Export from MISP Threat Report Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans (MISP Event #11) Threat Report Payload type: FakeM (MISP Attribute #1875) FakeM Shifting Tactics: Tracking changes in years-long espionage campaign against Tibetans 11 2016-03-10T00:00:00+00:00 2016-11-10T16:15:08+00:00 Closed Artifacts dropped Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873) Malware Artifacts File Hash Watchlist Artifacts dropped: ea45265fe98b25e719d5a9cc3b412d66 (MISP Attribute #1873) MD5 ea45265fe98b25e719d5a9cc3b412d66 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Attribution Attribution: Scarlet Mimic (MISP Attribute #1874) Malware Artifacts Attribution: Scarlet Mimic (MISP Attribute #1874) None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499) Malware Artifacts Domain Watchlist Network activity: filegoogle.firewall-gateway.com (MISP Attribute #499) filegoogle.firewall-gateway.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500) Malware Artifacts Domain Watchlist Network activity: accountgoogle.firewall-gateway.com (MISP Attribute #500) accountgoogle.firewall-gateway.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: sys.firewall-gateway.net (MISP Attribute #501) Malware Artifacts Domain Watchlist Network activity: sys.firewall-gateway.net (MISP Attribute #501) sys.firewall-gateway.net High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: news.firewall-gateway.com (MISP Attribute #502) Malware Artifacts Domain Watchlist Network activity: news.firewall-gateway.com (MISP Attribute #502) news.firewall-gateway.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503) Malware Artifacts Domain Watchlist Network activity: accountsgoogle.firewall-gateway.com (MISP Attribute #503) accountsgoogle.firewall-gateway.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504) Malware Artifacts Domain Watchlist Network activity: accounts-google.firewall-gateway.com (MISP Attribute #504) accounts-google.firewall-gateway.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505) Malware Artifacts Domain Watchlist Network activity: accountsgoogles.firewall-gateway.com (MISP Attribute #505) accountsgoogles.firewall-gateway.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: googlefile.firewall-gateway.net (MISP Attribute #506) Malware Artifacts Domain Watchlist Network activity: googlefile.firewall-gateway.net (MISP Attribute #506) googlefile.firewall-gateway.net High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507) Malware Artifacts Domain Watchlist Network activity: firewallupdate.firewall-gateway.com (MISP Attribute #507) firewallupdate.firewall-gateway.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508) Malware Artifacts Domain Watchlist Network activity: firewallupdate.firewall-gateway.net (MISP Attribute #508) firewallupdate.firewall-gateway.net High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509) Malware Artifacts Domain Watchlist Network activity: drivgoogle.firewall-gateway.com (MISP Attribute #509) drivgoogle.firewall-gateway.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: detail43.myfirewall.org (MISP Attribute #510) Malware Artifacts Domain Watchlist Network activity: detail43.myfirewall.org (MISP Attribute #510) detail43.myfirewall.org High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 95.154.195.159 (MISP Attribute #512) Malware Artifacts IP Watchlist Network activity: 95.154.195.159 (MISP Attribute #512) 95.154.195.159 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 95.154.195.171 (MISP Attribute #513) Malware Artifacts IP Watchlist Network activity: 95.154.195.171 (MISP Attribute #513) 95.154.195.171 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 5.54.19.17 (MISP Attribute #514) Malware Artifacts IP Watchlist Network activity: 5.54.19.17 (MISP Attribute #514) 5.54.19.17 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 78.129.252.159 (MISP Attribute #515) Malware Artifacts IP Watchlist Network activity: 78.129.252.159 (MISP Attribute #515) 78.129.252.159 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 87.117.229.109 (MISP Attribute #516) Malware Artifacts IP Watchlist Network activity: 87.117.229.109 (MISP Attribute #516) 87.117.229.109 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 109.169.40.172 (MISP Attribute #517) Malware Artifacts IP Watchlist Network activity: 109.169.40.172 (MISP Attribute #517) 109.169.40.172 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 46.127.56.109 (MISP Attribute #518) Malware Artifacts IP Watchlist Network activity: 46.127.56.109 (MISP Attribute #518) 46.127.56.109 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 192.253.251.118 (MISP Attribute #519) Malware Artifacts IP Watchlist Network activity: 192.253.251.118 (MISP Attribute #519) 192.253.251.118 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 109.169.77.230 (MISP Attribute #511) Malware Artifacts IP Watchlist Network activity: 109.169.77.230 (MISP Attribute #511) 109.169.77.230 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520) Malware Artifacts URL Watchlist Network activity: http://filegoogle.firewall-gateway.com/servicelogin (MISP Attribute #520) http://filegoogle.firewall-gateway.com/servicelogin High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521) Malware Artifacts URL Watchlist Network activity: http://accountgoogle.firewall-gateway.com/serviclogin (MISP Attribute #521) http://accountgoogle.firewall-gateway.com/serviclogin None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522) Malware Artifacts URL Watchlist Network activity: http://accountgoogle.firewall-gateway.com/servicclogin (MISP Attribute #522) http://accountgoogle.firewall-gateway.com/servicclogin None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530) Malware Artifacts Payload delivery: Reappraisal_of_India_Tibet_Policy.doc (MISP Attribute #530) None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531) Malware Artifacts File Hash Watchlist Payload delivery: 5c030802ad411fea059cc9cc4c118125 (MISP Attribute #531) MD5 5c030802ad411fea059cc9cc4c118125 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532) Malware Artifacts File Hash Watchlist Payload delivery: 7735e571d0450e2a31e97e4f8e0f66fa (MISP Attribute #532) MD5 7735e571d0450e2a31e97e4f8e0f66fa High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533) Malware Artifacts File Hash Watchlist Payload delivery: d2e9412428c3bcf3ec98dba8a78adb7b (MISP Attribute #533) MD5 d2e9412428c3bcf3ec98dba8a78adb7b High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534) Malware Artifacts File Hash Watchlist Payload delivery: 1bf438b5744db73eea58379a3b9f30e5 (MISP Attribute #534) MD5 1bf438b5744db73eea58379a3b9f30e5 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535) Malware Artifacts File Hash Watchlist Payload delivery: 3b869c8e23d66ad0527882fc79ff7237 (MISP Attribute #535) MD5 3b869c8e23d66ad0527882fc79ff7237 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536) Malware Artifacts File Hash Watchlist Payload delivery: fef27f432e0ae8218143bc410fda340e (MISP Attribute #536) MD5 fef27f432e0ae8218143bc410fda340e High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537) Malware Artifacts File Hash Watchlist Payload delivery: 8b83fc5d3a6a80281269f9e337fe3fff (MISP Attribute #537) MD5 8b83fc5d3a6a80281269f9e337fe3fff High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload type Event Threat Level: Medium MISP Tag: TLP:GREEN MISP Tag: SOURCE:CITIZENLAB MISP Tag: DETECT MISP Tag: PUBLISHED MISP Tag: TARGET:TIBETAN citizenlab https://citizenlab.org/2016/03/shifting-tactics/ ../../../descendant-or-self::node()