Logo
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Resources
Documentation Portal Ideas Portal Guardsix Academy License Portal
Sign in
  1. Guardsix Servicedesk
  2. Products Hub
  3. Marketplace

Hidden Cobra

Archived

Hidden Cobra is an APT hacking group mostly targeting media organizations, aerospace, financial and critical infrastructure across the globe. The malware, Hidden Cobra uses, are Remote Access Trojan (RAT) called Joanap and Server Message Block (SMB) worm called Brambul. With this integration, Logpoint can fully extract and correlate the Hidden Cobra events and at the same time combine the results with observations from other systems. The key analytical components of the integration enable users to normalize data from the specified source and view statistics for Hidden Cobra.

Release Details

Version: 3.0.0
Release date: June 05, 2018
Supported On: Logpoint v5.0.0 and later
SHA 256: eb10315ba6844aaa59783026532be00448f0bf9bf6a2ae776aea73fd4ba98dfe
Download

Package Details

  1. Dashboard Package
    • LP_Hidden Cobra
  2. Alert Packages
    • LP_Hidden Cobra Emails Sent to Attacker
    • LP_Hidden Cobra Vulnerable Sources
    • LP_Hidden Cobra Connection to Malicious Destination
    • LP_Incapsula Countries in Excessive Blocked List
    • LP_Hidden Cobra Affected Host
  3. KB List
    • HIDDEN_COBRA_HASH
    • HIDDEN_COBRA_EMAIL
    • HIDDEN_COBRA_CVE
    • HIDDEN_COBRA_FILE
    • HIDDEN_COBRA_IP

Installation

To install Hidden Cobra:

  1. Download the .pak file from the Download link above.
  2. Add the required Hidden Cobra as a device in Logpoint.
  3. Create a collection policy with Syslog, the normalization, and a relevant repository.
  4. Assign the policy to the device.
  5. Add the dashboard.

Screenshots

Screen_Shot_2018-06-05_at_9.20.16_AM.pngScreen_Shot_2018-06-04_at_4.31.13_PM.pngScreen_Shot_2018-06-04_at_4.36.53_PM.png

Log Source Requirements

  • Windows Server/Integrity Scanner
    • To detect malicious file installation and malware-infected hosts.
  • Mail Server
    • To detect any emails sent to the malicious address.
  • Firewall
    • To detect the connection to and from the malicious listed sources.
  • Vulnerability Management
    • To detect hosts vulnerable to malware.

Support

If you have any questions or require assistance, create a support ticket..

Comments

Article is closed for comments.

Follow

Related articles

  • Hitachi NAS
  • Intermapper
  • Support Overview
  • Hex2Ascii Process Plugin
  • Integrity Scanner
Consent Required To Proceed
By clicking “I Agree & Download”, you confirm that you are authorized to act on behalf of your organization and you give explicit consent for Guardsix to share your organization’s customer name and log source count with NXLog for the sole purposes of entitlement management, compliance verification, and support delivery related to the embedded NXLog technology in the Guardsix SIEM solution.

This data will not be used for sales or marketing and will not be shared with other third parties. You may withdraw your consent at any time by contacting Guardsix Support; withdrawal will not affect processing already performed.
Cancel I Agree & Download
Privacy policy    EULA    Terms of service   
Copyright © , Guardsix. All rights reserved.

Note: We use cookies that are essential for the smooth functioning of our website.