISP Attribute #90) MD5 53f81415ccedf453d6e3ebcdc142b966 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 6701662097e274f3cd089ceec35471d2 (MISP Attribute #91) Malware Artifacts File Hash Watchlist Payload delivery: 6701662097e274f3cd089ceec35471d2 (MISP Attribute #91) MD5 6701662097e274f3cd089ceec35471d2 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 699b3d90b050cae37f65c855ec7f616a (MISP Attribute #92) Malware Artifacts File Hash Watchlist Payload delivery: 699b3d90b050cae37f65c855ec7f616a (MISP Attribute #92) MD5 699b3d90b050cae37f65c855ec7f616a None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe (MISP Attribute #1878) Malware Artifacts URL Watchlist Payload delivery: http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe (MISP Attribute #1878) http://www.hjclub.info/bbs/uploadfiles/45/ca-bundle.exe High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload type Payload type Event Threat Level: High MISP Tag: TLP:GREEN MISP Tag: SOURCE:CITIZENLAB MISP Tag: DETECT MISP Tag: PUBLISHED citizenlab https://citizenlab.org/2015/10/targeted-attacks-ngo-burma/ ../../../descendant-or-self::node()