Export from MISP Threat Report Tracking UP007 and SLServer Espionage Campaigns (MISP Event #2) Threat Report Payload type: UP007 (MISP Attribute #30) UP007 Payload type: SLServer (MISP Attribute #52) SLServer Tracking UP007 and SLServer Espionage Campaigns 2 2016-04-18T00:00:00+00:00 2016-11-10T15:57:11+00:00 Closed Network activity Network activity: safetyssl.security-centers.com (MISP Attribute #45) Malware Artifacts Domain Watchlist Network activity: safetyssl.security-centers.com (MISP Attribute #45) safetyssl.security-centers.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: computer.security-centers.com (MISP Attribute #46) Malware Artifacts Domain Watchlist Network activity: computer.security-centers.com (MISP Attribute #46) computer.security-centers.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: hkemail.f3322.org (MISP Attribute #47) Malware Artifacts Domain Watchlist Network activity: hkemail.f3322.org (MISP Attribute #47) hkemail.f3322.org High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: www.olinaodi.com (MISP Attribute #48) Malware Artifacts Domain Watchlist Network activity: www.olinaodi.com (MISP Attribute #48) www.olinaodi.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: tenday.mysecondarydns.com (MISP Attribute #49) Malware Artifacts Domain Watchlist Network activity: tenday.mysecondarydns.com (MISP Attribute #49) tenday.mysecondarydns.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 59.188.12.123 (MISP Attribute #50) Malware Artifacts IP Watchlist Network activity: 59.188.12.123 (MISP Attribute #50) 59.188.12.123 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 210.61.12.153 (MISP Attribute #51) Malware Artifacts IP Watchlist Network activity: 210.61.12.153 (MISP Attribute #51) 210.61.12.153 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: d579d7a42ff140952da57264614c37bc (MISP Attribute #31) Malware Artifacts File Hash Watchlist Payload delivery: d579d7a42ff140952da57264614c37bc (MISP Attribute #31) MD5 d579d7a42ff140952da57264614c37bc High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: d8becbd6f188e3fb2c4d23a2d36d137b (MISP Attribute #32) Malware Artifacts File Hash Watchlist Payload delivery: d8becbd6f188e3fb2c4d23a2d36d137b (MISP Attribute #32) MD5 d8becbd6f188e3fb2c4d23a2d36d137b High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 09ddd70517cb48a46d9f93644b29c72f (MISP Attribute #33) Malware Artifacts File Hash Watchlist Payload delivery: 09ddd70517cb48a46d9f93644b29c72f (MISP Attribute #33) MD5 09ddd70517cb48a46d9f93644b29c72f High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: f70b295c6a5121b918682310ce0c2165 (MISP Attribute #34) Malware Artifacts File Hash Watchlist Payload delivery: f70b295c6a5121b918682310ce0c2165 (MISP Attribute #34) MD5 f70b295c6a5121b918682310ce0c2165 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: f80edbb0fcfe7cec17592f61a06e4df2 (MISP Attribute #35) Malware Artifacts File Hash Watchlist Payload delivery: f80edbb0fcfe7cec17592f61a06e4df2 (MISP Attribute #35) MD5 f80edbb0fcfe7cec17592f61a06e4df2 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: d8ede9e6c3a1a30398b0b98130ee3b38 (MISP Attribute #36) Malware Artifacts File Hash Watchlist Payload delivery: d8ede9e6c3a1a30398b0b98130ee3b38 (MISP Attribute #36) MD5 d8ede9e6c3a1a30398b0b98130ee3b38 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: ce8ec932be16b69ffa06626b3b423395 (MISP Attribute #37) Malware Artifacts File Hash Watchlist Payload delivery: ce8ec932be16b69ffa06626b3b423395 (MISP Attribute #37) MD5 ce8ec932be16b69ffa06626b3b423395 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 6a541de84074a2c4ff99eb43252d9030 (MISP Attribute #38) Malware Artifacts File Hash Watchlist Payload delivery: 6a541de84074a2c4ff99eb43252d9030 (MISP Attribute #38) MD5 6a541de84074a2c4ff99eb43252d9030 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: e0eb981ad6be0bd16246d5d442028687 (MISP Attribute #39) Malware Artifacts File Hash Watchlist Payload delivery: e0eb981ad6be0bd16246d5d442028687 (MISP Attribute #39) MD5 e0eb981ad6be0bd16246d5d442028687 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 639c7239f40d95f677a99abb059e8338 (MISP Attribute #40) Malware Artifacts File Hash Watchlist Payload delivery: 639c7239f40d95f677a99abb059e8338 (MISP Attribute #40) MD5 639c7239f40d95f677a99abb059e8338 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: d07b2738840ce3419df651d3a0a3a246 (MISP Attribute #41) Malware Artifacts File Hash Watchlist Payload delivery: d07b2738840ce3419df651d3a0a3a246 (MISP Attribute #41) MD5 d07b2738840ce3419df651d3a0a3a246 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 397021af7c0284c28db65297a6711235 (MISP Attribute #42) Malware Artifacts File Hash Watchlist Payload delivery: 397021af7c0284c28db65297a6711235 (MISP Attribute #42) MD5 397021af7c0284c28db65297a6711235 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: dc195d814ec16fe91690b7e949e696f6 (MISP Attribute #43) Malware Artifacts File Hash Watchlist Payload delivery: dc195d814ec16fe91690b7e949e696f6 (MISP Attribute #43) MD5 dc195d814ec16fe91690b7e949e696f6 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: cfcd2a90e87156e1a811f9c7b0051002 (MISP Attribute #44) Malware Artifacts File Hash Watchlist Payload delivery: cfcd2a90e87156e1a811f9c7b0051002 (MISP Attribute #44) MD5 cfcd2a90e87156e1a811f9c7b0051002 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload type Payload type Event Threat Level: High MISP Tag: SOURCE:CITIZENLAB MISP Tag: DETECT MISP Tag: PUBLISHED !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_file_set { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Searches for service files loading UP007" strings: $file1 = "\\Microsoft\\Internet Explorer\\conhost.exe" $file2 = "\\Microsoft\\Internet Explorer\\dll2.xor" $file3 = "\\Microsoft\\Internet Explorer\\HOOK.DLL" $file4 = "\\Microsoft\\Internet Explorer\\main.dll" $file5 = "\\Microsoft\\Internet Explorer\\nvsvc.exe" $file6 = "\\Microsoft\\Internet Explorer\\SBieDll.dll" $file7 = "\\Microsoft\\Internet Explorer\\mon" $file8 = "\\Microsoft\\Internet Explorer\\runas.exe" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and //Just a few of these as they differ 3 of ($file*) } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_dropper_registry_checks { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Searches for registry keys checked for by the dropper" strings: $reg1 = "SOFTWARE\\360Safe\\Liveup" $reg2 = "Software\\360safe" $reg3 = "SOFTWARE\\kingsoft\\Antivirus" $reg4 = "SOFTWARE\\Avira\\Avira Destop" $reg5 = "SOFTWARE\\rising\\RAV" $reg6 = "SOFTWARE\\JiangMin" $reg7 = "SOFTWARE\\Micropoint\\Anti-Attack" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and all of ($reg*) } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_dropper_dialog_remains { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Searches for related dialog remnants. How rude." strings: $dia1 = "fuckMessageBox 1.0" wide $dia2 = "Rundll 1.0" wide condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and any of them } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule maindll_mutex { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches on the maindll mutex" strings: $mutex = "h31415927tttt" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and $mutex } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_dialog_remains { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Searches for related dialog remnants." strings: $slserver = "SLServer" wide condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and $slserver } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_mutex { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Searches for the mutex." strings: $mutex = "M&GX^DSF&DA@F" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and $mutex } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_command_and_control { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Searches for the C2 server." strings: $c2 = "safetyssl.security-centers.com" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and $c2 } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_campaign_code { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Searches for the related campaign code." strings: $campaign = "wthkdoc0106" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and $campaign } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_unknown_string { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Searches for a unique string." strings: $string = "test-b7fa835a39" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and $string } citizenlab https://citizenlab.org/2016/04/between-hong-kong-and-burma/ ../../../descendant-or-self::node()