Export from MISP
Threat Report
Tracking UP007 and SLServer Espionage Campaigns (MISP Event #2)
Threat Report
Payload type: UP007 (MISP Attribute #30)
UP007
Payload type: SLServer (MISP Attribute #52)
SLServer
Tracking UP007 and SLServer Espionage Campaigns
2
2016-04-18T00:00:00+00:00
2016-11-10T15:57:11+00:00
Closed
Network activity
Network activity: safetyssl.security-centers.com (MISP Attribute #45)
Malware Artifacts
Domain Watchlist
Network activity: safetyssl.security-centers.com (MISP Attribute #45)
safetyssl.security-centers.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: computer.security-centers.com (MISP Attribute #46)
Malware Artifacts
Domain Watchlist
Network activity: computer.security-centers.com (MISP Attribute #46)
computer.security-centers.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: hkemail.f3322.org (MISP Attribute #47)
Malware Artifacts
Domain Watchlist
Network activity: hkemail.f3322.org (MISP Attribute #47)
hkemail.f3322.org
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: www.olinaodi.com (MISP Attribute #48)
Malware Artifacts
Domain Watchlist
Network activity: www.olinaodi.com (MISP Attribute #48)
www.olinaodi.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: tenday.mysecondarydns.com (MISP Attribute #49)
Malware Artifacts
Domain Watchlist
Network activity: tenday.mysecondarydns.com (MISP Attribute #49)
tenday.mysecondarydns.com
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 59.188.12.123 (MISP Attribute #50)
Malware Artifacts
IP Watchlist
Network activity: 59.188.12.123 (MISP Attribute #50)
59.188.12.123
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Network activity
Network activity: 210.61.12.153 (MISP Attribute #51)
Malware Artifacts
IP Watchlist
Network activity: 210.61.12.153 (MISP Attribute #51)
210.61.12.153
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: d579d7a42ff140952da57264614c37bc (MISP Attribute #31)
Malware Artifacts
File Hash Watchlist
Payload delivery: d579d7a42ff140952da57264614c37bc (MISP Attribute #31)
MD5
d579d7a42ff140952da57264614c37bc
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: d8becbd6f188e3fb2c4d23a2d36d137b (MISP Attribute #32)
Malware Artifacts
File Hash Watchlist
Payload delivery: d8becbd6f188e3fb2c4d23a2d36d137b (MISP Attribute #32)
MD5
d8becbd6f188e3fb2c4d23a2d36d137b
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 09ddd70517cb48a46d9f93644b29c72f (MISP Attribute #33)
Malware Artifacts
File Hash Watchlist
Payload delivery: 09ddd70517cb48a46d9f93644b29c72f (MISP Attribute #33)
MD5
09ddd70517cb48a46d9f93644b29c72f
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: f70b295c6a5121b918682310ce0c2165 (MISP Attribute #34)
Malware Artifacts
File Hash Watchlist
Payload delivery: f70b295c6a5121b918682310ce0c2165 (MISP Attribute #34)
MD5
f70b295c6a5121b918682310ce0c2165
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: f80edbb0fcfe7cec17592f61a06e4df2 (MISP Attribute #35)
Malware Artifacts
File Hash Watchlist
Payload delivery: f80edbb0fcfe7cec17592f61a06e4df2 (MISP Attribute #35)
MD5
f80edbb0fcfe7cec17592f61a06e4df2
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: d8ede9e6c3a1a30398b0b98130ee3b38 (MISP Attribute #36)
Malware Artifacts
File Hash Watchlist
Payload delivery: d8ede9e6c3a1a30398b0b98130ee3b38 (MISP Attribute #36)
MD5
d8ede9e6c3a1a30398b0b98130ee3b38
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: ce8ec932be16b69ffa06626b3b423395 (MISP Attribute #37)
Malware Artifacts
File Hash Watchlist
Payload delivery: ce8ec932be16b69ffa06626b3b423395 (MISP Attribute #37)
MD5
ce8ec932be16b69ffa06626b3b423395
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 6a541de84074a2c4ff99eb43252d9030 (MISP Attribute #38)
Malware Artifacts
File Hash Watchlist
Payload delivery: 6a541de84074a2c4ff99eb43252d9030 (MISP Attribute #38)
MD5
6a541de84074a2c4ff99eb43252d9030
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: e0eb981ad6be0bd16246d5d442028687 (MISP Attribute #39)
Malware Artifacts
File Hash Watchlist
Payload delivery: e0eb981ad6be0bd16246d5d442028687 (MISP Attribute #39)
MD5
e0eb981ad6be0bd16246d5d442028687
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 639c7239f40d95f677a99abb059e8338 (MISP Attribute #40)
Malware Artifacts
File Hash Watchlist
Payload delivery: 639c7239f40d95f677a99abb059e8338 (MISP Attribute #40)
MD5
639c7239f40d95f677a99abb059e8338
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: d07b2738840ce3419df651d3a0a3a246 (MISP Attribute #41)
Malware Artifacts
File Hash Watchlist
Payload delivery: d07b2738840ce3419df651d3a0a3a246 (MISP Attribute #41)
MD5
d07b2738840ce3419df651d3a0a3a246
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: 397021af7c0284c28db65297a6711235 (MISP Attribute #42)
Malware Artifacts
File Hash Watchlist
Payload delivery: 397021af7c0284c28db65297a6711235 (MISP Attribute #42)
MD5
397021af7c0284c28db65297a6711235
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: dc195d814ec16fe91690b7e949e696f6 (MISP Attribute #43)
Malware Artifacts
File Hash Watchlist
Payload delivery: dc195d814ec16fe91690b7e949e696f6 (MISP Attribute #43)
MD5
dc195d814ec16fe91690b7e949e696f6
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload delivery
Payload delivery: cfcd2a90e87156e1a811f9c7b0051002 (MISP Attribute #44)
Malware Artifacts
File Hash Watchlist
Payload delivery: cfcd2a90e87156e1a811f9c7b0051002 (MISP Attribute #44)
MD5
cfcd2a90e87156e1a811f9c7b0051002
High
Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none
Payload type
Payload type
Event Threat Level: High
MISP Tag: SOURCE:CITIZENLAB
MISP Tag: DETECT
MISP Tag: PUBLISHED
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_file_set
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for service files loading UP007"
strings:
$file1 = "\\Microsoft\\Internet Explorer\\conhost.exe"
$file2 = "\\Microsoft\\Internet Explorer\\dll2.xor"
$file3 = "\\Microsoft\\Internet Explorer\\HOOK.DLL"
$file4 = "\\Microsoft\\Internet Explorer\\main.dll"
$file5 = "\\Microsoft\\Internet Explorer\\nvsvc.exe"
$file6 = "\\Microsoft\\Internet Explorer\\SBieDll.dll"
$file7 = "\\Microsoft\\Internet Explorer\\mon"
$file8 = "\\Microsoft\\Internet Explorer\\runas.exe"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
//Just a few of these as they differ
3 of ($file*)
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_dropper_registry_checks
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for registry keys checked for by the dropper"
strings:
$reg1 = "SOFTWARE\\360Safe\\Liveup"
$reg2 = "Software\\360safe"
$reg3 = "SOFTWARE\\kingsoft\\Antivirus"
$reg4 = "SOFTWARE\\Avira\\Avira Destop"
$reg5 = "SOFTWARE\\rising\\RAV"
$reg6 = "SOFTWARE\\JiangMin"
$reg7 = "SOFTWARE\\Micropoint\\Anti-Attack"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
all of ($reg*)
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule dubseven_dropper_dialog_remains
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for related dialog remnants. How rude."
strings:
$dia1 = "fuckMessageBox 1.0" wide
$dia2 = "Rundll 1.0" wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
any of them
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule maindll_mutex
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Matches on the maindll mutex"
strings:
$mutex = "h31415927tttt"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$mutex
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_dialog_remains
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for related dialog remnants."
strings:
$slserver = "SLServer" wide
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$slserver
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_mutex
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the mutex."
strings:
$mutex = "M&GX^DSF&DA@F"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$mutex
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_command_and_control
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the C2 server."
strings:
$c2 = "safetyssl.security-centers.com"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$c2
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_campaign_code
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for the related campaign code."
strings:
$campaign = "wthkdoc0106"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$campaign
}
!Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule SLServer_unknown_string
{
meta:
author = "Matt Brooks, @cmatthewbrooks"
desc = "Searches for a unique string."
strings:
$string = "test-b7fa835a39"
condition:
//MZ header
uint16(0) == 0x5A4D and
//PE signature
uint32(uint32(0x3C)) == 0x00004550 and
$string
}
citizenlab
https://citizenlab.org/2016/04/between-hong-kong-and-burma/
../../../descendant-or-self::node()