<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>IOC: Forensic Artifacts</title>
	<atom:link href="http://ioc.forensicartifacts.com/feed/" rel="self" type="application/rss+xml" />
	<link>http://ioc.forensicartifacts.com</link>
	<description>The Definitive Database</description>
	<lastBuildDate>Fri, 11 May 2012 00:02:37 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>Debugger Persistence Mechanism</title>
		<link>http://ioc.forensicartifacts.com/2012/05/debugger-persistence-mechanism/</link>
		<comments>http://ioc.forensicartifacts.com/2012/05/debugger-persistence-mechanism/#comments</comments>
		<pubDate>Fri, 11 May 2012 00:02:37 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Registry]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Debugger]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Persistence]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=144</guid>
		<description><![CDATA[Authored By: TomU @c_APT_ure Description: This IOC detects malware that abuses the debugger mechanism to get injected into a legit system process at startup. ThreatExpert uses this sentence with variable executable names: &#8220;so that [malware.exe] is injected into the execution sequence of [legit-system.exe] by being installed as its default debugger&#8221; A Google search for these [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
TomU @c_APT_ure</p>
<p><strong>Description: </strong><br />
This IOC detects malware that abuses the debugger mechanism to get injected into a legit system process at startup. ThreatExpert uses this sentence with variable executable names: &#8220;so that [malware.exe] is injected into the execution sequence of [legit-system.exe] by being installed as its default debugger&#8221; A Google search for these terms (on ThreatExpert only) currently gives 2&#8217;240 hits (sample query: &#8220;site:threatexpert.com Image File Execution Options installs default debugger injected into the execution sequence&#8221;).</p>
<p><strong>Reports:</strong><br />
<a href="http://www.threatexpert.com/report.aspx?md5=9f7017b619c86759a5c981642c0bb521">http://www.threatexpert.com/report.aspx?md5=9f7017b619c86759a5c981642c0bb521</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=0b326488f7b5fc3c18641efbb6807b69">http://www.threatexpert.com/report.aspx?md5=0b326488f7b5fc3c18641efbb6807b69</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=dc6379164bf931aeba991df856fe11f8">http://www.threatexpert.com/report.aspx?md5=dc6379164bf931aeba991df856fe11f8</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=3ccc73f049a1de731baf7ea8915c92a8">http://www.threatexpert.com/report.aspx?md5=3ccc73f049a1de731baf7ea8915c92a8</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=48352e3a034a95845864c0f6aad07d39">http://www.threatexpert.com/report.aspx?md5=48352e3a034a95845864c0f6aad07d39</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=5458f76466e7ae80f1a57d6038fd9f1e">http://www.threatexpert.com/report.aspx?md5=5458f76466e7ae80f1a57d6038fd9f1e</a><br />
<a href="http://msdn.microsoft.com/en-us/library/a329t4ed%28v=vs.71%29.aspx">http://msdn.microsoft.com/en-us/library/a329t4ed%28v=vs.71%29.aspx</a><br />
<a href="http://msdn.microsoft.com/en-us/library/a329t4ed.aspx">http://msdn.microsoft.com/en-us/library/a329t4ed.aspx</a></p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;Registry KeyPath contains SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\<br />
&nbsp;&nbsp;&nbsp;Registry KeyPath contains .exe<br />
&nbsp;&nbsp;&nbsp;Registry ValueName is Debugger</p>
<p><strong>Download:<strong><br />
<a href='http://ioc.forensicartifacts.com/wp-content/uploads/2012/05/35ac9307-155e-4272-8dc0-dd98ed6c6ac5.ioc'>35ac9307-155e-4272-8dc0-dd98ed6c6ac5.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/05/debugger-persistence-mechanism/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>PWS-Zbot.gen.xj</title>
		<link>http://ioc.forensicartifacts.com/2012/05/pws-zbot-gen-xj/</link>
		<comments>http://ioc.forensicartifacts.com/2012/05/pws-zbot-gen-xj/#comments</comments>
		<pubDate>Wed, 02 May 2012 23:09:46 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[credential stealer]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=139</guid>
		<description><![CDATA[Authored By: TomU @c_APT_ure Description: malware EXE in PWD-protected ZIP delivered via Mail Reports: http://www.threatexpert.com/report.aspx?md5=0b326488f7b5fc3c18641efbb6807b69 http://www.sophos.com/de-de/threat-center/threat-analyses/viruses-and-spyware/Troj~Agent-VXI/detailed-analysis.aspx http://r.virscan.org/eb8d79b5fa6a88a21971cd8bc138e28f http://www.malware-control.com/statics-pages/0b326488f7b5fc3c18641efbb6807b69.php Indicators: OR &#160;&#160;&#160;File MD5 is 0b326488f7b5fc3c18641efbb6807b69 &#160;&#160;&#160;File MD5 is d667e6d28b341d5f61e4ed78e8f80232 &#160;&#160;&#160;File MD5 is 50f0fd1302b597bf4a94643a8bf1e08e &#160;&#160;&#160;File MD5 is A37D6F31AB21517E1CFB1F31C215D02C &#160;&#160;&#160;File MD5 is 82C1863434C15DB2A63525754751B9C0 &#160;&#160;&#160;File MD5 is cbe4cb47c73bfd9b8463f6dfae626872 &#160;&#160;&#160;File MD5 is 1b22c2f6988b89c21b7a5d8b7631f9ca &#160;&#160;&#160;File MD5 is f533b6c18dfdd82bf04efc8754071a02 &#160;&#160;&#160;Sha1sum is b8d14593843d1c1bfb7af4d018070e5bb5746fb3 [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
TomU @c_APT_ure</p>
<p><strong>Description: </strong><br />
malware EXE in PWD-protected ZIP delivered via Mail</p>
<p><strong>Reports:</strong><br />
<a href="http://www.threatexpert.com/report.aspx?md5=0b326488f7b5fc3c18641efbb6807b69">http://www.threatexpert.com/report.aspx?md5=0b326488f7b5fc3c18641efbb6807b69</a><br />
<a href="http://www.sophos.com/de-de/threat-center/threat-analyses/viruses-and-spyware/Troj~Agent-VXI/detailed-analysis.aspx">http://www.sophos.com/de-de/threat-center/threat-analyses/viruses-and-spyware/Troj~Agent-VXI/detailed-analysis.aspx</a><br />
<a href="http://r.virscan.org/eb8d79b5fa6a88a21971cd8bc138e28f">http://r.virscan.org/eb8d79b5fa6a88a21971cd8bc138e28f</a><br />
<a href="http://www.malware-control.com/statics-pages/0b326488f7b5fc3c18641efbb6807b69.php">http://www.malware-control.com/statics-pages/0b326488f7b5fc3c18641efbb6807b69.php</a></p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;File MD5 is 0b326488f7b5fc3c18641efbb6807b69<br />
&nbsp;&nbsp;&nbsp;File MD5 is d667e6d28b341d5f61e4ed78e8f80232<br />
&nbsp;&nbsp;&nbsp;File MD5 is 50f0fd1302b597bf4a94643a8bf1e08e<br />
&nbsp;&nbsp;&nbsp;File MD5 is A37D6F31AB21517E1CFB1F31C215D02C<br />
&nbsp;&nbsp;&nbsp;File MD5 is 82C1863434C15DB2A63525754751B9C0<br />
&nbsp;&nbsp;&nbsp;File MD5 is cbe4cb47c73bfd9b8463f6dfae626872<br />
&nbsp;&nbsp;&nbsp;File MD5 is 1b22c2f6988b89c21b7a5d8b7631f9ca<br />
&nbsp;&nbsp;&nbsp;File MD5 is f533b6c18dfdd82bf04efc8754071a02<br />
&nbsp;&nbsp;&nbsp;Sha1sum is b8d14593843d1c1bfb7af4d018070e5bb5746fb3<br />
&nbsp;&nbsp;&nbsp;File Name contains Details-From-Booking-Com_Reservation<br />
&nbsp;&nbsp;&nbsp;Network DNS is armyclub.net<br />
&nbsp;&nbsp;&nbsp;Network DNS is safeoil.net<br />
&nbsp;&nbsp;&nbsp;Network DNS contains .0zz0.com<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry KeyPath is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Execution Options\userinit.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry ValueName is Debugger<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry KeyPath is HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Settings\5.0\83F20BB1</p>
<p><strong>Download:</strong><br />
<a href='http://ioc.forensicartifacts.com/wp-content/uploads/2012/05/25a50f37-eac1-41a9-ac8d-4668df520dd1.ioc'>25a50f37-eac1-41a9-ac8d-4668df520dd1</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/05/pws-zbot-gen-xj/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ponmocup &#8211; #2</title>
		<link>http://ioc.forensicartifacts.com/2012/04/ponmocup-2/</link>
		<comments>http://ioc.forensicartifacts.com/2012/04/ponmocup-2/#comments</comments>
		<pubDate>Mon, 09 Apr 2012 00:35:44 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Ponmocup]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=121</guid>
		<description><![CDATA[Authored By: TomU @c_APT_ure Description: Detects an infected system from the ponmocup malware (with what I think is the most common basic indicator Reports: http://c-apt-ure.blogspot.com/2012/02/not-apt-but-nasty-malware-ponmocup.html http://c-apt-ure.blogspot.com/2012/03/ponmocup-lots-changed-but-not-all.html http://www9.dyndns-server.com:8080/pub/botnet-links.html http://www9.dyndns-server.com:8080/pub/botnet/ponmocup/ponmocup-analysis_2012-02-18.html http://www.threatexpert.com/report.aspx?md5=1098b041b743fa06e276eca074042b3d http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Mal~Ponmocup-A/detailed-analysis.aspx Indicators: OR &#160;&#160;&#160;AND &#160;&#160;&#160;&#160;&#160;&#160;Registry Path contains SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings &#160;&#160;&#160;&#160;&#160;&#160;Registry Type is REG_BINARY &#160;&#160;&#160;&#160;&#160;&#160;OR &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;Registry ValueName is 6 &#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;&#160;Registry ValueName is 9 Download: bcb504f2-8f2c-478d-9b25-042e8b952dc6.ioc]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
TomU @c_APT_ure</p>
<p><strong>Description: </strong><br />
Detects an infected system from the ponmocup malware (with what I think is the most common basic indicator</p>
<p><strong>Reports:</strong><br />
<a href="http://c-apt-ure.blogspot.com/2012/02/not-apt-but-nasty-malware-ponmocup.html">http://c-apt-ure.blogspot.com/2012/02/not-apt-but-nasty-malware-ponmocup.html</a><br />
<a href="http://c-apt-ure.blogspot.com/2012/03/ponmocup-lots-changed-but-not-all.html">http://c-apt-ure.blogspot.com/2012/03/ponmocup-lots-changed-but-not-all.html</a><br />
<a href="http://www9.dyndns-server.com:8080/pub/botnet-links.html">http://www9.dyndns-server.com:8080/pub/botnet-links.html</a><br />
<a href="http://www9.dyndns-server.com:8080/pub/botnet/ponmocup/ponmocup-analysis_2012-02-18.html">http://www9.dyndns-server.com:8080/pub/botnet/ponmocup/ponmocup-analysis_2012-02-18.html</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=1098b041b743fa06e276eca074042b3d">http://www.threatexpert.com/report.aspx?md5=1098b041b743fa06e276eca074042b3d</a><br />
<a href="http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Mal~Ponmocup-A/detailed-analysis.aspx">http://www.sophos.com/en-us/threat-center/threat-analyses/viruses-and-spyware/Mal~Ponmocup-A/detailed-analysis.aspx<br />
</a></p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Path contains SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Type is REG_BINARY<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;OR<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry ValueName is 6<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry ValueName is 9</p>
<p><strong>Download:</strong><br />
<a href='http://ioc.forensicartifacts.com/wp-content/uploads/2012/04/bcb504f2-8f2c-478d-9b25-042e8b952dc6.ioc'>bcb504f2-8f2c-478d-9b25-042e8b952dc6.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/04/ponmocup-2/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Zeus AnalyticDNS.com</title>
		<link>http://ioc.forensicartifacts.com/2012/03/zeus-analyticdns-com/</link>
		<comments>http://ioc.forensicartifacts.com/2012/03/zeus-analyticdns-com/#comments</comments>
		<pubDate>Sat, 24 Mar 2012 14:25:53 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[analyticdns.com]]></category>
		<category><![CDATA[credential stealer]]></category>
		<category><![CDATA[myapp-ups.com]]></category>
		<category><![CDATA[phishing email]]></category>
		<category><![CDATA[Zeus]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=115</guid>
		<description><![CDATA[Authored By: @LucasErratus Description: This malware is a variant of the Zeus Bot. Change the exe size range to make it fuzzy and detect exe files in the directory it gets dropped to (e.g. 100000 TO 200000). That will allow it to catch all versions and varients that still copy to that location. Indicators: OR [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
@LucasErratus</p>
<p><strong>Description: </strong><br />
This malware is a variant of the Zeus Bot. Change the exe size range to make it fuzzy and detect exe files in the directory it gets dropped to (e.g. 100000 TO 200000). That will allow it to catch all versions and varients that still copy to that location.</p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;DnsEntryItem/Host contains myapp-ups.com<br />
&nbsp;&nbsp;&nbsp;DnsEntryItem/Host contains analyticdns.com<br />
&nbsp;&nbsp;&nbsp;File PEInfo VersionInfoList VersionInfo OriginalFilename is Y2gtqjxmvounynm.exe<br />
&nbsp;&nbsp;&nbsp;File CertificateSubject is Tfrbpcs<br />
&nbsp;&nbsp;&nbsp;File PEInfo VersionInfoList VersionInfo Companyname is Walter Hintenaus<br />
&nbsp;&nbsp;&nbsp;File PEInfo VersionInfoList VersionInfo InternalName is Lodge Tuna Angel<br />
&nbsp;&nbsp;&nbsp;File PEInfo VersionInfoList VersionInfo ProductName is Loyal<br />
&nbsp;&nbsp;&nbsp;File PEInfo VersionInfoList VersionInfo FileDescription is Seth Achoo Xiv<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains -DED2-FBD9A76483EE}<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains -6CED-298D15DD51B5}<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains -2E3B-B788507ACFBF}<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains -377E-962C6878EE14}<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;OR<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Extension is exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;OR<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Size is [154192 TO 154192]<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Compile Time is 2011-07-24T05:58:28Z<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Extension is tmp<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Size is 0<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;OR<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Full Path contains \Users\<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Full Path contains \AppData\Roaming\<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Full path contains \Application Data\<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Full path contains Documents<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;File Full path contains Settings</p>
<p><strong>Download:</strong><br />
<a href='http://ioc.forensicartifacts.com/wp-content/uploads/2012/03/10ccb93f-970b-4f0a-8e0c-5772cdd90a20.ioc'>10ccb93f-970b-4f0a-8e0c-5772cdd90a20.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/03/zeus-analyticdns-com/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ramnit</title>
		<link>http://ioc.forensicartifacts.com/2012/01/ramnit/</link>
		<comments>http://ioc.forensicartifacts.com/2012/01/ramnit/#comments</comments>
		<pubDate>Fri, 20 Jan 2012 02:48:57 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[OpenIOC]]></category>
		<category><![CDATA[Ramnit]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=104</guid>
		<description><![CDATA[Authored By: Christopher Bentley &#8211; @cbentle2 Description: IOC for Ramnit, Advanced Malware that has rookit capabilities, and has been seen to drop addtional malware on the infected host including spam engine. Reports: http://contagiodump.blogspot.com/2012/01/blackhole-ramnit-samples-and-analysis.html#more http://www.threatexpert.com/report.aspx?md5=e4633c77362e55dde5fdcda63f826c1b Indicators: OR &#160;&#160;&#160;Process StringList is \\.\631D2408D44C4f47AC647AB96987D4D5 &#160;&#160;&#160;Process Handle Name is !IETld!Mutex &#160;&#160;&#160;DriverItem/StringList/string is &#160;&#160;&#160;c:\project\demetra\loader~1\drivers\ssdt\driver~1\objfre_win7_x86\i386\SdtRestore.pdb &#160;&#160;&#160;DriverItem/StringList/string is \Device\631D2408D44C4f47AC647AB96987D4D5 &#160;&#160;&#160;Process StringList contains ECHOADDSUBSETDATECONTENT [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
Christopher Bentley &#8211; @cbentle2</p>
<p><strong>Description: </strong><br />
IOC for Ramnit, Advanced Malware that has rookit capabilities, and has been seen to drop addtional malware on the infected host including spam engine.</p>
<p><strong>Reports:</strong><br />
<a href="http://contagiodump.blogspot.com/2012/01/blackhole-ramnit-samples-and-analysis.html#more">http://contagiodump.blogspot.com/2012/01/blackhole-ramnit-samples-and-analysis.html#more</a><br />
<a href="http://www.threatexpert.com/report.aspx?md5=e4633c77362e55dde5fdcda63f826c1b">http://www.threatexpert.com/report.aspx?md5=e4633c77362e55dde5fdcda63f826c1b</a></p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;Process StringList is \\.\631D2408D44C4f47AC647AB96987D4D5<br />
&nbsp;&nbsp;&nbsp;Process Handle Name is !IETld!Mutex<br />
&nbsp;&nbsp;&nbsp;DriverItem/StringList/string is &nbsp;&nbsp;&nbsp;c:\project\demetra\loader~1\drivers\ssdt\driver~1\objfre_win7_x86\i386\SdtRestore.pdb<br />
&nbsp;&nbsp;&nbsp;DriverItem/StringList/string is \Device\631D2408D44C4f47AC647AB96987D4D5<br />
&nbsp;&nbsp;&nbsp;Process StringList contains <%IDBOT%><%REMOTE={*}%><#{*} {*}#>ECHOADDSUBSETDATECONTENT POST<br />
&nbsp;&nbsp;&nbsp;DriverItem/StringList/string is 631D2408D44C4f47AC647AB96987D4D5<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Hook HookDescription is SystemCall<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Hook Hooking Module contains \LOCALS~1\Temp\<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Hook Hooked Module is ntoskrnl.exe<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList contains Micorsoft Windows Service<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList contains TANGrabber<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Name is services.exe<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process arguments is not 	C:\WINDOWS\System32\svchost.exe -k netsvcs<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process arguments is not 	C:\WINDOWS\System32\svchost -k rpcss<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process arguments is not 	C:\WINDOWS\System32\svchost.exe -k LocalService<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process arguments is not 	C:\WINDOWS\System32\svchost.exe -k NetworkService<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process arguments is not 	C:\WINDOWS\System32\svchost -k DcomLaunch<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Name is svchost.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process arguments is not 	C:\WINDOWS\System32\svchost.exe -k imgsvc<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Name is svchost.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;OR<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList contains LOCALS~1\Temp\~TM4.tmp<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is Hide Browser v1.1<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is 220 220 RMNetwork FTP<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is Ftp Grabber v1.0<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is Virus Module v1.0 (exe, dll only)<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is VNC Module v1.0 (Zeus Model)<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is Byob Ernie Gild Lotto 2002-2006<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is Reich.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Handle Name contains CTF.Compart.MutexDefaultS-1-5-21<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Handle Name contains CTF.Layouts.MutexDefaultS-1-5-21<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Handle Name contains CTF.TMD.MutexDefaultS-1-5-21<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Handle Name contains CTF.TimListCache.FMPDefaultsS-1-5-21<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Handle Name contains CTF.Asm.MutexDefaultS-1-5-21<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Handle Name contains CTF.LBES.MutexDefaultS-1-5-21<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Handle Name contains \Start Menu\Programs\Startup<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clMailMessage.pas<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clSocket.pas<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clCertificate.pas<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clSspiTls.pas<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clTlsSocket.pas<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clSocks.pas<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is X:\old_backup\Delphi\Mailer4\cl\Sources\clTcpClient.pas<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TModule_POPPeeper<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TModule_Eudora<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TModule_Gmail<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TModule_IncrediMail<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TModule_GroupMailFree<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TModule_VypressAuvis<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TModule_The_Bat<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TModule_Outlook0<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList is TOutlookIdentItem</p>
<p><strong>Download:</strong><br />
<a href="http://ioc.forensicartifacts.com/wp-content/uploads/2012/01/5c03d9e7-c67c-45e8-aa2f-326bc5ddc76a.ioc" title="5c03d9e7-c67c-45e8-aa2f-326bc5ddc76a.ioc" target="_blank">5c03d9e7-c67c-45e8-aa2f-326bc5ddc76a.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/01/ramnit/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Duqu</title>
		<link>http://ioc.forensicartifacts.com/2012/01/duqu/</link>
		<comments>http://ioc.forensicartifacts.com/2012/01/duqu/#comments</comments>
		<pubDate>Sat, 07 Jan 2012 01:35:30 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Virus]]></category>
		<category><![CDATA[Windows]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=95</guid>
		<description><![CDATA[Authored By: Christopher Bentley &#8211; @cbentle2 Description: Generic indicator for the DUQU virus. Based on Stuxtnet Reports: http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet Indicators: OR &#160;&#160;&#160;File MD5 is 0a566b1616c8afeef214372b1a0580c7 &#160;&#160;&#160;File MD5 is 0eecd17c6c215b358b7b872b74bfd800 &#160;&#160;&#160;File MD5 is 4541e850a228eb69fd0f0e924624b245 &#160;&#160;&#160;File MD5 is b4ac366e24204d821376653279cbad86 &#160;&#160;&#160;File MD5 is e8d6b4dadb96ddb58775e6c85b10b6cc &#160;&#160;&#160;File MD5 is c9a31ea148232b201fe7cb7db5c75f5e &#160;&#160;&#160;File MD5 is f60968908f03372d586e71d87fe795cd &#160;&#160;&#160;File MD5 is 9749d38ae9b9ddd81b50aad679ee87ec &#160;&#160;&#160;File Name is [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
Christopher Bentley &#8211; @cbentle2</p>
<p><strong>Description: </strong><br />
Generic indicator for the DUQU virus. Based on Stuxtnet</p>
<p><strong>Reports:</strong><br />
<a href="http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet">http://www.symantec.com/connect/w32_duqu_precursor_next_stuxnet</a></p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;File MD5 is 0a566b1616c8afeef214372b1a0580c7<br />
&nbsp;&nbsp;&nbsp;File MD5 is 0eecd17c6c215b358b7b872b74bfd800<br />
&nbsp;&nbsp;&nbsp;File MD5 is 4541e850a228eb69fd0f0e924624b245<br />
&nbsp;&nbsp;&nbsp;File MD5 is b4ac366e24204d821376653279cbad86<br />
&nbsp;&nbsp;&nbsp;File MD5 is e8d6b4dadb96ddb58775e6c85b10b6cc<br />
&nbsp;&nbsp;&nbsp;File MD5 is c9a31ea148232b201fe7cb7db5c75f5e<br />
&nbsp;&nbsp;&nbsp;File MD5 is f60968908f03372d586e71d87fe795cd<br />
&nbsp;&nbsp;&nbsp;File MD5 is 9749d38ae9b9ddd81b50aad679ee87ec<br />
&nbsp;&nbsp;&nbsp;File Name is cmi4432.pnf<br />
&nbsp;&nbsp;&nbsp;File Name is cmi4464.pnf<br />
&nbsp;&nbsp;&nbsp;File Name is netp191.PNF<br />
&nbsp;&nbsp;&nbsp;File Name is jiminet7.sys<br />
&nbsp;&nbsp;&nbsp;File Name is cmi4432.sys<br />
&nbsp;&nbsp;&nbsp;File Name is nfred965.sys<br />
&nbsp;&nbsp;&nbsp;File Name is nred961.sys<br />
&nbsp;&nbsp;&nbsp;File PEInfo ResourceInfoList ResourceInfo Name is 302<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 68.132.129.18<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 206.183.111.97<br />
&nbsp;&nbsp;&nbsp;Process StringList is kasperskychk.dyndns.org<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 77.241.93.160<br />
&nbsp;&nbsp;&nbsp;Service Name is JmiNET3<br />
&nbsp;&nbsp;&nbsp;Service Name is cmi4432<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains adp<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains ~DQ<br />
&nbsp;&nbsp;&nbsp;Process StringList is \DEVICE\Gdp1<br />
&nbsp;&nbsp;&nbsp;Service Path contains C:\Windows\System32\drivers<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Path contains HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet &nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Settings\Zones\4\<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Text contains CF1D<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;EventLog source is DCOM<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;EventLog ID is 32212354481<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;EventLog type is Error<br />
&nbsp;&nbsp;&nbsp;OR<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Hook Hooked Module is ntdll.dll</p>
<p><strong>IOC File:</strong><br />
<a href="http://ioc.forensicartifacts.com/wp-content/uploads/2012/01/5add2090-312b-4628-a4f8-c42d1ca7c2a9.ioc" title="5add2090-312b-4628-a4f8-c42d1ca7c2a9.ioc">5add2090-312b-4628-a4f8-c42d1ca7c2a9.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/01/duqu/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Generic Process Path Indicator</title>
		<link>http://ioc.forensicartifacts.com/2012/01/generic-process-path-indicator/</link>
		<comments>http://ioc.forensicartifacts.com/2012/01/generic-process-path-indicator/#comments</comments>
		<pubDate>Sat, 07 Jan 2012 01:19:16 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[System]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Processes]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=91</guid>
		<description><![CDATA[Authored By: Christopher Bentley &#8211; @cbentle2 Description: Generic Indicator to identify Common commands not run from their default process path locations. cmd.exe, csrss.exe, explorer.exe, lsass.exe,services.exe, spoolsv.exe, smss.exe, svchost.exe, winlogon.exe and ctfmon.exe Indicators: OR &#160;&#160;&#160;AND &#160;&#160;&#160;&#160;&#160;&#160; Process Name is explorer.exe &#160;&#160;&#160;&#160;&#160;&#160; Process path is not C:\WINDOWS\ &#160;&#160;&#160;AND &#160;&#160;&#160;&#160;&#160;&#160; Process Name is cmd.exe &#160;&#160;&#160;&#160;&#160;&#160; Process path is [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
Christopher Bentley &#8211; @cbentle2</p>
<p><strong>Description: </strong><br />
Generic Indicator to identify Common commands not run from their default process path locations.<br />
  cmd.exe, csrss.exe, explorer.exe, lsass.exe,services.exe, spoolsv.exe, smss.exe, svchost.exe, winlogon.exe and ctfmon.exe</p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is explorer.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is cmd.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is lsass.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is services.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is csrss.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is spoolsrv.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is smss.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is svchost.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is winlogon.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process Name is ctfmon.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp; Process path is not C:\WINDOWS\system32</p>
<p><strong>IOC File:</strong><br />
<a href="http://ioc.forensicartifacts.com/wp-content/uploads/2012/01/7fe9ed86-72f5-4444-b99e-72ae535154fa.ioc" title="7fe9ed86-72f5-4444-b99e-72ae535154fa.ioc" target="_blank">7fe9ed86-72f5-4444-b99e-72ae535154fa.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/01/generic-process-path-indicator/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Morto</title>
		<link>http://ioc.forensicartifacts.com/2012/01/morto/</link>
		<comments>http://ioc.forensicartifacts.com/2012/01/morto/#comments</comments>
		<pubDate>Fri, 06 Jan 2012 00:14:47 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Worm]]></category>
		<category><![CDATA[Morto]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=80</guid>
		<description><![CDATA[Authored By: Keith Gilbert &#8211; @digital4rensics Description: Finds common Morto infections and alerts on either the dropper, loader, or payload. Tested with success, no FPs. DNS &#038; Process entries have not been verified. Category: Worm Reports: http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=Worm%3AWin32%2FMorto.A Indicators: OR &#160;&#160;&#160;DnsEntryItem/RecordName contains qfsl.net &#160;&#160;&#160;DnsEntryItem/RecordName contains ms.jifr &#160;&#160;&#160;File Full Path contains Windows\Offline Web Pages\1.40_TestDdos &#160;&#160;&#160;File Full Path [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
Keith Gilbert &#8211; @digital4rensics</p>
<p><strong>Description: </strong><br />
Finds common Morto infections and alerts on either the dropper, loader, or payload. Tested with success, no FPs. DNS &#038; Process entries have not been verified.</p>
<p><strong>Category: </strong><br />
Worm</p>
<p><strong>Reports:</strong><br />
<a href="http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=Worm%3AWin32%2FMorto.A">http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?name=Worm%3AWin32%2FMorto.A</a></p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;DnsEntryItem/RecordName contains qfsl.net<br />
&nbsp;&nbsp;&nbsp;DnsEntryItem/RecordName contains ms.jifr<br />
&nbsp;&nbsp;&nbsp;File Full Path contains Windows\Offline Web Pages\1.40_TestDdos<br />
&nbsp;&nbsp;&nbsp;File Full Path contains Windows\Offline Web Pages\cache.txt<br />
&nbsp;&nbsp;&nbsp;File Full Path contains Windows\clb.dll<br />
&nbsp;&nbsp;&nbsp;File Full Path contains Windows\clb.dll.bak<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Path contains SYSTEM\WPA<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;OR<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry ValueName is ie<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry ValueName is md<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry ValueName is sr<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Value is Sens<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Value is 6to4<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry ValueName is sn<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Path contains SYSTEM\ControlSet001\Control\Windows<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry ValueName is NoPopUpsOnBoot<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Text is 00000001<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Path contains Software\Microsoft\WindowsNT\CurrentVersion\AppCompatFlags\Layers<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Registry Value contains rundll32.exe=RUNASADMIN<br />
&nbsp;&nbsp;&nbsp;AND<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Name is svchost.exe<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process StringList contains letmein<br />
&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;Process Handle Name contains System32\Sens32.dll</p>
<p><strong>IOC File:</strong><br />
<a href="http://ioc.forensicartifacts.com/wp-content/uploads/2012/01/326c3286-1a3c-403f-8e78-61f3ce1f3ab1.ioc" title="326c3286-1a3c-403f-8e78-61f3ce1f3ab1.ioc" target="_blank">326c3286-1a3c-403f-8e78-61f3ce1f3ab1.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/01/morto/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Ponmocup</title>
		<link>http://ioc.forensicartifacts.com/2012/01/ponmocup/</link>
		<comments>http://ioc.forensicartifacts.com/2012/01/ponmocup/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 23:58:30 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Ponmocup]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=75</guid>
		<description><![CDATA[Authored By: Christopher Bentley Description: IOC for Ponmocup\Vundo Reports: http://www9.dyndns-server.com:8080/pub/botnet-links.html Indicators: OR &#160;&#160;&#160;File MD5 is 820ed1d99e2b771d915e033450fa0b0f &#160;&#160;&#160;File MD5 is bd291073fc2cb39456886d091a5ee85c &#160;&#160;&#160;File MD5 is 593af63840f11883610ba95d6744c4b1 &#160;&#160;&#160;Network DNS contains checkwebspeed.net &#160;&#160;&#160;Process Handle Name is WBEMPROVIDERSTATICMUTEX &#160;&#160;&#160;Registry Path is HKEY_LOCAL_MACHINE\SOFTWARE\qrjaslop &#160;&#160;&#160;Registry Path is HKEY_CURRENT_USER\Software\zpppmcegc &#160;&#160;&#160;Port Remote IP is 96.126.106.156 &#160;&#160;&#160;Process Stringlist contains http://imagehut4.cn/update/utu.da &#160;&#160;&#160;Process Handle Name contains \temp\scse.tmp [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
Christopher Bentley</p>
<p><strong>Description: </strong><br />
IOC for Ponmocup\Vundo</p>
<p><strong>Reports:</strong><br />
<a href="http://www9.dyndns-server.com:8080/pub/botnet-links.html">http://www9.dyndns-server.com:8080/pub/botnet-links.html</a></p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;File MD5 is 820ed1d99e2b771d915e033450fa0b0f<br />
&nbsp;&nbsp;&nbsp;File MD5 is bd291073fc2cb39456886d091a5ee85c<br />
&nbsp;&nbsp;&nbsp;File MD5 is 593af63840f11883610ba95d6744c4b1<br />
&nbsp;&nbsp;&nbsp;Network DNS contains checkwebspeed.net<br />
&nbsp;&nbsp;&nbsp;Process Handle Name is WBEMPROVIDERSTATICMUTEX<br />
&nbsp;&nbsp;&nbsp;Registry Path is HKEY_LOCAL_MACHINE\SOFTWARE\qrjaslop<br />
&nbsp;&nbsp;&nbsp;Registry Path is HKEY_CURRENT_USER\Software\zpppmcegc<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 96.126.106.156<br />
&nbsp;&nbsp;&nbsp;Process Stringlist contains http://imagehut4.cn/update/utu.da<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains \temp\scse.tmp<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains \temp\scsf.tmp<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 184.105.178.92<br />
&nbsp;&nbsp;&nbsp;Registry Path contains HKEY_LOCAL_MACHINE\Software\Nojrkfkyp<br />
&nbsp;&nbsp;&nbsp;Process Handle Name Contains C:\WINDOWS\system32\drivers\etc\hosts<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 94.75.201.35<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 85.17.139.239<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 85.17.139.238<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 85.17.188.195<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 94.75.201.36<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 94.75.234.98<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 94.75.234.107<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 174.36.82.151<br />
&nbsp;&nbsp;&nbsp;Port Remote IP contains 78.159.100.32<br />
&nbsp;&nbsp;&nbsp;Registry Path contains HKEY_CURRENT_USER\Software\GHUZPSK<br />
&nbsp;&nbsp;&nbsp;Process StringList contains html/license_43EC922A3D0E1F403834ED406BA80D5A686E</p>
<p><strong>Download:</strong><br />
<a href="http://ioc.forensicartifacts.com/wp-content/uploads/2012/01/c6245aef-5583-449e-92df-87f6b253de2c.ioc" title="c6245aef-5583-449e-92df-87f6b253de2c.ioc">c6245aef-5583-449e-92df-87f6b253de2c.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/01/ponmocup/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Shylock</title>
		<link>http://ioc.forensicartifacts.com/2012/01/shylock/</link>
		<comments>http://ioc.forensicartifacts.com/2012/01/shylock/#comments</comments>
		<pubDate>Thu, 05 Jan 2012 23:47:13 +0000</pubDate>
		<dc:creator>Keith</dc:creator>
				<category><![CDATA[IOC]]></category>
		<category><![CDATA[Malware]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[Shylock]]></category>

		<guid isPermaLink="false">http://ioc.forensicartifacts.com/?p=69</guid>
		<description><![CDATA[Authored By: Christopher Bentley Updated On: Feb. 6 2012 Description: Banking Trojan discovered by Trusteer Shylock intercepts network traffic and attempts to add malicious code to it. Category: Trojan Reports: http://quequero.org/uicwiki/index.php?title=Shylock_via_%20volatility Indicators: OR &#160;&#160;&#160;Process StringList contains _SHUTDOWN &#160;&#160;&#160;Process StringList contains MASTER_ &#160;&#160;&#160;Process StringList contains EVT_VNC &#160;&#160;&#160;Process StringList contains EVT_BACK &#160;&#160;&#160;Process StringList is extensadv.cc &#160;&#160;&#160;Process StringList [...]]]></description>
			<content:encoded><![CDATA[<p><strong>Authored By: </strong><br />
Christopher Bentley</p>
<p><strong>Updated On: Feb. 6 2012 </strong></p>
<p><strong>Description: </strong><br />
Banking Trojan discovered by Trusteer Shylock intercepts network traffic and attempts to add malicious code to it. </p>
<p><strong>Category: </strong><br />
Trojan</p>
<p><strong>Reports:</strong><br />
<a href="http://quequero.org/uicwiki/index.php?title=Shylock_via_%20volatility">http://quequero.org/uicwiki/index.php?title=Shylock_via_%20volatility</a></p>
<p><strong>Indicators:</strong><br />
OR<br />
&nbsp;&nbsp;&nbsp;Process StringList contains _SHUTDOWN<br />
&nbsp;&nbsp;&nbsp;Process StringList contains MASTER_<br />
&nbsp;&nbsp;&nbsp;Process StringList contains EVT_VNC<br />
&nbsp;&nbsp;&nbsp;Process StringList contains EVT_BACK<br />
&nbsp;&nbsp;&nbsp;Process StringList is extensadv.cc<br />
&nbsp;&nbsp;&nbsp;Process StringList is topbeat.cc<br />
&nbsp;&nbsp;&nbsp;Process StringList is brainsphere.cc<br />
&nbsp;&nbsp;&nbsp;Process StringList is commonworldme.cc<br />
&nbsp;&nbsp;&nbsp;Process StringList is gigacat.cc<br />
&nbsp;&nbsp;&nbsp;Process StringList is nw-serv.cc<br />
&nbsp;&nbsp;&nbsp;Process StringList contains IE_Hook::GetRequestInfo<br />
&nbsp;&nbsp;&nbsp;Process StringList contains FF_Hook::getRequestInfo<br />
&nbsp;&nbsp;&nbsp;Process StringList contains EX_Hook::CreateProcess<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 178.208.75.226<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 81.177.170.135<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 88.198.50.150<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 65.55.87.173<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 91.223.180.66<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 92.60.177.233<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 92.60.177.234<br />
&nbsp;&nbsp;&nbsp;Port Remote IP is 93.190.45.75<br />
&nbsp;&nbsp;&nbsp;Process StringList contains hijackdll.dll<br />
&nbsp;&nbsp;&nbsp;Process Handle Name contains MTX_<br />
&nbsp;&nbsp;&nbsp;Process StringList is FF::PR_WriteHook entry<br />
&nbsp;&nbsp;&nbsp;Process StringList is FF::PR_WriteHook exit<br />
&nbsp;&nbsp;&nbsp;Process StringList is HijackProcessAttach::*** MASTER *** MASTER *** MASTER *** %s PID=%u<br />
&nbsp;&nbsp;&nbsp;HijackProcessAttach::entry<br />
&nbsp;&nbsp;&nbsp;Process StringList is FF::BEFORE INJECT<br />
&nbsp;&nbsp;&nbsp;Process StringList is FF::AFTER INJECT<br />
&nbsp;&nbsp;&nbsp;Process StringList is IE::BEFORE INJECT<br />
&nbsp;&nbsp;&nbsp;Process StringList is IE::AFTER INJECT<br />
&nbsp;&nbsp;&nbsp;Process StringList is *** VNC *** VNC *** VNC *** VNC *** VNC *** VNC *** VNC *** VNC *** VNC *** VNC &nbsp;&nbsp;&nbsp;*** %s<br />
&nbsp;&nbsp;&nbsp;Process StringList is *** LOG INJECTS *** %s<br />
&nbsp;&nbsp;&nbsp;Process StringList is *** inject to process %s not allowed<br />
&nbsp;&nbsp;&nbsp;Process StringList is *** BackSocks *** BackSocks *** BackSocks *** BackSocks *** BackSocks *** &nbsp;&nbsp;&nbsp;BackSocks *** BackSocks *** %s<br />
&nbsp;&nbsp;&nbsp;Process StringList is .?AVFF_Hook@@<br />
&nbsp;&nbsp;&nbsp;Process StringList is .?AVIE_Hook@@<br />
&nbsp;&nbsp;&nbsp;Process StringList contains Inject::InjectDllFromMemory<br />
&nbsp;&nbsp;&nbsp;Process StringList contains paragua-analyst.cc<br />
&nbsp;&nbsp;&nbsp;Process StringList contains BadSocks.dll</p>
<p><strong>IOC File:</strong><br />
<a href="http://ioc.forensicartifacts.com/wp-content/uploads/2012/01/1623644e-7016-46ff-b302-07b7a75bfbe81.ioc" title="1623644e-7016-46ff-b302-07b7a75bfbe8.ioc" target="_blank">1623644e-7016-46ff-b302-07b7a75bfbe8.ioc</a></p>
]]></content:encoded>
			<wfw:commentRss>http://ioc.forensicartifacts.com/2012/01/shylock/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

<!-- Dynamic page generated in 0.303 seconds. -->
<!-- Cached page generated by WP-Super-Cache on 2012-05-11 06:34:13 -->

