Files
Ryan Xu 1a009c8077 attack flow and cacao patch (#107) (#108)
* Update README.md

fix link

* Update README.md

* add Attack Flow content for two corpus malware

* add info about attack flow and cacao

* add info about attack flow and cacao

* info about cacao playbook

* update readme for cacao and attack flow

* add text for cacao

* update readme for cacao and attack flow

Co-authored-by: Desiree Beck <dbeck@mitre.org>
2023-06-28 10:09:08 -04:00

1177 lines
42 KiB
JSON

{
"type": "bundle",
"id": "bundle--4b103626-18ac-4365-a9f3-300815e450da",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.609Z",
"modified": "2023-04-07T14:33:04.609Z",
"objects": [
{
"type": "extension-definition",
"id": "extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4",
"spec_version": "2.1",
"created": "2022-08-02T19:34:35.143Z",
"modified": "2022-08-02T19:34:35.143Z",
"name": "Attack Flow",
"description": "Extends STIX 2.1 with features to create Attack Flows.",
"created_by_ref": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
"schema": "https://center-for-threat-informed-defense.github.io/attack-flow/stix/attack-flow-schema-2.0.0.json",
"version": "2.0.0",
"extension_types": [
"new-sdo"
],
"external_references": [
{
"source_name": "Documentation",
"description": "Documentation for Attack Flow",
"url": "https://center-for-threat-informed-defense.github.io/attack-flow"
},
{
"source_name": "GitHub",
"description": "Source code repository for Attack Flow",
"url": "https://github.com/center-for-threat-informed-defense/attack-flow"
}
]
},
{
"type": "identity",
"id": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
"spec_version": "2.1",
"created": "2022-08-02T19:34:35.143Z",
"modified": "2022-08-02T19:34:35.143Z",
"create_by_ref": "identity--fb9c968a-745b-4ade-9b25-c324172197f4",
"name": "MITRE Engenuity Center for Threat-Informed Defense",
"identity_class": "organization"
},
{
"type": "attack-flow",
"id": "attack-flow--37caa819-ace9-4d22-8313-4ab44e46640a",
"spec_version": "2.1",
"created": "2023-04-05T18:50:21.503Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"created_by_ref": "identity--dd2d58e7-c86c-419c-be28-eca4b1c815bf",
"start_refs": [
"attack-action--45238a64-cca7-4b73-b70e-f2bb9d57f5c6",
"attack-action--1514add9-71b2-41ab-9be9-2382620367ef"
],
"name": "Shamoon",
"scope": "malware",
"external_references": [
{
"source_name": "McAfee",
"description": "Article",
"url": "https://www.mcafee.com/blogs/other-blogs/mcafee-labs/shamoon-returns-to-wipe-systems-in-middle-east-europe/"
},
{
"source_name": "MBC",
"description": "Malware corpus",
"url": "https://github.com/MBCProject/mbc-markdown/blob/Lauren-malware-corpus/xample-malware/shamoon.md"
}
]
},
{
"type": "identity",
"id": "identity--dd2d58e7-c86c-419c-be28-eca4b1c815bf",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.609Z",
"modified": "2023-04-07T14:33:04.609Z",
"name": "Lauren Parker",
"identity_class": "individual",
"contact_information": "lparker@mitre.org"
},
{
"type": "attack-action",
"id": "attack-action--45238a64-cca7-4b73-b70e-f2bb9d57f5c6",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Ingress Tool Transfer",
"technique_id": "T1105",
"description": "Shamoon is placed on the target system through unknown means",
"confidence": 70,
"effect_refs": [
"attack-action--5042c11d-5d35-4bf0-a8c8-e8913e2505ce"
]
},
{
"type": "attack-condition",
"id": "attack-condition--b39f76f6-09ed-442f-b696-ac978a5487b5",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"description": "Shamoon dropper has received an appropriate argument to run",
"on_true_refs": [
"attack-action--18ac2f5f-282e-4d62-aa93-bc7567467f76"
]
},
{
"type": "attack-action",
"id": "attack-action--5042c11d-5d35-4bf0-a8c8-e8913e2505ce",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Obfuscated Files or Information",
"technique_id": "T1027",
"description": "Shamoon dropper contains 3 components masked as encrypted files embedded in the PE sections",
"confidence": 100,
"effect_refs": [
"attack-condition--b39f76f6-09ed-442f-b696-ac978a5487b5"
]
},
{
"type": "file",
"id": "file--e46c754c-c096-4f87-920d-ad5c92a47831",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"hashes": "MD5: \tde07c4ac94a50663851e5dabe6e50d1f;\nSHA-1: df177772518a8fcedbbc805ceed8daecc0f42fed; SHA-256: \tc3ab58b3154e5f5101ba74fccfd27a9ab445e41262cdf47e8cc3be7416a5904f",
"size": "1.8 MB",
"name": "MaintenaceSrv32.exe",
"ctime": "2011-11-28T16:50:59.000Z"
},
{
"type": "attack-action",
"id": "attack-action--536348d5-cd08-4031-82e0-612d13187348",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Deobfuscate/Decode Files or Information",
"technique_id": "T1140",
"description": "Shamoon dropper decrypts the embedded resources into the C:\\Windows\\System32 folder ",
"confidence": 100,
"effect_refs": [
"attack-action--11e47c90-b34b-4265-b4dc-010d857a5752"
]
},
{
"type": "tool",
"id": "tool--c344a37f-c1ae-42a1-ac43-ba185ea4bc21",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "MNU",
"description": "communication module",
"tool_types": [
"unknown"
]
},
{
"type": "malware",
"id": "malware--61779767-a88b-4883-a433-b05e0cab925d",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "Shamoon",
"description": "destructive malware targeting oil, gas, telecom, and energy companies and government organizations",
"malware_types": [
"dropper",
"trojan"
],
"is_family": true,
"capabilities": [
"escalates-privileges",
"installs-other-components",
"anti-debugging",
"anti-vm"
]
},
{
"type": "malware",
"id": "malware--8330215a-4eb4-4812-87e6-1e5b14ac4205",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "PIC",
"description": "64-bit version of the dropper",
"malware_types": [
"dropper",
"trojan"
],
"is_family": true,
"capabilities": [
"escalates-privileges",
"installs-other-components",
"anti-debugging",
"anti-vm"
]
},
{
"type": "malware",
"id": "malware--c658e292-4c33-44b7-801b-c40323499950",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "LNG",
"description": "wiper component",
"malware_types": [
"wiper"
],
"is_family": false,
"capabilities": [
"compromises-data-availability"
]
},
{
"type": "attack-action",
"id": "attack-action--18ac2f5f-282e-4d62-aa93-bc7567467f76",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Deobfuscate/Decode Files or Information",
"technique_id": "T1140",
"description": "Shamoon dropper decrypts several strings in memory",
"confidence": 100,
"effect_refs": [
"attack-action--1fe37889-9591-40d8-b20b-a3578e05f1c0"
]
},
{
"type": "attack-action",
"id": "attack-action--1fe37889-9591-40d8-b20b-a3578e05f1c0",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "System Information Discovery",
"technique_id": "T1082",
"description": "Shamoon gathers information on the System and determines whether to drop the 32-bit or 64-bit version",
"confidence": 100,
"effect_refs": [
"attack-action--f468a33c-d9e2-4938-9412-658e256acedf",
"attack-action--bcd6b440-aa42-43c0-90a7-af7a6d29ea61"
]
},
{
"type": "attack-action",
"id": "attack-action--f468a33c-d9e2-4938-9412-658e256acedf",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Ingress Tool Transfer",
"technique_id": "T1105",
"description": "Shamoon drops a file key8854321.pub into the folder c:\\Windows\\Temp\\key8854321.pub",
"confidence": 100,
"effect_refs": [
"attack-operator--adcac5fc-f2c9-439a-8ca4-82a1edba4433"
]
},
{
"type": "file",
"id": "file--057c8ab8-947c-47ec-8a01-8296cbbc3907",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"hashes": "MD5: 41f8cd9ac3fb6b1771177e5770537518; SHA-1: \t43ed9c1309d8bb14bd62b016a5c34a2adbe45943; SHA-256: \t9979678be7b89a9f01c2481ea6f420417e67572f52aad66ae4ccce3c65a7b504",
"size": "782 B",
"name": "key8854321.pub"
},
{
"type": "directory",
"id": "directory--713c50dc-64a9-4854-8804-1adffd42791e",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"path": "c:\\Windows\\Temp\\key8854321.pub"
},
{
"type": "attack-action",
"id": "attack-action--bcd6b440-aa42-43c0-90a7-af7a6d29ea61",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Deobfuscate/Decode Files or Information",
"technique_id": "T1140",
"description": "Shamoon dropper decrypts 2 files for later use",
"confidence": 100,
"effect_refs": [
"attack-operator--adcac5fc-f2c9-439a-8ca4-82a1edba4433"
]
},
{
"type": "file",
"id": "file--165ada62-d185-4ba9-9c6b-6654c71e017e",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "mdmnis5tQ1.pnf"
},
{
"type": "file",
"id": "file--e342d706-bde4-4985-890c-5a679b36399e",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "averbh_noav.pnf"
},
{
"type": "directory",
"id": "directory--2ea57f2a-3c00-4f3b-811a-0a10e7685fd9",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"path": "C:\\Windows\\inf\\mdmnis5tQ1.pnf"
},
{
"type": "directory",
"id": "directory--280eb736-0baf-4a96-97e0-65a3466cb799",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"path": "C:\\Windows\\inf\\averbh_noav.pnf"
},
{
"type": "attack-operator",
"id": "attack-operator--adcac5fc-f2c9-439a-8ca4-82a1edba4433",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"operator": "AND",
"effect_refs": [
"attack-action--1514add9-71b2-41ab-9be9-2382620367ef"
]
},
{
"type": "attack-action",
"id": "attack-action--1514add9-71b2-41ab-9be9-2382620367ef",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "System Services",
"technique_id": "T1569",
"description": "Shamoon enables the service RemoteRegistry to remotely modify the registry",
"confidence": 100,
"effect_refs": [
"attack-action--0c56e942-1cb5-4335-ac0b-fe11442bcb4a"
]
},
{
"type": "attack-action",
"id": "attack-action--0c56e942-1cb5-4335-ac0b-fe11442bcb4a",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Modify Registry",
"technique_id": "T1112",
"description": "Shamoon enables the registry key LocalAccountTokenFilterPolicy, which disables remote user account control",
"confidence": 100,
"effect_refs": [
"attack-action--7573f4c7-5cef-4aaf-853b-391dc145dd81"
]
},
{
"type": "attack-action",
"id": "attack-action--7573f4c7-5cef-4aaf-853b-391dc145dd81",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Network Share Discovery",
"technique_id": "T1135",
"description": "Malware checks if specific shares exist to copy and spread itself",
"confidence": 100,
"effect_refs": [
"attack-action--0ab1c6fd-eb0a-4601-a629-3694f5ed5222"
]
},
{
"type": "attack-action",
"id": "attack-action--0ab1c6fd-eb0a-4601-a629-3694f5ed5222",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "System Service Discovery",
"technique_id": "T1007",
"description": "Shamoon queries LocalService to retrieve specific information related to the LocalService account",
"confidence": 100,
"effect_refs": [
"attack-action--536348d5-cd08-4031-82e0-612d13187348"
]
},
{
"type": "infrastructure",
"id": "infrastructure--842a04a1-0a42-4217-9514-8787ec2e4471",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "ADMIN$",
"infrastructure_types": [
"network-share"
]
},
{
"type": "attack-action",
"id": "attack-action--11e47c90-b34b-4265-b4dc-010d857a5752",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Timestomp",
"technique_id": "T1070.006",
"description": "The file times are set to August 2012 as an anti-forensics trick",
"confidence": 100,
"effect_refs": [
"attack-action--81b765cf-ba71-4818-8b1f-276aee316264"
]
},
{
"type": "note",
"id": "note--f9d1fe3d-0efd-4a01-aa69-a668361d0d32",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"content": "Any file Shamoon can destroy, it changes the date to August 2012",
"object_refs": [
"attack-action--11e47c90-b34b-4265-b4dc-010d857a5752"
]
},
{
"type": "infrastructure",
"id": "infrastructure--aa463037-9cd7-486b-a70a-4e9c110404eb",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "C$\\WINDOWS",
"infrastructure_types": [
"network-share"
]
},
{
"type": "infrastructure",
"id": "infrastructure--f4146823-dc6c-4ece-add5-b99632572876",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "E$\\WINDOWS",
"infrastructure_types": [
"network-share"
]
},
{
"type": "infrastructure",
"id": "infrastructure--e564b7fb-d887-4ba0-a67c-7dec8bc2649f",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "D$\\WINDOWS",
"infrastructure_types": [
"network-share"
]
},
{
"type": "attack-action",
"id": "attack-action--81b765cf-ba71-4818-8b1f-276aee316264",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Access Token Manipulation: Token Impersonation/Theft",
"technique_id": "T1134.001",
"description": "Shamoon elevates privileges by impersonating the user's token",
"confidence": 100,
"effect_refs": [
"attack-action--6934aee5-fb1d-456c-a0f8-020991900f6b"
]
},
{
"type": "attack-action",
"id": "attack-action--6934aee5-fb1d-456c-a0f8-020991900f6b",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Create or Modify System Process: Windows Service",
"technique_id": "T1543.003",
"description": "Shamoon creates a new service MaintenaceSrv with the Autostart option and runs the service with its own process",
"confidence": 100,
"effect_refs": [
"attack-condition--5bca49d8-ee56-4134-a084-a4936d004801",
"attack-condition--d50a040d-b440-4034-8713-23c1c504a9af"
]
},
{
"type": "attack-condition",
"id": "attack-condition--5bca49d8-ee56-4134-a084-a4936d004801",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"description": "The wiper has been dropped on the system and can now run",
"on_true_refs": [
"attack-action--b18d81cf-9c59-413d-b148-45a2067adbbd"
]
},
{
"type": "attack-action",
"id": "attack-action--b18d81cf-9c59-413d-b148-45a2067adbbd",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Ingress Tool Transfer",
"technique_id": "T1105",
"description": "Wiper is dropped into the System32 folder",
"confidence": 100,
"effect_refs": [
"attack-action--128547af-e0f2-4185-afae-9b40736a5c56"
]
},
{
"type": "malware",
"id": "malware--a55fe43a-7622-4094-ae85-d86304ae71de",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "netbxndxlg2.exe",
"description": "This executable is the wiper component. It can have many different names and contains the wiper driver embedded within its resources. It requires a parameter to run.",
"malware_types": [
"wiper"
],
"is_family": true,
"capabilities": [
"anti-forensics",
"hides-executing-driver"
]
},
{
"type": "directory",
"id": "directory--e8d2e666-4458-4aac-b1dc-012a94de815c",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"path": "C:\\Windows\\System32"
},
{
"type": "attack-action",
"id": "attack-action--128547af-e0f2-4185-afae-9b40736a5c56",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Obfuscated Files or Information",
"technique_id": "T1027",
"description": "Shamoon wiper component contains the wiper driver embedded in its resources",
"confidence": 100,
"effect_refs": [
"attack-action--697e8511-7e7e-48b3-aff7-0bf6b15bc868"
]
},
{
"type": "attack-action",
"id": "attack-action--697e8511-7e7e-48b3-aff7-0bf6b15bc868",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Deobfuscate/Decode Files or Information",
"technique_id": "T1140",
"description": "Shamoon wiper decrypts the wiper driver",
"confidence": 100,
"effect_refs": [
"attack-action--ce6c04c1-c6ab-4aab-a194-ac50e51640d7"
]
},
{
"type": "malware",
"id": "malware--e6bee1d3-8348-4b91-a453-86e1d8e9dfc3",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "hdv_725x.sys",
"description": "Wiper driver which can have multiple different names.",
"malware_types": [
"wiper"
],
"is_family": true,
"capabilities": [
"compromises-data-availability",
"wipes-data"
]
},
{
"type": "file",
"id": "file--5d5d34f0-e5c5-44ec-99dd-a0489af7c07e",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"hashes": "MD5: \t887c614608e7cd9a691858caf468c28f; SHA-1: \tceb7876c01c75673699c74ff7fac64a5ca0e67a1; SHA-256: 391e7b90bf3f0bfeb2c2602cc65aa6be4dd1c01374b89c4a48425f2d22fe231c",
"size": "393 KB",
"name": "netbxndxlg2.exe",
"ctime": "2011-11-28T15:52:52.000Z"
},
{
"type": "attack-action",
"id": "attack-action--ce6c04c1-c6ab-4aab-a194-ac50e51640d7",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Create or Modify System Process: Windows Service",
"technique_id": "T1543.003",
"description": "The wiper driver creates a service to run the driver",
"confidence": 100,
"command_ref": "process--e57d55da-f484-4028-b536-6c1db57e1aac",
"effect_refs": [
"attack-action--2f8b5bc0-849b-44c2-adbd-4846bfbcf382"
]
},
{
"type": "process",
"id": "process--e57d55da-f484-4028-b536-6c1db57e1aac",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"command_line": "sc create hdv_725x type= kernel start= demand binpath= WINDOWS\\hdv_725x.sys 2>&1 >nul"
},
{
"type": "attack-action",
"id": "attack-action--2f8b5bc0-849b-44c2-adbd-4846bfbcf382",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Disk Wipe",
"technique_id": "T1561",
"description": "The wiper driver overwrites every file in C:\\Windows\\System32 and all files on the system",
"confidence": 100,
"effect_refs": [
"attack-action--3a6645fc-5ec3-426b-be28-b2faaa221b1f"
]
},
{
"type": "attack-action",
"id": "attack-action--3a6645fc-5ec3-426b-be28-b2faaa221b1f",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "System Shutdown/Reboot",
"technique_id": "T1529",
"description": "Disk wiper forces a reboot",
"confidence": 100,
"command_ref": "process--8a2b6ded-1aab-48fd-a713-7d5cd7bf5cad"
},
{
"type": "process",
"id": "process--8a2b6ded-1aab-48fd-a713-7d5cd7bf5cad",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"command_line": "Shutdown -r -f -t 2"
},
{
"type": "note",
"id": "note--2506b2a8-07a9-4a3a-a7d8-5621298b9fc8",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"content": "Once reboot, the system shows a blue screen",
"object_refs": [
"attack-action--3a6645fc-5ec3-426b-be28-b2faaa221b1f"
]
},
{
"type": "attack-condition",
"id": "attack-condition--d50a040d-b440-4034-8713-23c1c504a9af",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"description": "The worm component is dropped onto the system ",
"on_true_refs": [
"attack-action--ef1f8cce-2e33-4444-bf37-e5c1d4bc20c2"
]
},
{
"type": "attack-action",
"id": "attack-action--ef1f8cce-2e33-4444-bf37-e5c1d4bc20c2",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Ingress Tool Transfer",
"technique_id": "T1105",
"description": "Worm is dropped into the System32 folder",
"confidence": 100,
"effect_refs": [
"attack-action--2d0ca7f5-25c6-4f85-aab7-9694e1cb4214"
]
},
{
"type": "malware",
"id": "malware--b242717a-18bc-4380-bc3b-9e96a2b6e7b2",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"name": "averfx2swtvZ.exe",
"description": "Worm component can have many different names",
"malware_types": [
"worm"
],
"is_family": true,
"capabilities": [
"access-remote-machines",
"infects-remote-machines",
"probes-local-network"
]
},
{
"type": "file",
"id": "file--538ab06b-7a80-4a90-b586-8e8e837222a6",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"hashes": "MD5: b41f586fc9c95c66f0967f1592641a85; SHA-1: \t10411f07640edcaa6104f078af09e2543aa0ca07; SHA-256: \t0694bdf9f08e4f4a09d13b7b5a68c0148ceb3fcc79442f4db2aa19dd23681afe",
"size": "260.50 KB",
"name": "averfx2swtvZ.exe",
"ctime": "2011-11-28T15:53:13.000Z"
},
{
"type": "directory",
"id": "directory--2d04594e-97e6-419f-8846-ecc667d28350",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"path": "C:\\Windows\\System32"
},
{
"type": "file",
"id": "file--a8a30517-52b1-4c70-9814-93e3fd456c26",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"hashes": "MD5: 92fff1d754faab445e90651dfb0ded4d; SHA- 1: \tbf3e0bc893859563811e9a481fde84fe7ecd0684; SHA-256: \t6985ef5809d0789eeff623cd2436534b818fd2843f09fa2de2b4a6e2c0e1a879",
"size": "27.14 KB",
"name": "hdv_725x.sys",
"ctime": "2011-12-28T17:51:24.000Z"
},
{
"type": "attack-action",
"id": "attack-action--2d0ca7f5-25c6-4f85-aab7-9694e1cb4214",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Remote System Discovery",
"technique_id": "T1018",
"description": "Worm scans the local network for potential control servers to connect to",
"confidence": 100,
"effect_refs": [
"attack-condition--ad9dc433-b702-4ef9-9a89-84f72a90fe85"
]
},
{
"type": "attack-condition",
"id": "attack-condition--ad9dc433-b702-4ef9-9a89-84f72a90fe85",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"description": "Worm connects to remote servers",
"on_true_refs": [
"attack-action--dfbfce2d-4710-4333-b591-62ef89bbb868"
]
},
{
"type": "attack-action",
"id": "attack-action--dfbfce2d-4710-4333-b591-62ef89bbb868",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"extensions": {
"extension-definition--fb9c968a-745b-4ade-9b25-c324172197f4": {
"extension_type": "new-sdo"
}
},
"name": "Lateral Tool Transfer",
"technique_id": "T1570",
"description": "Worm can spread the Shamoon dropper to remote systems",
"confidence": 100
},
{
"type": "note",
"id": "note--0b87f10c-f4f6-4d97-9d14-c8dc717bc124",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"content": "The wiper can be used independently from the dropper",
"object_refs": [
"file--5d5d34f0-e5c5-44ec-99dd-a0489af7c07e"
]
},
{
"type": "note",
"id": "note--23503f72-803d-41c0-af57-db208344cd82",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"content": "Shamoon has evolved over the years. This is the name of the Shamoon service created in 2018. In 2016, the service created was NtsSrv. In 2017, the service created was NtertSrv.",
"object_refs": [
"attack-action--6934aee5-fb1d-456c-a0f8-020991900f6b"
]
},
{
"type": "note",
"id": "note--7ce81b7a-c7e4-49e9-9011-cb6e8628cbb2",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"content": "The worm component may not run during the infection. The worm and the wiper are mutually exclusive components.",
"object_refs": [
"attack-condition--d50a040d-b440-4034-8713-23c1c504a9af"
]
},
{
"type": "relationship",
"id": "relationship--8b08fa3a-922c-4ce0-b2ad-8144295feb74",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--45238a64-cca7-4b73-b70e-f2bb9d57f5c6",
"target_ref": "malware--61779767-a88b-4883-a433-b05e0cab925d"
},
{
"type": "relationship",
"id": "relationship--9badb941-4667-4d60-814b-135fc92f3748",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--536348d5-cd08-4031-82e0-612d13187348",
"target_ref": "tool--c344a37f-c1ae-42a1-ac43-ba185ea4bc21"
},
{
"type": "relationship",
"id": "relationship--cb408a9a-ccdd-4d02-b859-9ca581dba035",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--536348d5-cd08-4031-82e0-612d13187348",
"target_ref": "malware--8330215a-4eb4-4812-87e6-1e5b14ac4205"
},
{
"type": "relationship",
"id": "relationship--9b610f7b-ae46-449f-81e6-5dca1836398f",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--536348d5-cd08-4031-82e0-612d13187348",
"target_ref": "malware--c658e292-4c33-44b7-801b-c40323499950"
},
{
"type": "relationship",
"id": "relationship--f75d7c2e-43c7-4840-a94b-9d23ef6c1991",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "malware--61779767-a88b-4883-a433-b05e0cab925d",
"target_ref": "file--e46c754c-c096-4f87-920d-ad5c92a47831"
},
{
"type": "relationship",
"id": "relationship--dda9fabb-5d18-458a-aaf1-1e722651c47f",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--f468a33c-d9e2-4938-9412-658e256acedf",
"target_ref": "file--057c8ab8-947c-47ec-8a01-8296cbbc3907"
},
{
"type": "relationship",
"id": "relationship--ee5d30a6-6c96-41e6-b219-65f58eb47723",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "file--057c8ab8-947c-47ec-8a01-8296cbbc3907",
"target_ref": "directory--713c50dc-64a9-4854-8804-1adffd42791e"
},
{
"type": "relationship",
"id": "relationship--916f4c68-1ccf-4752-a1be-ee14dc4e8017",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--bcd6b440-aa42-43c0-90a7-af7a6d29ea61",
"target_ref": "file--e342d706-bde4-4985-890c-5a679b36399e"
},
{
"type": "relationship",
"id": "relationship--3c6cfd47-e762-4d5a-9e63-65b4a0a62a2c",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--bcd6b440-aa42-43c0-90a7-af7a6d29ea61",
"target_ref": "file--165ada62-d185-4ba9-9c6b-6654c71e017e"
},
{
"type": "relationship",
"id": "relationship--c09b64df-0d02-42a1-b530-e07ad426b71e",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "file--165ada62-d185-4ba9-9c6b-6654c71e017e",
"target_ref": "directory--2ea57f2a-3c00-4f3b-811a-0a10e7685fd9"
},
{
"type": "relationship",
"id": "relationship--71f595a7-66da-4ab9-931f-daed28c93ae6",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "file--e342d706-bde4-4985-890c-5a679b36399e",
"target_ref": "directory--280eb736-0baf-4a96-97e0-65a3466cb799"
},
{
"type": "relationship",
"id": "relationship--cf9d0ba0-5c2b-47e0-8710-5ab3cabfbf89",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--7573f4c7-5cef-4aaf-853b-391dc145dd81",
"target_ref": "infrastructure--f4146823-dc6c-4ece-add5-b99632572876"
},
{
"type": "relationship",
"id": "relationship--8b6ca669-bbe2-420a-8e34-5d4133b9919c",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--7573f4c7-5cef-4aaf-853b-391dc145dd81",
"target_ref": "infrastructure--e564b7fb-d887-4ba0-a67c-7dec8bc2649f"
},
{
"type": "relationship",
"id": "relationship--f05185d2-ad48-4ae2-9225-39fb25257070",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--7573f4c7-5cef-4aaf-853b-391dc145dd81",
"target_ref": "infrastructure--842a04a1-0a42-4217-9514-8787ec2e4471"
},
{
"type": "relationship",
"id": "relationship--a020c0e6-55cc-4bdb-9b20-459226dab84c",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.610Z",
"modified": "2023-04-07T14:33:04.610Z",
"relationship_type": "related-to",
"source_ref": "attack-action--7573f4c7-5cef-4aaf-853b-391dc145dd81",
"target_ref": "infrastructure--aa463037-9cd7-486b-a70a-4e9c110404eb"
},
{
"type": "relationship",
"id": "relationship--f24bbdd1-e089-463a-829a-680eaaae797c",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.611Z",
"modified": "2023-04-07T14:33:04.611Z",
"relationship_type": "related-to",
"source_ref": "attack-action--b18d81cf-9c59-413d-b148-45a2067adbbd",
"target_ref": "malware--a55fe43a-7622-4094-ae85-d86304ae71de"
},
{
"type": "relationship",
"id": "relationship--777c3a0b-422b-4e68-9958-8441316c75c0",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.611Z",
"modified": "2023-04-07T14:33:04.611Z",
"relationship_type": "related-to",
"source_ref": "malware--a55fe43a-7622-4094-ae85-d86304ae71de",
"target_ref": "directory--e8d2e666-4458-4aac-b1dc-012a94de815c"
},
{
"type": "relationship",
"id": "relationship--b40638ae-cb16-460b-889b-26db24c9aff4",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.611Z",
"modified": "2023-04-07T14:33:04.611Z",
"relationship_type": "related-to",
"source_ref": "malware--a55fe43a-7622-4094-ae85-d86304ae71de",
"target_ref": "file--5d5d34f0-e5c5-44ec-99dd-a0489af7c07e"
},
{
"type": "relationship",
"id": "relationship--53da268e-da39-488b-ab01-2c874374b333",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.611Z",
"modified": "2023-04-07T14:33:04.611Z",
"relationship_type": "related-to",
"source_ref": "attack-action--697e8511-7e7e-48b3-aff7-0bf6b15bc868",
"target_ref": "malware--e6bee1d3-8348-4b91-a453-86e1d8e9dfc3"
},
{
"type": "relationship",
"id": "relationship--19d2cecb-de9c-4afd-8bee-1ea3cf84cf43",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.611Z",
"modified": "2023-04-07T14:33:04.611Z",
"relationship_type": "related-to",
"source_ref": "malware--e6bee1d3-8348-4b91-a453-86e1d8e9dfc3",
"target_ref": "file--a8a30517-52b1-4c70-9814-93e3fd456c26"
},
{
"type": "relationship",
"id": "relationship--fa3c9953-e564-4d2b-bcd1-af70dde6a7c6",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.611Z",
"modified": "2023-04-07T14:33:04.611Z",
"relationship_type": "related-to",
"source_ref": "attack-action--ef1f8cce-2e33-4444-bf37-e5c1d4bc20c2",
"target_ref": "malware--b242717a-18bc-4380-bc3b-9e96a2b6e7b2"
},
{
"type": "relationship",
"id": "relationship--2b8e0a9f-e3f6-4b64-8683-51f04ddc6941",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.611Z",
"modified": "2023-04-07T14:33:04.611Z",
"relationship_type": "related-to",
"source_ref": "malware--b242717a-18bc-4380-bc3b-9e96a2b6e7b2",
"target_ref": "file--538ab06b-7a80-4a90-b586-8e8e837222a6"
},
{
"type": "relationship",
"id": "relationship--dd796c44-54a5-463a-aac8-16c55842b894",
"spec_version": "2.1",
"created": "2023-04-07T14:33:04.611Z",
"modified": "2023-04-07T14:33:04.611Z",
"relationship_type": "related-to",
"source_ref": "malware--b242717a-18bc-4380-bc3b-9e96a2b6e7b2",
"target_ref": "directory--2d04594e-97e6-419f-8846-ecc667d28350"
}
]
}