Files

5.0 KiB

1uuidevent_idcategorytypevaluecommentto_idsdate
2007694f1-b73a-40a5-bcf5-dded277466698Network activityurlhttp://aax.me/0b152020161108
319e97c58-4992-4f0b-8f49-6a6378a289eb8Payload deliverysha2564320204d577ef8b939115d16110e97ff04cb4f7d1e77ba5ce011d43f74abc7bemessage_032456944343.docm020161108
4280056b8-69aa-432c-9826-6d5b820eb44e8Payload deliveryemail-srcandrew.dwight389@outlook.comThe Case of the Fake Journalist020161108
535aa025c-2f62-4f9d-9fb7-391542226a7a8Network activitydomainoptimizedimghosting.comThe document’s macro was identical to the one sent to Donaghy, except it reported back to, and downloaded Stage Two from a different URL120161108
63813bc78-21d9-40a2-b76e-61016eb71ccb8Network activitydomainadhostingcache.com120161108
741c48554-6911-48eb-88a0-411dc4bd90478Payload deliverysha11c3757006f972ca957d925accf8bbb3023550d1bmessage_032456944343.docm020161108
845dbee97-3aa0-487d-bd73-a3c10a5114038Network activityip-dst95.215.44.37IP linked to adhostingcache.com020161108
9537df72e-b2b9-4016-b337-06930c42c4558Network activityurlhttp://goo.gl/60HAqJredirects to http://aax.me/0b152020161108
1058224765-51f8-4d28-9040-49798e96ca058Attributionthreat-actorStealth Falcon020161108
11582247a8-11b4-4da0-9ca1-69fe8e96ca058Payload deliverydomainaax.me120161108
12582247d0-d7a0-49c3-a6ae-69fe8e96ca058Payload deliveryurlhttp://aax.me/a6faaLink sent in a phishing email120161108
13582247f6-eeec-47b0-b6d8-69fe8e96ca058Payload deliveryurlhttps://cloud.openmailbox.org/index.php/s/ujDNWMmg8pdG3AL/authenticateownCloud15 instance020161108
145822492e-087c-4fa8-afe1-49798e96ca058Network activitydomainsimpleadbanners.comDomains linked to adhostingcache.com020161108
155822492e-1d40-4098-a87b-49798e96ca058Network activitydomainclickstatistic.comDomains linked to adhostingcache.com020161108
165822492e-7490-4c3f-9a10-49798e96ca058Network activitydomainbestairlinepricetags.comDomains linked to adhostingcache.com020161108
175822492e-d888-418e-906d-49798e96ca058Network activitydomainfasttravelclearance.comDomains linked to adhostingcache.com020161108
185822494d-792c-4d8c-9be0-49798e96ca058Network activitydomainairlineadverts.comDomain linked to incapsulawebcache.com020161108
195822494d-7ab0-42bd-bd9d-49798e96ca058Network activitydomainministrynewschannel.comDomain linked to incapsulawebcache.com020161108
205822494d-bf14-4b41-803a-49798e96ca058Network activitydomainministrynewsinfo.comDomain linked to incapsulawebcache.com020161108
2162fcd7b4-5d95-49bd-a9ff-3c2e1854839b8Network activityurlhttp://optimizedimghosting.com/wddf/hrrw/ggrr.txtThe document’s macro was identical to the one sent to Donaghy, except it reported back to, and downloaded Stage Two from a different URL020161108
226c1856f6-0068-4c83-8aba-9fd4bb4277a18Payload deliveryurlhttp://aax.me/d0ddeloaded a page containing a redirect to the website of Al Jazeera. Before completing the redirect, it invoked JavaScript to profile the target’s computer.020161108
23707eed9b-bb2c-4951-af0d-060b4c860e898External analysislinkhttps://citizenlab.org/2016/05/stealth-falcon/020161108
2470881ae4-3da1-409e-8bd3-7f508092a2c98Payload deliverysha2565a372b45285fe6f3df3ba277ee2de55d4a30fc8ef05de729cf464103632db40fright2fight.docm (malicious document)020161108
257fd6e683-9615-4f4e-b901-03e7dbb813378Network activityurlhttps://incapsulawebcache.com/cache/cache.nfo020161108
268010c934-027b-40c5-ba1e-3efca8e52d5a8Network activitydomainincapsulawebcache.comstage two server120161108
278682a3ad-80da-4732-bf5a-e675e27c56fe8Network activitydomainedgecacheimagehosting.comstage two server120161108
289ca61973-d717-496a-a158-82d9b2e379658Payload deliverymd587e1df6f36b96b56186444e37e2a1ef5message_032456944343.docm020161108
29bc8e2ca7-cd3c-4205-9028-b8b106f123898Payload deliveryemail-srcthe_right_to_fight@openmailbox.orgFake invitation020161108
30cd191e4e-a5a1-4009-93b7-92cc6a3d69848Payload deliverysha1f25466e4820404c817eaf75818b7177891735886right2fight.docm (malicious document)020161108
31d9a62cda-db4c-4d70-858c-6bbaaa041e638Network activitydomainadhostingcaches.comregistered on December 3rd120161108
32decfcbf1-1331-4624-88b7-a88c94637dd08Network activityurlhttp://adhostingcache.com/ehhe/eh4g4/adcache.txtGathered information is returned to and the server’s response is executed as a PowerShell command.020161108
33e8f3b924-1221-4d08-8fef-f689529a7b6d8Network activityurlhttp://aax.me/redirect.jsto profile a user’s system, perhaps to gather intelligence about potentially exploitable vulnerabilities.020161108
34f0215c0c-b708-43d8-873e-80a3e8e54cfa8Network activityurlhttps://edgecacheimagehosting.com/images/image.nfoThe Stage Two in this case reported back to020161108
35f4f40c31-dd17-4dc6-baa3-6beb35c04c008Payload deliverymd580e8ef78b9e28015cde4205aaa65da97right2fight.docm (malicious document)020161108