<?xml version="1.0" encoding="UTF-8"?>
<response><Event><id>743</id><org>CIRCL</org><date>2014-04-23</date><threat_level_id>2</threat_level_id><info>OSINT - NetWiredRC - A feature-rich Remote Access Tool.</info><published>0</published><uuid>5357b40a-cf1c-49b7-bacc-4b1a950d2109</uuid><attribute_count>21</attribute_count><analysis>2</analysis><timestamp>1398260448</timestamp><distribution>3</distribution><proposal_email_lock>1</proposal_email_lock><orgc>CIRCL</orgc><locked>0</locked><publish_timestamp>0</publish_timestamp><Attribute><id>42124</id><type>filename</type><category>Artifacts dropped</category><to_ids>1</to_ids><uuid>5357b7a4-8610-4256-9ab4-a037950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257572</timestamp><comment>logfile per day, format DD-MM-YYYY (without extension)</comment><value>%AppData%\Microsoft\Crypto\Logs\</value><ShadowAttribute/></Attribute><Attribute><id>42125</id><type>filename</type><category>Artifacts dropped</category><to_ids>1</to_ids><uuid>5357b7a4-7e18-49cb-baad-a037950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257593</timestamp><comment/><value>%AppData%\Microsoft\Crypto\Office.exe</value><ShadowAttribute/></Attribute><Attribute><id>42126</id><type>filename</type><category>Artifacts dropped</category><to_ids>1</to_ids><uuid>5357b7a4-3c9c-4906-8b34-a037950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257607</timestamp><comment/><value>%AppData%\Microsoft\Crypto\Office.exe.Identifier</value><ShadowAttribute/></Attribute><Attribute><id>42123</id><type>mutex</type><category>Artifacts dropped</category><to_ids>1</to_ids><uuid>5357b763-27d4-4f0c-8ffa-a538950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257507</timestamp><comment/><value>mJhcimNA</value><ShadowAttribute/></Attribute><Attribute><id>42121</id><type>regkey|value</type><category>Artifacts dropped</category><to_ids>1</to_ids><uuid>5357b748-db74-4f8d-93b2-bf58950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257480</timestamp><comment/><value>HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |Office</value><ShadowAttribute/></Attribute><Attribute><id>42122</id><type>regkey|value</type><category>Artifacts dropped</category><to_ids>1</to_ids><uuid>5357b748-b764-4b5d-8ff6-bf58950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257480</timestamp><comment/><value>HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components|-</value><ShadowAttribute/></Attribute><Attribute><id>42131</id><type>link</type><category>External analysis</category><to_ids>0</to_ids><uuid>5357b956-0f80-40d4-ac53-5840950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398258006</timestamp><comment>CIRCL TR-23 Analysis - NetWiredRC malware</comment><value>https://www.circl.lu/pub/tr-23/</value><ShadowAttribute><id>231</id><type>comment</type><category>External analysis</category><to_ids>1</to_ids><uuid>5357b956-0f80-40d4-ac53-5840950d2109</uuid><event_id>743</event_id><old_id>42131</old_id><comment>CIRCL TR-23 Analysis - NetWiredRC malware</comment><org>CERT.at</org><value>https://www.circl.lu/pub/tr-23/&#13;
&#13;
not working</value></ShadowAttribute></Attribute><Attribute><id>42134</id><type>link</type><category>External analysis</category><to_ids>0</to_ids><uuid>5357ba41-a670-4d50-8403-be22950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398258254</timestamp><comment/><value>http://www.microsoft.com/security/portal/threat/encyclopedia/entry.aspx?Name=Backdoor:Win32/NetWiredRC.B#tab=2</value><ShadowAttribute/></Attribute><Attribute><id>42120</id><type>ip-dst</type><category>Network activity</category><to_ids>1</to_ids><uuid>5357b4f7-8804-4974-92e7-5840950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398256887</timestamp><comment>Sample B</comment><value>37.252.120.122</value><ShadowAttribute/></Attribute><Attribute><id>42148</id><type>snort</type><category>Network activity</category><to_ids>1</to_ids><uuid>5357c2e0-d484-4b2e-9922-ce64950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398260448</timestamp><comment/><value>alert tcp $HOME_NET any -&gt; $EXTERNAL_NET any ( \&#13;
    msg:"NetWiredRC registration"; \&#13;
    pkt_data; content:"|41 00 00 00 03|"; \&#13;
    offset:0; \&#13;
    depth:10; \&#13;
    reference:url,https://www.circl.lu/pub/tr-23/; \&#13;
    sid:70123;\&#13;
    rev:1;)</value><ShadowAttribute/></Attribute><Attribute><id>42147</id><type>snort</type><category>Network activity</category><to_ids>1</to_ids><uuid>5357c2ca-5d28-49cf-89ad-aca9950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398260426</timestamp><comment/><value>alert tcp $HOME_NET any -&gt; $EXTERNAL_NET any ( \&#13;
    msg:"NetWiredRC heartbeat"; \&#13;
    pkt_data; \&#13;
    content:"|01 00 00 00 02|"; \&#13;
    offset:0; \&#13;
    depth:10; \&#13;
    reference:url,https://www.circl.lu/pub/tr-23/; \&#13;
    sid:70023;\ &#13;
    rev:1;)</value><ShadowAttribute/></Attribute><Attribute><id>42114</id><type>md5</type><category>Payload delivery</category><to_ids>1</to_ids><uuid>5357b442-5fe0-46e9-beed-bf58950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398256706</timestamp><comment>Sample A</comment><value>37e922093d8a837b250e72cc87a664cd</value><ShadowAttribute/></Attribute><Attribute><id>42127</id><type>md5</type><category>Payload delivery</category><to_ids>1</to_ids><uuid>5357b832-2c04-474a-8791-a036950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257829</timestamp><comment>Similarity by network connection (same IP:PORT), strings, attribution: NetWiredRC</comment><value>4af801e0de96814e9095bf78be790003</value><ShadowAttribute/></Attribute><Attribute><id>42128</id><type>md5</type><category>Payload delivery</category><to_ids>1</to_ids><uuid>5357b832-4a8c-4a76-a0b1-a036950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257839</timestamp><comment>Similarity by network connection (same IP:PORT), strings, attribution: NetWiredRC</comment><value>1d2f110f37c43a05407e8295d75a1974</value><ShadowAttribute/></Attribute><Attribute><id>42129</id><type>md5</type><category>Payload delivery</category><to_ids>1</to_ids><uuid>5357b8f8-874c-426d-81ac-be18950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257912</timestamp><comment>Quick analysis: previous version of this malware  - missing features: SOCKS, audio recording, find file by MD5</comment><value>1e279c58a4156ef2ae1ff55a4bc3aaf6</value><ShadowAttribute/></Attribute><Attribute><id>42115</id><type>sha1</type><category>Payload delivery</category><to_ids>1</to_ids><uuid>5357b45b-2684-4508-a65d-be18950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398256731</timestamp><comment>Sample A</comment><value>c4d06a2fc80bffbc6a64f92f95ffee02f92c6bb9</value><ShadowAttribute/></Attribute><Attribute><id>42130</id><type>sha1</type><category>Payload delivery</category><to_ids>1</to_ids><uuid>5357b91d-10fc-4fdd-a6fd-ce64950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398257949</timestamp><comment>Quick analysis: previous version of this malware - missing features: SOCKS, audio recording, find file by MD5</comment><value>40e8e3b5fce0cd551106ccb86fc83a0ca03c9349</value><ShadowAttribute/></Attribute><Attribute><id>42116</id><type>sha256</type><category>Payload delivery</category><to_ids>1</to_ids><uuid>5357b46c-b9a0-446c-bb3d-b035950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398256748</timestamp><comment>Sample A</comment><value>3946d499d81e8506b8291dc0bd13475397bbcd7cb6e2c7ea504c079c92b99f62</value><ShadowAttribute/></Attribute><Attribute><id>42117</id><type>md5</type><category>Payload installation</category><to_ids>1</to_ids><uuid>5357b483-3278-47d5-b413-5845950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398256771</timestamp><comment>Sample B</comment><value>759545ab2edad3149174e263d6c81dce</value><ShadowAttribute/></Attribute><Attribute><id>42118</id><type>sha1</type><category>Payload installation</category><to_ids>1</to_ids><uuid>5357b491-f69c-47be-830f-588f950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398256785</timestamp><comment>Sample B</comment><value>2182ff6537f38a4e8c273316484c2c84872633d0</value><ShadowAttribute/></Attribute><Attribute><id>42119</id><type>sha256</type><category>Payload installation</category><to_ids>1</to_ids><uuid>5357b49d-7ee0-4f05-a7d5-ce64950d2109</uuid><event_id>743</event_id><distribution>3</distribution><timestamp>1398256797</timestamp><comment>Sample B</comment><value>34d88b04956cbed54190823c94753b0dc6d8c19339d22153127293433b398cf1</value><ShadowAttribute/></Attribute><ShadowAttribute/><RelatedEvent><Event><id>718</id><org>CIRCL</org><date>2014-04-04</date><risk>Undefined</risk><info>CIRCL UNKCAMP (Not actionable -&gt; no takedown request or no active probing)</info><user_id>3</user_id><published>1</published><uuid>5342b584-4c9c-406b-94da-4b54950d2109</uuid><attribute_count>3</attribute_count><analysis>1</analysis><orgc>CIRCL</orgc><timestamp>1396965601</timestamp><distribution>2</distribution><proposal_email_lock>0</proposal_email_lock><locked>0</locked><threat_level_id>2</threat_level_id><publish_timestamp>1397072061</publish_timestamp></Event></RelatedEvent></Event><xml_version>2.2.0</xml_version></response>
