Export from MISP Threat Report It’s Parliamentary: KeyBoy and the targeting of the Tibetan Community (MISP Event #17) Threat Report Payload delivery: CVE-2012-0158 (MISP Attribute #811) 8307e444cad98b1b59568ad2eba5f201 8307e444cad98b1b59568ad2eba5f201 CVE-2012-0158 Payload delivery: CVE-2014-4114 (MISP Attribute #832) Vulnerability CVE-2014-4114 CVE-2014-4114 Payload delivery: CVE-2015-1641 (MISP Attribute #1374) Vulnerability CVE-2015-1641 CVE-2015-1641 Payload type: KeyBoy (MISP Attribute #809) KeyBoy It’s Parliamentary: KeyBoy and the targeting of the Tibetan Community 17 2016-11-07T00:00:00+00:00 2016-11-16T15:02:57+00:00 Open Artifacts dropped Artifacts dropped: 8f08609e4e0b3d26814b3073a42df415 (MISP Attribute #813) Malware Artifacts File Hash Watchlist Artifacts dropped: 8f08609e4e0b3d26814b3073a42df415 (MISP Attribute #813) MD5 8f08609e4e0b3d26814b3073a42df415 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 495adb1b9777002ecfe22aaf52fcee93 (MISP Attribute #814) Malware Artifacts File Hash Watchlist Artifacts dropped: 495adb1b9777002ecfe22aaf52fcee93 (MISP Attribute #814) MD5 495adb1b9777002ecfe22aaf52fcee93 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 0c7e55509e0b6d4277b3facf864af018 (MISP Attribute #822) Malware Artifacts File Hash Watchlist Artifacts dropped: 0c7e55509e0b6d4277b3facf864af018 (MISP Attribute #822) MD5 0c7e55509e0b6d4277b3facf864af018 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 98977426d544bd145979f65f0322ae30 (MISP Attribute #827) Malware Artifacts File Hash Watchlist Artifacts dropped: 98977426d544bd145979f65f0322ae30 (MISP Attribute #827) MD5 98977426d544bd145979f65f0322ae30 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: c5b5f01ba24d6c02636388809f44472e (MISP Attribute #833) Malware Artifacts File Hash Watchlist Artifacts dropped: c5b5f01ba24d6c02636388809f44472e (MISP Attribute #833) MD5 c5b5f01ba24d6c02636388809f44472e High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 371bc132499f455f06fa80696db0df27 (MISP Attribute #834) Malware Artifacts File Hash Watchlist Artifacts dropped: 371bc132499f455f06fa80696db0df27 (MISP Attribute #834) MD5 371bc132499f455f06fa80696db0df27 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 087bffa8a570079948310dc9731c5709 (MISP Attribute #1372) Malware Artifacts File Hash Watchlist Artifacts dropped: 087bffa8a570079948310dc9731c5709 (MISP Attribute #1372) MD5 087bffa8a570079948310dc9731c5709 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver (MISP Attribute #1365) Malware Artifacts Host Characteristics Artifacts dropped: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver (MISP Attribute #1365) Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Ver HKEY_CURRENT_USER High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d (MISP Attribute #1368) Malware Artifacts File Hash Watchlist Artifacts dropped: 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d (MISP Attribute #1368) SHA256 58105e9772f6befbc319c147a97faded4fbacf839947b34fe3695ae72771da5d None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 (MISP Attribute #1369) Malware Artifacts File Hash Watchlist Artifacts dropped: 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 (MISP Attribute #1369) SHA256 9a55577d357922711ab0821bf5379289293c8517ae1d94d48c389f306af57a04 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Artifacts dropped Artifacts dropped: 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 (MISP Attribute #1373) Malware Artifacts File Hash Watchlist Artifacts dropped: 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 (MISP Attribute #1373) SHA256 5da2f14c382d7cac8dfa6c86e528a646a81f0b40cfee9611c8cfb4b5d589aa88 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: tibetvoices.com (MISP Attribute #817) Malware Artifacts Domain Watchlist Network activity: tibetvoices.com (MISP Attribute #817) tibetvoices.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: www.about.jkub.com (MISP Attribute #823) Malware Artifacts Domain Watchlist Network activity: www.about.jkub.com (MISP Attribute #823) www.about.jkub.com High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: www.eleven.mypop3.org (MISP Attribute #824) Malware Artifacts Domain Watchlist Network activity: www.eleven.mypop3.org (MISP Attribute #824) www.eleven.mypop3.org High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: www.backus.myftp.name (MISP Attribute #825) Malware Artifacts Domain Watchlist Network activity: www.backus.myftp.name (MISP Attribute #825) www.backus.myftp.name High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 45.125.12.147 (MISP Attribute #815) Malware Artifacts IP Watchlist Network activity: 45.125.12.147 (MISP Attribute #815) 45.125.12.147 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 103.40.102.233 (MISP Attribute #816) Malware Artifacts IP Watchlist Network activity: 103.40.102.233 (MISP Attribute #816) 103.40.102.233 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 116.193.154.69 (MISP Attribute #820) Malware Artifacts IP Watchlist Network activity: 116.193.154.69 (MISP Attribute #820) 116.193.154.69 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 103.242.134.243 (MISP Attribute #828) Malware Artifacts IP Watchlist Network activity: 103.242.134.243 (MISP Attribute #828) 103.242.134.243 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 45.32.47.148 (MISP Attribute #829) Malware Artifacts IP Watchlist Network activity: 45.32.47.148 (MISP Attribute #829) 45.32.47.148 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 157.7.84.81 (MISP Attribute #830) Malware Artifacts IP Watchlist Network activity: 157.7.84.81 (MISP Attribute #830) 157.7.84.81 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 192.241.149.43 (MISP Attribute #831) Malware Artifacts IP Watchlist Network activity: 192.241.149.43 (MISP Attribute #831) 192.241.149.43 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Network activity Network activity: 112.10.117.47 (MISP Attribute #1880) Malware Artifacts IP Watchlist Network activity: 112.10.117.47 (MISP Attribute #1880) 112.10.117.47 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #1366) Malware Artifacts Malicious E-mail Payload delivery: tibetanparliarnent@yahoo.com (MISP Attribute #1366) tibetanparliarnent@yahoo.com None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 8307e444cad98b1b59568ad2eba5f201 (MISP Attribute #810) Malware Artifacts File Hash Watchlist Payload delivery: 8307e444cad98b1b59568ad2eba5f201 (MISP Attribute #810) MD5 8307e444cad98b1b59568ad2eba5f201 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 0b4d45db323f68b465ae052d3a872068 (MISP Attribute #812) Malware Artifacts File Hash Watchlist Payload delivery: 0b4d45db323f68b465ae052d3a872068 (MISP Attribute #812) MD5 0b4d45db323f68b465ae052d3a872068 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: beadf21b923600554b0ce54df42e78f5 (MISP Attribute #818) Malware Artifacts File Hash Watchlist Payload delivery: beadf21b923600554b0ce54df42e78f5 (MISP Attribute #818) MD5 beadf21b923600554b0ce54df42e78f5 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 69df3d3df4d99bc6045d073d89c68697 (MISP Attribute #819) Malware Artifacts File Hash Watchlist Payload delivery: 69df3d3df4d99bc6045d073d89c68697 (MISP Attribute #819) MD5 69df3d3df4d99bc6045d073d89c68697 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 05b5cf94f07fee666eb086c91182ad25 (MISP Attribute #821) Malware Artifacts File Hash Watchlist Payload delivery: 05b5cf94f07fee666eb086c91182ad25 (MISP Attribute #821) MD5 05b5cf94f07fee666eb086c91182ad25 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 8846d109b457a2ee44ddbf54d1cf7944 (MISP Attribute #826) Malware Artifacts File Hash Watchlist Payload delivery: 8846d109b457a2ee44ddbf54d1cf7944 (MISP Attribute #826) MD5 8846d109b457a2ee44ddbf54d1cf7944 None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 913b82ff8f090670fc6387e3a7bea12d (MISP Attribute #1879) Malware Artifacts File Hash Watchlist Payload delivery: 913b82ff8f090670fc6387e3a7bea12d (MISP Attribute #1879) MD5 913b82ff8f090670fc6387e3a7bea12d None Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 23d284245e53ae4fe05c517d807ffccf (MISP Attribute #1370) Malware Artifacts File Hash Watchlist Payload delivery: 23d284245e53ae4fe05c517d807ffccf (MISP Attribute #1370) MD5 23d284245e53ae4fe05c517d807ffccf High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 (MISP Attribute #1367) Malware Artifacts File Hash Watchlist Payload delivery: 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 (MISP Attribute #1367) SHA256 5f24a5ee9ecfd4a8e5f967ffcf24580a83942cd7b09d310b9525962ed2614a49 High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery: 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf (MISP Attribute #1371) Malware Artifacts File Hash Watchlist Payload delivery: 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf (MISP Attribute #1371) SHA256 542c85fda8df8510c1b66a122e459aac8c0919f1fe9fa2c43fd87899cffa05bf High Derived from MISP's IDS flag. If an attribute is marked for IDS exports, the confidence will be high, otherwise none Payload delivery Payload delivery Payload delivery Payload type Event Threat Level: Medium MISP Tag: TLP:AMBER MISP Tag: SOURCE:CITIZENLAB MISP Tag: NOTPUBLISHED MISP Tag: DETECT MISP Tag: TARGET:TIBETAN !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe" rule new_keyboy_export { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches the new 2016 sample's export" date = "2016-08-28" md5 = "495adb1b9777002ecfe22aaf52fcee93" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and filesize < 200KB and //The malware family seems to share many exports //but this is the new kid on the block. pe.exports("cfsUpdate") } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule new_keyboy_header_codes { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches the 2016 sample's header codes" date = "2016-08-28" md5 = "495adb1b9777002ecfe22aaf52fcee93" strings: $s1 = "*l*" wide fullword $s2 = "*a*" wide fullword $s3 = "*s*" wide fullword $s4 = "*d*" wide fullword $s5 = "*f*" wide fullword $s6 = "*g*" wide fullword $s7 = "*h*" wide fullword condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and filesize < 200KB and all of them } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_commands { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches the 2016 sample's sent and received commands" date = "2016-08-28" md5 = "495adb1b9777002ecfe22aaf52fcee93" strings: $s1 = "Update" wide fullword $s2 = "UpdateAndRun" wide fullword $s3 = "Refresh" wide fullword $s4 = "OnLine" wide fullword $s5 = "Disconnect" wide fullword $s6 = "Pw_Error" wide fullword $s7 = "Pw_OK" wide fullword $s8 = "Sysinfo" wide fullword $s9 = "Download" wide fullword $s10 = "UploadFileOk" wide fullword $s11 = "RemoteRun" wide fullword $s12 = "FileManager" wide fullword condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and filesize < 200KB and 6 of them } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_errors { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches the sample's shell error2 log statements" date = "2016-08-28" md5 = "495adb1b9777002ecfe22aaf52fcee93" strings: //These strings are in ASCII pre-2015 and UNICODE in 2016 $error = "Error2" ascii wide //2016 specific: $s1 = "Can't find [%s]!Check the file name and try again!" ascii wide $s2 = "Open [%s] error! %d" ascii wide $s3 = "The Size of [%s] is zero!" ascii wide $s4 = "CreateThread DownloadFile[%s] Error!" ascii wide $s5 = "UploadFile [%s] Error:Connect Server Failed!" ascii wide $s6 = "Receive [%s] Error(Recved[%d] != Send[%d])!" ascii wide $s7 = "Receive [%s] ok! Use %2.2f seconds, Average speed %2.2f k/s" ascii wide $s8 = "CreateThread UploadFile[%s] Error!" ascii wide //Pre-2016: $s9 = "Ready Download [%s] ok!" ascii wide $s10 = "Get ControlInfo from FileClient error!" ascii wide $s11 = "FileClient has a error!" ascii wide $s12 = "VirtualAlloc SendBuff Error(%d)" ascii wide $s13 = "ReadFile [%s] Error(%d)..." ascii wide $s14 = "ReadFile [%s] Data[Readed(%d) != FileSize(%d)] Error..." ascii wide $s15 = "CreateThread DownloadFile[%s] Error!" ascii wide $s16 = "RecvData MyRecv_Info Size Error!" ascii wide $s17 = "RecvData MyRecv_Info Tag Error!" ascii wide $s18 = "SendData szControlInfo_1 Error!" ascii wide $s19 = "SendData szControlInfo_3 Error!" ascii wide $s20 = "VirtualAlloc RecvBuff Error(%d)" ascii wide $s21 = "RecvData Error!" ascii wide $s22 = "WriteFile [%s} Error(%d)..." ascii wide condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and filesize < 200KB and $error and 3 of ($s*) } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: rule keyboy_systeminfo { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches the system information format before sending to C2" date = "2016-08-28" md5 = "495adb1b9777002ecfe22aaf52fcee93" strings: //These strings are ASCII pre-2015 and UNICODE in 2016 $s1 = "SystemVersion: %s" ascii wide $s2 = "Product ID: %s" ascii wide $s3 = "InstallPath: %s" ascii wide $s4 = "InstallTime: %d-%d-%d, %02d:%02d:%02d" ascii wide $s5 = "ResgisterGroup: %s" ascii wide $s6 = "RegisterUser: %s" ascii wide $s7 = "ComputerName: %s" ascii wide $s8 = "WindowsDirectory: %s" ascii wide $s9 = "System Directory: %s" ascii wide $s10 = "Number of Processors: %d" ascii wide $s11 = "CPU[%d]: %s: %sMHz" ascii wide $s12 = "RAM: %dMB Total, %dMB Free." ascii wide $s13 = "DisplayMode: %d x %d, %dHz, %dbit" ascii wide $s14 = "Uptime: %d Days %02u:%02u:%02u" ascii wide condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and filesize < 200KB and 7 of them } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe" rule keyboy_related_exports { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches the new 2016 sample's export" date = "2016-08-28" md5 = "495adb1b9777002ecfe22aaf52fcee93" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and filesize < 200KB and //The malware family seems to share many exports //but this is the new kid on the block. pe.exports("Embedding") or pe.exports("SSSS") or pe.exports("GetUP") } !Not implemented attribute category/type combination caught! attribute[Artifacts dropped][yara]: import "pe" rule keyboy_init_config_section { meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches the Init section where the config is stored" date = "2016-08-28" condition: //MZ header uint16(0) == 0x5A4D and //PE signature uint32(uint32(0x3C)) == 0x00004550 and //Payloads are normally smaller but the new dropper we spotted //is a bit larger. filesize < 300KB and //Observed virtual sizes of the .Init section vary but they've //always been 1024, 2048, or 4096 bytes. for any i in (0..pe.number_of_sections - 1): ( pe.sections[i].name == ".Init" and pe.sections[i].virtual_size % 1024 == 0 ) } !Not implemented attribute category/type combination caught! attribute[Payload delivery][yara]: rule CVE_2012_0158_KeyBoy { meta: author = "Etienne Maynier <etienne@citizenlab.ca>" description = "CVE-2012-0158 variant" file = "8307e444cad98b1b59568ad2eba5f201" strings: $a = "d0cf11e0a1b11ae1000000000000000000000000000000003e000300feff09000600000000000000000000000100000001" nocase // OLE header $b = "ffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffffff" nocase // junk data $c = /5(\{\\b0\}|)[ ]*2006F00(\{\\b0\}|)[ ]*6F007(\{\\b0\}|)[ ]*400200045(\{\\b0\}|)[ ]*006(\{\\b0\}|)[ ]*E007(\{\\b0\}|)[ ]*400720079/ nocase $d = "MSComctlLib.ListViewCtrl.2" $e = "ac38c874503c307405347aaaebf2ac2c31ebf6e8e3" nocase //decoding shellcode condition: all of them } !Not implemented attribute category/type combination caught! attribute[Payload delivery][yara]: rule keyboy_exploit_doc_meta{ meta: author = "Matt Brooks, @cmatthewbrooks" desc = "Matches the meta associated with these exploit docs" date = "2016-09-30" strings: $role = "{\\author Master}{\\operator Master}" $creatim = "{\\creatim\\yr2015\\mo10\\dy16\\hr11\\min37}" $revtim = "{\\revtim\\yr2015\\mo10\\dy16\\hr13\\min54}" condition: uint32be(0) == 0x7B5C7274 and filesize < 1MB and all of them } citizenlab ../../../descendant-or-self::node()