Ejemplo n.º 1
0
macrodoc = TTP(name="Macro-dropper")
macrodoc.killchain = "3"
macrodoc.description = "Macro-enabled MS Office document"
macrodoc.save()
bartalex.action(macrodoc, 'testrun', verb="leverages")
bartalex.action(macrodoc, 'testrun', verb="leverages")
bartalex.action(macrodoc, 'testrun', verb="leverages")

bartalex_callback.action(macrodoc, 'testrun', verb="seen in")
bartalex_callback2.action(macrodoc, 'testrun', verb="seen in")

payload_download = TTP(name="Payload retrieval (HTTP)")
payload_download.killchain = "3"
payload_download.description = "Payload is retreived from an external URL"
payload_download.save()
macrodoc.action(payload_download, 'testrun', verb="leverages")
bartalex_callback.action(payload_download, 'testrun', verb="indicates")
bartalex_callback2.action(payload_download, 'testrun', verb="indicates")

# add observables
o1 = Observable.add_text("85.214.71.240")
# o2 = Observable.add_text("http://soccersisters.net/mg.jpg")
o3 = Observable.add_text("http://agentseek.com/mg.jpg")
o4 = Observable.add_text("http://www.delianfoods.com/5t546523/lhf3f334f.exe")
o5 = Observable.add_text("http://sanoko.jp/5t546523/lhf3f334f.exe")
o6 = Observable.add_text("http://hrakrue-home.de/87yte55/6t45eyv.exe")
Link.connect(o6, bartalex_callback2)
Link.connect(o6, bartalex).add_history('testrun', 'Queries')
Link.connect(o6, dridex).add_history('testrun', 'Drops')
o7 = Observable.add_text("http://kdojinyhb.wz.cz/87yte55/6t45eyv.exe")
o8 = Observable.add_text("http://kdojinyhb.wz.cz/87yte55/6t45eyv.exe2")
Ejemplo n.º 2
0
# TTP

macrodoc = TTP(name="Macro-dropper")
macrodoc.killchain = "delivery"
macrodoc.description = "Macro-enabled MS Office document"
macrodoc.save()
bartalex.action("leverages", macrodoc)
bartalex_callback.action("seen in", macrodoc)
bartalex_callback2.action("seen in", macrodoc)

payload_download = TTP(name="Payload retrieval (HTTP)")
payload_download.killchain = "delivery"
payload_download.description = "Payload is retreived from an external URL"
payload_download.save()
macrodoc.action("leverages", payload_download)
bartalex_callback.action("indicates", payload_download)
bartalex_callback2.action("indicates", payload_download)

# add observables
o1 = Observable.add_text("85.214.71.240")
# o2 = Observable.add_text("http://soccersisters.net/mg.jpg")
o3 = Observable.add_text("http://agentseek.com/mg.jpg")
o4 = Observable.add_text("http://www.delianfoods.com/5t546523/lhf3f334f.exe")
o5 = Observable.add_text("http://sanoko.jp/5t546523/lhf3f334f.exe")
o6 = Observable.add_text("http://hrakrue-home.de/87yte55/6t45eyv.exe")
Link.connect(o6, bartalex_callback2)
Link.connect(o6, bartalex).add_history("Queries")
Link.connect(o6, dridex).add_history("Drops")
o7 = Observable.add_text("http://kdojinyhb.wz.cz/87yte55/6t45eyv.exe")
o8 = Observable.add_text("http://kdojinyhb.wz.cz/87yte55/6t45eyv.exe2")
Ejemplo n.º 3
0
macrodoc = TTP(name="Macro-dropper")
macrodoc.killchain = "3"
macrodoc.description = "Macro-enabled MS Office document"
macrodoc.save()
bartalex.action(macrodoc, 'testrun', verb="leverages")
bartalex.action(macrodoc, 'testrun', verb="leverages")
bartalex.action(macrodoc, 'testrun', verb="leverages")

bartalex_callback.action(macrodoc, 'testrun', verb="seen in")
bartalex_callback2.action(macrodoc, 'testrun', verb="seen in")

payload_download = TTP(name="Payload retrieval (HTTP)")
payload_download.killchain = "3"
payload_download.description = "Payload is retreived from an external URL"
payload_download.save()
macrodoc.action(payload_download, 'testrun', verb="leverages")
bartalex_callback.action(payload_download, 'testrun', verb="indicates")
bartalex_callback2.action(payload_download, 'testrun', verb="indicates")

# add observables
o1 = Observable.add_text("85.214.71.240")
# o2 = Observable.add_text("http://soccersisters.net/mg.jpg")
o3 = Observable.add_text("http://agentseek.com/mg.jpg")
o4 = Observable.add_text("http://www.delianfoods.com/5t546523/lhf3f334f.exe")
o5 = Observable.add_text("http://sanoko.jp/5t546523/lhf3f334f.exe")
o6 = Observable.add_text("http://hrakrue-home.de/87yte55/6t45eyv.exe")
Link.connect(o6, bartalex_callback2)
Link.connect(o6, bartalex).add_history('testrun', 'Queries')
Link.connect(o6, dridex).add_history('testrun', 'Drops')
o7 = Observable.add_text("http://kdojinyhb.wz.cz/87yte55/6t45eyv.exe")
o8 = Observable.add_text("http://kdojinyhb.wz.cz/87yte55/6t45eyv.exe2")