WhisperGate and HermeticWiper & CVE-2021-32648

- On January 14th, 2022, reports began on a malware operation dubbed "WhisperGate" targeting multiple -organizations in Ukraine. - On February 23, 2022, a new wiper malware known as "HermeticWiper" was disclosed by several cybersecurity researchers. The new wiper "HermeticWiper" was also being used against organizations in Ukraine. CVE-2021-32648 vulnerability has a CVSS score of 9.1 and was found in octobercms, which is a CMS platform based on the Laravel PHP Framework. In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request. The issue has been patched in Build 472 and v1.1.5. **The playbook includes the following tasks:** - Collect related known indicators from Unit 42, CISA and Malware News blog. - Search for possible vulnerable servers using Xpanse. - Indicators and exploitation patterns hunting using PAN-OS, Cortex XDR and SIEM products. - Block indicators automatically or manually. **Mitigations:** * October CMS security recommendations * Deploy YARA detection Rules. More information: [UNIT42 Blog - Ongoing Russia and Ukraine Cyber Conflict](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/) [Russia-Ukraine Cyberattacks: How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon and Website Defacement](https://unit42.paloaltonetworks.com/preparing-for-cyber-impact-russia-ukraine-crisis/) [Microsoft Blog](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/) [CVE-2021-32648 NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-32648#vulnCurrentDescriptionTitle) Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

WhisperGate and HermeticWiper & CVE-2021-32648 · 50 tasks · 7 inputs · 0 outputs

Details

IDWhisperGate and HermeticWiper & CVE-2021-32648
From Version6.5.0
Tasks50

README

  • On January 14th, 2022, reports began on a malware operation dubbed “WhisperGate” targeting multiple -organizations in Ukraine.

  • On February 23, 2022, a new wiper malware known as “HermeticWiper” was disclosed by several cybersecurity researchers. The new wiper “HermeticWiper” was also being used against organizations in Ukraine.

CVE-2021-32648 vulnerability has a CVSS score of 9.1 and was found in octobercms, which is a CMS platform based on the Laravel PHP Framework.
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
The issue has been patched in Build 472 and v1.1.5.

The playbook includes the following tasks:

  • Collect related known indicators from Unit 42, CISA and Malware News blog.
  • Search for possible vulnerable servers using Xpanse.
  • Indicators and exploitation patterns hunting using PAN-OS, Cortex XDR and SIEM products.
  • Block indicators automatically or manually.

Mitigations:

  • October CMS security recommendations
  • Deploy YARA detection Rules.

More information:
UNIT42 Blog - Ongoing Russia and Ukraine Cyber Conflict
Russia-Ukraine Cyberattacks: How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon and Website Defacement
Microsoft Blog
CVE-2021-32648 NVD

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.

Dependencies

This playbook uses the following sub-playbooks, integrations, and scripts.

Sub-playbooks

  • Rapid Breach Response - Set Incident Info
  • Block Indicators - Generic v3
  • Panorama query threat logs
  • Threat Hunting - Generic

Integrations

This playbook does not use any integrations.

Scripts

  • IsIntegrationAvailable
  • ParseHTMLIndicators
  • http

Commands

  • expanse-get-issues
  • xdr-xql-generic-query
  • closeInvestigation
  • extractIndicators
  • createNewIndicator

Playbook Inputs


Name Description Default Value Required
PlaybookDescription The playbook description for Rapid Breach Response layout. - On January 14th, 2022, reports began on a malware operation dubbed “WhisperGate” targeting multiple -organizations in Ukraine.

- On February 23, 2022, a new wiper malware known as “HermeticWiper” was disclosed by several cybersecurity researchers. The new wiper “HermeticWiper” was also being used against organizations in Ukraine.

CVE-2021-32648 vulnerability has a CVSS score of 9.1 and was found in octobercms, which is a CMS platform based on the Laravel PHP Framework.
In affected versions of the october/system package an attacker can request an account password reset and then gain access to the account using a specially crafted request.
The issue has been patched in Build 472 and v1.1.5.

The playbook includes the following tasks:
- Collect related known indicators from Unit 42, CISA and Malware News blog.
- Search for possible vulnerable servers using Xpanse.
- Indicators and exploitation patterns hunting using PAN-OS, Cortex XDR and SIEM products.
- Block indicators automatically or manually.

Mitigations:
* October CMS security recommendations
* Deploy YARA detection Rules.

More information:
UNIT42 Blog - Ongoing Russia and Ukraine Cyber Conflict
Russia-Ukraine Cyberattacks: How to Protect Against Related Cyberthreats Including DDoS, HermeticWiper, Gamaredon and Website Defacement
Microsoft Blog
CVE-2021-32648 NVD

Note: This is a beta playbook, which lets you implement and test pre-release software. Since the playbook is beta, it might contain bugs. Updates to the pack during the beta phase might include non-backward compatible features. We appreciate your feedback on the quality and usability of the pack to help us identify issues, fix them, and continually improve.
Optional
BlockIndicatorsAutomatically Whether to block the indicators automatically or not. False Optional
CollectedIndicatorsSeverity The verdict of the collected indicators. Default is “Malicious”.
Other options can be “Suspicious” and “Unknown”.
Malicious Optional
RelatedCVE The WhisperGate malware related CVE. CVE-2021-32648 Optional
RunXQLHuntingQueries Whether to perform XQL hunting queries. Default is “False”. False Optional
UserVerification Possible values: True/False.\nWhether to provide user verification for blocking IPs. \n\nFalse - No prompt will be displayed to the user.\nTrue - The server will ask the user for blocking verification and will display the blocking list False Optional
AutoBlockIndicators Should the given indicators be automatically blocked, or should the user be given the option to choose?
If set to True - no prompt will appear, and all provided indicators will be blocked automatically.
If set to False - the user will be prompted to select which indicators to block.
True Optional

Playbook Outputs


There are no outputs for this playbook.

Playbook Image


WhisperGate and HermeticWiper & CVE-2021-32648

Inputs

  • PlaybookDescription — The playbook description for Rapid Breach Response layout.
  • BlockIndicatorsAutomatically — Whether to block the indicators automatically or not.
  • CollectedIndicatorsSeverity — The verdict of the collected indicators. Default is "Malicious". Other options can be "Suspicious" and "Unknown".
  • RelatedCVE — The WhisperGate malware related CVE.
  • RunXQLHuntingQueries — Whether to perform XQL hunting queries. Default is "False".
  • UserVerification — Possible values: True/False.\nWhether to provide user verification for blocking IPs. \n\nFalse - No prompt will be displayed to the user.\nTrue - The server will ask the user for blocking verification and will display the blocking list
  • AutoBlockIndicators — Should the given indicators be automatically blocked, or should the user be given the option to choose? If set to True - no prompt will appear, and all provided indicators will be blocked automatically. If set to False - the user will be prompted to select which indicators to block.

Commands used

closeInvestigation createNewIndicator expanse-get-issues extractIndicators xdr-xql-generic-query

Flowchart

yes No Yes yes yes yes yes Start Start Collect Indicators Collect Indicators Collect indicators from Malware News - ParseHTMLIndicators Collect indicators from M... ParseHTMLIndicators Extract Indicators Extract Indicators Extract Indicators From Data Collected - extractIndicators Extract Indicators From D... extractIndicators Tag and Link Indicators Tag and Link Indicators Threat Hunting Threat Hunting Rapid Breach Response - Set Incident Info - Rapid Breach Response - Set Incident Info Rapid Breach Response - S... Rapid Breach Response - Set I... Handle Rapid Breach Response Layout Handle Rapid Breach Respo... Remediation Remediation Block indicators automatically? Block indicators automati... Block indicators manually Block indicators manually Mitigation Mitigation October CMS security recommendations October CMS security reco... Analysis resolution - Should continue with the investigation? Analysis resolution - Sho... Done Done Investigate Further Investigate Further Close Investigation - closeInvestigation Close Investigation closeInvestigation Resolution Resolution Patch Vulnerability and workarounds Patch Vulnerability and w... Deploy Detection Rules Deploy Detection Rules Tag File indicators - createNewIndicator Tag File indicators createNewIndicator Tag CVE indicators - createNewIndicator Tag CVE indicators createNewIndicator Download Yara Rules - http Download Yara Rules http Yara Rules Yara Rules Collect Detection Rules Collect Detection Rules Threat ID Hunting Threat ID Hunting Indicators Hunting Indicators Hunting Threat Hunting - Generic - Threat Hunting - Generic Threat Hunting - Generic Threat Hunting - Generic Panorama query threat logs - Panorama Query Logs Panorama query threat logs Panorama Query Logs Tag URL indicators - createNewIndicator Tag URL indicators createNewIndicator Cortex XDR - XQL Hunting Queries Cortex XDR - XQL Hunting ... Should run XQL hunting queries? Should run XQL hunting qu... Search for WhisperGate use of InstallUtil (Wiper) - xdr-xql-generic-query Search for WhisperGate us... xdr-xql-generic-query Search for WhisperGate powershell sleep command - xdr-xql-generic-query Search for WhisperGate po... xdr-xql-generic-query Search for WhisperGate disable windows defender - xdr-xql-generic-query Search for WhisperGate di... xdr-xql-generic-query Check if Cortex XDR - XQL Query Engine is Enabled - IsIntegrationAvailable Check if Cortex XDR - XQL... IsIntegrationAvailable Hunting for WhisperGate in Your Network Hunting for WhisperGate i... Search for WhisperGate self-delete - xdr-xql-generic-query Search for WhisperGate se... xdr-xql-generic-query Xpanse Xpanse Is Xpanse enabled? Is Xpanse enabled? Search for possible vulnerable servers using Xpanse - expanse-get-issues Search for possible vulne... expanse-get-issues Review possible vulnerable servers Review possible vulnerabl... Found servers using Xpanse? Found servers using Xpanse? Collect HermeticWiper indicators from Unit 42 - ParseHTMLIndicators Collect HermeticWiper ind... ParseHTMLIndicators Collect indicators from CISA - ParseHTMLIndicators Collect indicators from CISA ParseHTMLIndicators Best practices by CISA Best practices by CISA Review and deploy CISA mitigation suggestions Review and deploy CISA mi... Collect Whispergate indicators from Unit 42 - ParseHTMLIndicators Collect Whispergate indic... ParseHTMLIndicators Block Indicators - Generic v3 - Block Indicators - Generic v3 Block Indicators - Generi... Block Indicators - Generic v3
id: WhisperGate and HermeticWiper & CVE-2021-32648
version: -1
name: WhisperGate and HermeticWiper & CVE-2021-32648
description: "- On January 14th, 2022, reports began on a malware operation dubbed\
  \ \"WhisperGate\" targeting multiple -organizations in Ukraine.\n\n- On February\
  \ 23, 2022, a new wiper malware known as \"HermeticWiper\" was disclosed by several\
  \ cybersecurity researchers. The new wiper \"HermeticWiper\" was also being used\
  \ against organizations in Ukraine.\n\nCVE-2021-32648 vulnerability has a CVSS score\
  \ of 9.1 and was found in octobercms, which is a CMS platform based on the Laravel\
  \ PHP Framework. \nIn affected versions of the october/system package an attacker\
  \ can request an account password reset and then gain access to the account using\
  \ a specially crafted request. \nThe issue has been patched in Build 472 and v1.1.5.\n\
  \n**The playbook includes the following tasks:**\n- Collect related known indicators\
  \ from Unit 42, CISA and Malware News blog.\n-  Search for possible vulnerable servers\
  \ using Xpanse.\n- Indicators and exploitation patterns hunting using PAN-OS, Cortex\
  \ XDR and SIEM products.\n- Block indicators automatically or manually.\n\n**Mitigations:**\n\
  * October CMS security recommendations\n* Deploy YARA detection Rules.\n\nMore information:\n\
  [UNIT42 Blog - Ongoing Russia and Ukraine Cyber Conflict](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/)\n\
  [Russia-Ukraine Cyberattacks: How to Protect Against Related Cyberthreats Including\
  \ DDoS, HermeticWiper, Gamaredon and Website Defacement](https://unit42.paloaltonetworks.com/preparing-for-cyber-impact-russia-ukraine-crisis/)\n\
  [Microsoft Blog](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/)\n\
  [CVE-2021-32648 NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-32648#vulnCurrentDescriptionTitle)\n\
  \nNote: This is a beta playbook, which lets you implement and test pre-release software.\
  \ Since the playbook is beta, it might contain bugs. Updates to the pack during\
  \ the beta phase might include non-backward compatible features. We appreciate your\
  \ feedback on the quality and usability of the pack to help us identify issues,\
  \ fix them, and continually improve."
starttaskid: "0"
tasks:
  "0":
    id: "0"
    taskid: a1ca955f-64f6-44f0-8fe7-2437dd02e740
    type: start
    task:
      id: a1ca955f-64f6-44f0-8fe7-2437dd02e740
      version: -1
      name: ""
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "66"
      - "1"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": -1570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "1":
    id: "1"
    taskid: 7d005429-4b8f-460f-8dcf-f36db1b57273
    type: title
    task:
      id: 7d005429-4b8f-460f-8dcf-f36db1b57273
      version: -1
      name: Collect Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "2"
      - "121"
      - "122"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1490,
          "y": -1420
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "2":
    id: "2"
    taskid: a4f738a2-c9ed-44ab-8fec-71ca22ac196a
    type: regular
    task:
      id: a4f738a2-c9ed-44ab-8fec-71ca22ac196a
      version: -1
      name: Collect indicators from Malware News
      description: This script will extract indicators from HTML and will handle bad
        TLD to avoid file extensions false positives.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      exclude_indicators:
        simple: cdn.discordapp.com
      unescape_domain:
        simple: "True"
      url:
        simple: https://malware.news/t/analysis-of-destructive-malware-whispergate-targeting-ukraine/56413
    continueonerror: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1490,
          "y": -1270
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "8":
    id: "8"
    taskid: e15957c8-5336-4c6e-8327-504f1b7bcb72
    type: title
    task:
      id: e15957c8-5336-4c6e-8327-504f1b7bcb72
      version: -1
      name: Extract Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "9"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": -930
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "9":
    id: "9"
    taskid: 3c5f9496-92fa-4694-830f-c46d15395437
    type: regular
    task:
      id: 3c5f9496-92fa-4694-830f-c46d15395437
      version: -1
      name: Extract Indicators From Data Collected
      description: commands.local.cmd.extract.indicators
      script: Builtin|||extractIndicators
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "10"
    scriptarguments:
      text:
        complex:
          root: http.parsedBlog.indicators
          filters:
          - - operator: isNotEqualString
              left:
                value:
                  simple: http.parsedBlog.indicators
                iscontext: true
              right:
                value:
                  simple: cdn.discordapp.com
    continueonerror: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": -770
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "10":
    id: "10"
    taskid: 3d464ce7-dae2-4b9d-8c9a-958be618bfbe
    type: title
    task:
      id: 3d464ce7-dae2-4b9d-8c9a-958be618bfbe
      version: -1
      name: Tag and Link Indicators
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "57"
      - "58"
      - "104"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": -570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "23":
    id: "23"
    taskid: 86e2d738-b36a-4129-8b88-63fca8c92aef
    type: title
    task:
      id: 86e2d738-b36a-4129-8b88-63fca8c92aef
      version: -1
      name: Threat Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "100"
      - "101"
      - "105"
      - "116"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 100
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "35":
    id: "35"
    taskid: 95f0a35e-81a7-4fa9-8117-0fde1a4c507c
    type: playbook
    task:
      id: 95f0a35e-81a7-4fa9-8117-0fde1a4c507c
      version: -1
      name: Rapid Breach Response - Set Incident Info
      description: This playbook is responsible for setting up the Rapid Breach Response Incident Info tab in the layout.
      playbookName: Rapid Breach Response - Set Incident Info
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "23"
    scriptarguments:
      SourceOfIndicators:
        complex:
          root: http.parsedBlog
          accessor: sourceLink
      countTotalIndicators:
        complex:
          root: ExtractedIndicators
          accessor: Domain
          transformers:
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.IP
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.URL
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
          - operator: append
            args:
              item:
                value:
                  simple: ExtractedIndicators.CVE
                iscontext: true
          - operator: uniq
          - operator: count
      playbookDescription:
        complex:
          root: inputs.PlaybookDescription
    separatecontext: true
    loop:
      iscommand: false
      scriptArguments:
        SourceOfIndicators:
          complex:
            root: http.parsedBlog
            accessor: sourceLink
        countTotalIndicators:
          complex:
            root: ExtractedIndicators
            accessor: Domain
            transformers:
            - operator: append
              args:
                item:
                  value:
                    simple: ExtractedIndicators.IP
                  iscontext: true
            - operator: append
              args:
                item:
                  value:
                    simple: ExtractedIndicators.URL
                  iscontext: true
            - operator: append
              args:
                item:
                  value:
                    simple: ExtractedIndicators.File
                  iscontext: true
            - operator: append
              args:
                item:
                  value:
                    simple: ExtractedIndicators.CVE
                  iscontext: true
            - operator: uniq
            - operator: count
        playbookDescription:
          complex:
            root: inputs.PlaybookDescription
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1230,
          "y": -90
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "36":
    id: "36"
    taskid: 011f7a94-8fae-4908-8e86-30c4963b535f
    type: title
    task:
      id: 011f7a94-8fae-4908-8e86-30c4963b535f
      version: -1
      name: Handle Rapid Breach Response Layout
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "35"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": -220
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "37":
    id: "37"
    taskid: 408db1f9-bfc6-44ef-8a07-e86a4dd76af2
    type: title
    task:
      id: 408db1f9-bfc6-44ef-8a07-e86a4dd76af2
      version: -1
      name: Remediation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "39"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 1070
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "39":
    id: "39"
    taskid: 1e296219-7690-4d40-8771-9384143fed92
    type: condition
    task:
      id: 1e296219-7690-4d40-8771-9384143fed92
      version: -1
      name: Block indicators automatically?
      description: Checks whether IOCs associated with the incident can be blocked automatically.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "40"
      "yes":
      - "126"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.BlockIndicatorsAutomatically
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 1210
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "40":
    id: "40"
    taskid: 87059209-1e24-4551-8aee-6a3f25690993
    type: regular
    task:
      id: 87059209-1e24-4551-8aee-6a3f25690993
      version: -1
      name: Block indicators manually
      description: Manually block the IOCs in the relevant systems.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "42"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1450,
          "y": 1380
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "42":
    id: "42"
    taskid: d5c5ab97-2de6-4370-8920-7709d0005cb8
    type: title
    task:
      id: d5c5ab97-2de6-4370-8920-7709d0005cb8
      version: -1
      name: Mitigation
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "52"
      - "53"
      - "123"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 1550
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "43":
    id: "43"
    taskid: 57211625-0d10-497b-84b8-f66a0fc565eb
    type: regular
    task:
      id: 57211625-0d10-497b-84b8-f66a0fc565eb
      version: -1
      name: October CMS security recommendations
      description: |-
        **Patches**
        Issue has been patched in Build 472 and v1.1.5

        **Workarounds**
        Apply octobercms/library@016a297 and octobercms/library@5bd1a28 to your installation manually if you are unable to upgrade.

        **Recommendations**
        - Keep server OS and system software up to date.
        - Keep October CMS software up to date.
        - Use a multi-factor authentication plugin.
        - Change the default backend URL or block public access to the backend area.

        For more information about the recommendations, [October CMS security](https://github.com/octobercms/october/security/advisories/GHSA-mxr5-mc97-63rc)
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "49"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 1850
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "45":
    id: "45"
    taskid: 8a881740-b7dd-4887-8dee-28e60e961341
    type: condition
    task:
      id: 8a881740-b7dd-4887-8dee-28e60e961341
      version: -1
      name: Analysis resolution - Should continue with the investigation?
      description: Check with the analyst whether to continue with the investigation.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      "No":
      - "48"
      "Yes":
      - "47"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 2150
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    message:
      to:
      subject:
      body:
        simple: Do you need to continue with the investigation?
      methods: []
      format: ""
      bcc:
      cc:
      timings:
        retriescount: 2
        retriesinterval: 360
        completeafterreplies: 1
        completeafterv2: false
        completeaftersla: false
      replyOptions:
      - "Yes"
      - "No"
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "46":
    id: "46"
    taskid: 2d4d72ab-9326-4b6d-8b9e-1f8d5331e2fc
    type: title
    task:
      id: 2d4d72ab-9326-4b6d-8b9e-1f8d5331e2fc
      version: -1
      name: Done
      type: title
      iscommand: false
      brand: ""
      description: ''
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 2490
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "47":
    id: "47"
    taskid: 6fd4ee79-72d8-4c33-8722-cdb5747725fe
    type: regular
    task:
      id: 6fd4ee79-72d8-4c33-8722-cdb5747725fe
      version: -1
      name: Investigate Further
      description: Manual step for further incident investigation.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "46"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1000,
          "y": 2320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "48":
    id: "48"
    taskid: d0edcba7-1e41-4dca-87c7-01961d5b2195
    type: regular
    task:
      id: d0edcba7-1e41-4dca-87c7-01961d5b2195
      version: -1
      name: Close Investigation
      description: Close the current incident
      script: Builtin|||closeInvestigation
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "46"
    scriptarguments:
      closeReason:
        simple: No further actions are required.
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1450,
          "y": 2320
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "49":
    id: "49"
    taskid: 6e11084c-7bca-4c71-8760-97c507c67788
    type: title
    task:
      id: 6e11084c-7bca-4c71-8760-97c507c67788
      version: -1
      name: Resolution
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "45"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 2020
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "52":
    id: "52"
    taskid: 35ead5bd-f931-4d3a-8970-348b471af043
    type: title
    task:
      id: 35ead5bd-f931-4d3a-8970-348b471af043
      version: -1
      name: 'Patch Vulnerability and workarounds '
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "43"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 1700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "53":
    id: "53"
    taskid: a856f1cc-8a84-4a13-8686-fe39b6397277
    type: title
    task:
      id: a856f1cc-8a84-4a13-8686-fe39b6397277
      version: -1
      name: Deploy Detection Rules
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "65"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 790,
          "y": 1700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "57":
    id: "57"
    taskid: 84fb31d5-5cbc-4849-8487-1d7c497b4f00
    type: regular
    task:
      id: 84fb31d5-5cbc-4849-8487-1d7c497b4f00
      version: -1
      name: Tag File indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "36"
    scriptarguments:
      relatedIncidents:
        complex:
          root: incident
          accessor: id
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: WhisperGate, HermeticWiper
      type:
        simple: File
      value:
        complex:
          root: ExtractedIndicators
          accessor: File
          transformers:
          - operator: uniq
      verdict:
        complex:
          root: inputs.CollectedIndicatorsSeverity
    continueonerror: true
    continueonerrortype: ""
    view: |-
      {
        "position": {
          "x": 1230,
          "y": -400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "58":
    id: "58"
    taskid: 8b0b19c0-7fd5-488b-8581-57fa1704ed75
    type: regular
    task:
      id: 8b0b19c0-7fd5-488b-8581-57fa1704ed75
      version: -1
      name: Tag CVE indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "36"
    scriptarguments:
      relatedIncidents:
        complex:
          root: incident
          accessor: id
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: UkraineAttack
      type:
        simple: CVE
      value:
        complex:
          root: inputs.RelatedCVE
          transformers:
          - operator: split
            args:
              delimiter:
                value:
                  simple: ', '
    continueonerror: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1670,
          "y": -400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "62":
    id: "62"
    taskid: a6661128-38aa-425f-8ccb-2df548e0492b
    type: regular
    task:
      id: a6661128-38aa-425f-8ccb-2df548e0492b
      version: -1
      name: Download Yara Rules
      description: Download Yara Rules
      scriptName: http
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      filename:
        simple: YaraRules.yar
      method:
        simple: GET
      saveAsFile:
        simple: "yes"
      url:
        simple: https://github.com/cado-security/DFIR_Resources_Whispergate/blob/main/YARA/WhisperGate.yara
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 980,
          "y": -1270
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "65":
    id: "65"
    taskid: 6edf44f4-0063-4d41-8ae3-5fbc5b5bd0c8
    type: regular
    task:
      id: 6edf44f4-0063-4d41-8ae3-5fbc5b5bd0c8
      version: -1
      name: Yara Rules
      description: Yara rules file has been downloaded as YaraRules.yar and is available for download directly from XSOAR.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "49"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 790,
          "y": 1850
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "66":
    id: "66"
    taskid: 3da30928-66de-4d18-898f-cded08a28e8f
    type: title
    task:
      id: 3da30928-66de-4d18-898f-cded08a28e8f
      version: -1
      name: Collect Detection Rules
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "62"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 980,
          "y": -1420
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "100":
    id: "100"
    taskid: 71cfa71c-8625-46b2-8e9d-3ddcbe952c0e
    type: title
    task:
      id: 71cfa71c-8625-46b2-8e9d-3ddcbe952c0e
      version: -1
      name: Threat ID Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "103"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 260
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "101":
    id: "101"
    taskid: dceb0812-143b-4954-889f-e18868854977
    type: title
    task:
      id: dceb0812-143b-4954-889f-e18868854977
      version: -1
      name: Indicators Hunting
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "102"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 770,
          "y": 260
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "102":
    id: "102"
    taskid: 184eddce-ce7d-4239-8815-ca4294fcc164
    type: playbook
    task:
      id: 184eddce-ce7d-4239-8815-ca4294fcc164
      version: -1
      name: Threat Hunting - Generic
      description: 'This playbook enables threat hunting for IOCs in your enterprise. It currently supports the following integrations: - Splunk - Qradar - Pan-os - Cortex data lake - Autofocus'
      playbookName: Threat Hunting - Generic
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "37"
    scriptarguments:
      MD5:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "32"
          transformers:
          - operator: uniq
      QRadarTimeFrame:
        simple: LAST 7 DAYS
      SHA256:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "64"
          transformers:
          - operator: uniq
      SplunkEarliestTime:
        simple: -7d@d
      SplunkLatestTime:
        simple: now
      URLDomain:
        complex:
          root: ExtractedIndicators.Domain
          filters:
          - - operator: notContainsString
              left:
                value:
                  simple: ExtractedIndicators.Domain
                iscontext: true
              right:
                value:
                  simple: motorsich
          transformers:
          - operator: uniq
    separatecontext: true
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 770,
          "y": 400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "103":
    id: "103"
    taskid: e9c77646-5fb7-4d45-87c2-ad84351d1878
    type: playbook
    task:
      id: e9c77646-5fb7-4d45-87c2-ad84351d1878
      version: -1
      name: Panorama query threat logs
      description: 'Query Panorama Logs of types: traffic, threat, url, data-filtering
        and wildfire.'
      playbookName: Panorama Query Logs
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "37"
    scriptarguments:
      log_type:
        simple: threat
      query:
        simple: (threatid eq 92199) or (threatid eq 2466152) or (threatid eq 2467711)
    separatecontext: true
    loop:
      iscommand: false
      scriptArguments:
        log_type:
          simple: threat
        query:
          simple: (threatid eq 91991) or (threatid eq 91994) or (threatid eq 91995) or (threatid eq 92001) or (threatid eq 92012)
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 1230,
          "y": 400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: true
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "104":
    id: "104"
    taskid: a5178a75-7cb8-46b5-8bdf-7240e68bbfa8
    type: regular
    task:
      id: a5178a75-7cb8-46b5-8bdf-7240e68bbfa8
      version: -1
      name: Tag URL indicators
      description: commands.local.cmd.new.indicator
      script: Builtin|||createNewIndicator
      type: regular
      iscommand: true
      brand: Builtin
    nexttasks:
      '#none#':
      - "36"
    scriptarguments:
      relatedIncidents:
        complex:
          root: incident
          accessor: id
      retry-count:
        simple: "3"
      retry-interval:
        simple: "2"
      tags:
        simple: WhisperGate
      type:
        simple: URL
      value:
        complex:
          root: ExtractedIndicators
          accessor: URL
          transformers:
          - operator: uniq
      verdict:
        complex:
          root: inputs.CollectedIndicatorsSeverity
    continueonerror: true
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 780,
          "y": -400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "105":
    id: "105"
    taskid: b33528a9-5237-4fb4-8de2-595f0f015d8f
    type: title
    task:
      id: b33528a9-5237-4fb4-8de2-595f0f015d8f
      version: -1
      name: 'Cortex XDR - XQL Hunting Queries '
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "106"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1740,
          "y": 260
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "106":
    id: "106"
    taskid: 1c6ff04c-e3c5-4d1b-8eee-19207d618915
    type: condition
    task:
      id: 1c6ff04c-e3c5-4d1b-8eee-19207d618915
      version: -1
      name: Should run XQL hunting queries?
      description: Checks whether to execute XDR shell script for exploitation hunting.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "37"
      "yes":
      - "110"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: inputs.RunXQLHuntingQueries
            iscontext: true
          right:
            value:
              simple: "True"
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 1740,
          "y": 400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "107":
    id: "107"
    taskid: 722663ab-8054-4685-810b-1ef94f203ee7
    type: regular
    task:
      id: 722663ab-8054-4685-810b-1ef94f203ee7
      version: -1
      name: Search for WhisperGate use of InstallUtil (Wiper)
      description: Runs XQL query to find indication of WhisperGate activity
      tags:
      - UserXQL
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "37"
    scriptarguments:
      query:
        simple: "config case_sensitive = false \n|dataset = xdr_data \n|filter (event_type\
          \ = FILE and (event_sub_type = ENUM.FILE_WRITE or event_sub_type = ENUM.FILE_CREATE_NEW)\
          \ and (action_file_name = \"installutil.exe\" AND action_file_path contains\
          \ \"\\appdata\\local\\temp\\installutil.exe\")) or ((event_type = ENUM.PROCESS\
          \ and event_sub_type = ENUM.PROCESS_START) and action_process_image_name\
          \ = \"installutil.exe\" and action_process_image_path contains \"\\appdata\\\
          local\\temp\\installutil.exe\")\n|dedup agent_id, actor_process_image_command_line,\
          \ actor_process_image_sha256, action_file_path, action_file_sha256, action_process_image_sha256,\
          \ action_process_image_command_line \n|fields _time, agent_id,agent_hostname,\
          \ actor_effective_username, action_file_name, action_file_path, action_file_sha256,\
          \ actor_process_image_path, actor_process_image_command_line, \nactor_process_image_sha256,\
          \ action_process_image_path, action_process_image_command_line, action_process_image_sha256"
      query_name:
        simple: Search for WhisperGate use of InstallUtil (Wiper)
      time_frame:
        simple: 7 days
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 2890,
          "y": 885
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 2
    isoversize: false
    isautoswitchedtoquietmode: false
  "108":
    id: "108"
    taskid: c6d8a24d-50ab-45d1-817c-d3deab1911bb
    type: regular
    task:
      id: c6d8a24d-50ab-45d1-817c-d3deab1911bb
      version: -1
      name: Search for WhisperGate powershell sleep command
      description: Runs XQL query to find indication of WhisperGate activity
      tags:
      - UserXQL
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "37"
    scriptarguments:
      query:
        simple: "config case_sensitive = false \n|dataset = xdr_data \n|filter event_type\
          \ = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START \n|filter action_process_image_name\
          \ = \"powershell.exe\" and action_process_image_command_line contains \"\
          UwB0AGEAcgB0AC0AUwBsAGUAZQBwACAALQBzACAAMQAwAA==\"\n|fields _time, agent_hostname,\
          \ actor_effective_username, actor_process_image_path, actor_process_image_sha256,action_process_image_path,\
          \ action_process_image_command_line, action_process_image_sha256 "
      query_name:
        simple: Search for WhisperGate powershell sleep command
      time_frame:
        simple: 7 days
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 2450,
          "y": 885
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 2
    isoversize: false
    isautoswitchedtoquietmode: false
  "109":
    id: "109"
    taskid: 3bcf961f-5899-4bec-813c-11dc6957b69b
    type: regular
    task:
      id: 3bcf961f-5899-4bec-813c-11dc6957b69b
      version: -1
      name: Search for WhisperGate disable windows defender
      description: Runs XQL query to find indication of WhisperGate activity
      tags:
      - UserXQL
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "37"
    scriptarguments:
      query:
        simple: "config case_sensitive = false \n|dataset = xdr_data \n|filter ((event_type\
          \ = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START) and (action_process_image_name\
          \ = \"advancedrun.exe\" and (action_process_image_command_line contains\
          \ \"stop windefend\" OR action_process_image_command_line contains \"mdir\
          \ 'c:\\programdata\\microsoft\\windows defender\")) or (action_process_image_name\
          \ = \"wscript.exe\" and action_process_image_command_line contains \"nmddfrqqrbyjeygggda.vbs\"\
          )) or (event_type = FILE and (event_sub_type = ENUM.FILE_WRITE or event_sub_type\
          \ = ENUM.FILE_CREATE_NEW) and (action_file_name = \"nmddfrqqrbyjeygggda.vbs\"\
          ))\n|dedup agent_id, actor_process_image_command_line, actor_process_image_sha256,\
          \ action_file_path, action_file_sha256, action_process_image_sha256, action_process_image_command_line\
          \ \n|fields _time, agent_id,agent_hostname, actor_effective_username, action_file_name,\
          \ action_file_path, action_file_sha256, actor_process_image_path, actor_process_image_command_line,\
          \ \nactor_process_image_sha256, action_process_image_path, action_process_image_command_line,\
          \ action_process_image_sha256"
      query_name:
        simple: Search for WhisperGate disable windows defender
      time_frame:
        simple: 7 days
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 3330,
          "y": 885
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 2
    isoversize: false
    isautoswitchedtoquietmode: false
  "110":
    id: "110"
    taskid: a05004cd-cd49-4891-8f1e-c87a8c952cfd
    type: condition
    task:
      id: a05004cd-cd49-4891-8f1e-c87a8c952cfd
      version: -1
      name: Check if Cortex XDR - XQL Query Engine is Enabled
      description: Returns 'yes' if integration brand is available. Otherwise returns
        'no'
      scriptName: IsIntegrationAvailable
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "37"
      "yes":
      - "111"
    scriptarguments:
      brandname:
        simple: Cortex XDR - XQL Query Engine
    results:
    - brandInstances
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1940,
          "y": 570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "111":
    id: "111"
    taskid: 60387cfa-8f53-476f-8634-68871f15c503
    type: title
    task:
      id: 60387cfa-8f53-476f-8634-68871f15c503
      version: -1
      name: Hunting for WhisperGate in Your Network
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "109"
      - "107"
      - "108"
      - "115"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 2630,
          "y": 740
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "115":
    id: "115"
    taskid: 9867c8c1-184f-403e-83d1-8e9764a173f6
    type: regular
    task:
      id: 9867c8c1-184f-403e-83d1-8e9764a173f6
      version: -1
      name: 'Search for WhisperGate self-delete '
      description: Runs XQL query to find indication of WhisperGate activity
      tags:
      - UserXQL
      script: '|||xdr-xql-generic-query'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "37"
    scriptarguments:
      query:
        simple: "config case_sensitive = false \n|dataset = xdr_data \n|filter event_type\
          \ = ENUM.PROCESS and event_sub_type = ENUM.PROCESS_START \n|filter (action_process_image_name\
          \ = \"cmd.exe\" OR action_process_image_name = \"ping.exe\") and action_process_image_command_line\
          \ contains \"111.111.111.111 -n 5 -w 10\"\n|fields _time, agent_hostname,\
          \ actor_effective_username, actor_process_image_path, actor_process_image_sha256,action_process_image_path,\
          \ action_process_image_command_line, action_process_image_sha256"
      query_name:
        simple: Creation of a list of the rare Java process
      time_frame:
        simple: 7 days
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1990,
          "y": 885
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 2
    isoversize: false
    isautoswitchedtoquietmode: false
  "116":
    id: "116"
    taskid: b9596da0-4a1b-4956-8b72-1d76403a98f6
    type: title
    task:
      id: b9596da0-4a1b-4956-8b72-1d76403a98f6
      version: -1
      name: Xpanse
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "117"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 270,
          "y": 260
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "117":
    id: "117"
    taskid: 73bcfe16-ee17-4b84-88d8-fcf0d2842f2f
    type: condition
    task:
      id: 73bcfe16-ee17-4b84-88d8-fcf0d2842f2f
      version: -1
      name: Is Xpanse enabled?
      description: Checks if Xpanse instance is enabled.
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "37"
      "yes":
      - "118"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isEqualString
          left:
            value:
              complex:
                root: modules
                filters:
                - - operator: containsString
                    left:
                      value:
                        simple: modules.brand
                      iscontext: true
                    right:
                      value:
                        simple: Xpanse
                    ignorecase: true
                accessor: state
            iscontext: true
          right:
            value:
              simple: active
          ignorecase: true
    view: |-
      {
        "position": {
          "x": 270,
          "y": 400
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "118":
    id: "118"
    taskid: ef08b09b-ad88-40e6-8a9c-e764b896bd6c
    type: regular
    task:
      id: ef08b09b-ad88-40e6-8a9c-e764b896bd6c
      version: -1
      name: Search for possible vulnerable servers using Xpanse
      description: Retrieve issues
      script: '|||expanse-get-issues'
      type: regular
      iscommand: true
      brand: ""
    nexttasks:
      '#none#':
      - "120"
    scriptarguments:
      issue_type:
        simple: October CMS
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 20,
          "y": 570
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "119":
    id: "119"
    taskid: d22bbaa5-93c8-4ad5-8525-20f0c4ce6355
    type: regular
    task:
      id: d22bbaa5-93c8-4ad5-8525-20f0c4ce6355
      version: -1
      name: 'Review possible vulnerable servers '
      description: "Expander shows systems that are exposed to the public internet,\
        \ without the need to install agents or sensors of any kind. Some of the systems\
        \ below do not advertise version information, or are otherwise restricted\
        \ from doing so depending on the configuration of our customers’ networks.\
        \ Expander attempts to retrieve or derive version information, but this is\
        \ not possible in all cases. \n\nXpanse issue IDs:\n${Expanse.Issue.id}"
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "37"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": -250,
          "y": 900
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "120":
    id: "120"
    taskid: 9a3e2b4d-4f7c-4d9d-8fe6-0847a1e725da
    type: condition
    task:
      id: 9a3e2b4d-4f7c-4d9d-8fe6-0847a1e725da
      version: -1
      name: Found servers using Xpanse?
      description: Checks if Xpanse found possible vulnerable server
      type: condition
      iscommand: false
      brand: ""
    nexttasks:
      '#default#':
      - "37"
      "yes":
      - "119"
    separatecontext: false
    conditions:
    - label: "yes"
      condition:
      - - operator: isExists
          left:
            value:
              complex:
                root: Expanse.Issue
                accessor: id
            iscontext: true
    view: |-
      {
        "position": {
          "x": 20,
          "y": 725
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "121":
    id: "121"
    taskid: afb1c763-c9a6-4d95-86bc-2e6a3674ea28
    type: regular
    task:
      id: afb1c763-c9a6-4d95-86bc-2e6a3674ea28
      version: -1
      name: Collect HermeticWiper indicators from Unit 42
      description: This script will extract indicators from given HTML and will handle bad top-level domains to avoid false positives caused by file extensions.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "125"
    scriptarguments:
      exclude_indicators:
        simple: motorsich.com
      unescape_domain:
        simple: "True"
      url:
        simple: https://unit42.paloaltonetworks.com/preparing-for-cyber-impact-russia-ukraine-crisis/
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 2340,
          "y": -1270
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "122":
    id: "122"
    taskid: 53c71a22-f293-4a30-8b55-4869d1ffc113
    type: regular
    task:
      id: 53c71a22-f293-4a30-8b55-4869d1ffc113
      version: -1
      name: Collect indicators from CISA
      description: This script will extract indicators from given HTML and will handle bad top-level domains to avoid false positives caused by file extensions.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      url:
        simple: https://www.cisa.gov/uscert/ncas/alerts/aa22-057a
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1910,
          "y": -1270
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "123":
    id: "123"
    taskid: 18315565-0bda-497c-8246-0de529f92e1d
    type: title
    task:
      id: 18315565-0bda-497c-8246-0de529f92e1d
      version: -1
      name: Best practices by CISA
      type: title
      iscommand: false
      brand: ""
      description: ''
    nexttasks:
      '#none#':
      - "124"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1670,
          "y": 1700
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "124":
    id: "124"
    taskid: df80a5e0-ecfd-4ce4-8a7e-a008c9845a9a
    type: regular
    task:
      id: df80a5e0-ecfd-4ce4-8a7e-a008c9845a9a
      version: -1
      name: 'Review and deploy CISA mitigation suggestions '
      description: |-
        CISA published serval mitigation actions in their [blog](https://www.cisa.gov/uscert/ncas/alerts/aa22-057a).

        Please review and deploy the relevant mitigation to prevent, remediate and mitigate destructive malwares.
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "49"
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 1670,
          "y": 1850
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "125":
    id: "125"
    taskid: df322ad1-d4c7-494b-8197-4a950f0f029a
    type: regular
    task:
      id: df322ad1-d4c7-494b-8197-4a950f0f029a
      version: -1
      name: Collect Whispergate indicators from Unit 42
      description: This script will extract indicators from given HTML and will handle bad top-level domains to avoid false positives caused by file extensions.
      scriptName: ParseHTMLIndicators
      type: regular
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "8"
    scriptarguments:
      exclude_indicators:
        simple: cdn.discordapp.com
      unescape_domain:
        simple: "True"
      url:
        simple: https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/
    separatecontext: false
    view: |-
      {
        "position": {
          "x": 2340,
          "y": -1100
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
  "126":
    id: "126"
    taskid: b6b0fcf2-eb63-4ed7-84a3-5f6f3f4b0bc5
    type: playbook
    task:
      id: b6b0fcf2-eb63-4ed7-84a3-5f6f3f4b0bc5
      version: -1
      name: Block Indicators - Generic v3
      description: |+
        This playbook blocks malicious indicators using all integrations that are enabled, using the following sub-playbooks:

        - Block URL - Generic v2
        - Block Account - Generic v2
        - Block IP - Generic v3
        - Block File - Generic v2
        - Block Email - Generic
        - Block Domain - Generic

      playbookName: Block Indicators - Generic v3
      type: playbook
      iscommand: false
      brand: ""
    nexttasks:
      '#none#':
      - "42"
    scriptarguments:
      AutoBlockIndicators:
        complex:
          root: inputs.AutoBlockIndicators
      AutoCommit:
        simple: "No"
      CustomBlockRule:
        simple: "True"
      CustomURLCategory:
        simple: XSOAR Remediation - Malicious URLs
      IP:
        complex:
          root: DBotScore
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: ip
              ignorecase: true
          - - operator: greaterThanOrEqual
              left:
                value:
                  simple: DBotScore.Score
                iscontext: true
              right:
                value:
                  simple: "3"
          accessor: Indicator
          transformers:
          - operator: uniq
      MD5:
        complex:
          root: ExtractedIndicators
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "32"
              ignorecase: true
          accessor: File
          transformers:
          - operator: uniq
      SHA256:
        complex:
          root: ExtractedIndicators.File
          filters:
          - - operator: hasLength
              left:
                value:
                  simple: ExtractedIndicators.File
                iscontext: true
              right:
                value:
                  simple: "64"
          transformers:
          - operator: uniq
      URL:
        complex:
          root: ExtractedIndicators
          accessor: URL
          transformers:
          - operator: uniq
      UserVerification:
        complex:
          root: inputs.UserVerification
      Username:
        complex:
          root: DBotScore
          filters:
          - - operator: isEqualString
              left:
                value:
                  simple: DBotScore.Type
                iscontext: true
              right:
                value:
                  simple: username
              ignorecase: true
          - - operator: greaterThanOrEqual
              left:
                value:
                  simple: DBotScore.Score
                iscontext: true
              right:
                value:
                  simple: "3"
          accessor: Indicator
          transformers:
          - operator: uniq
    separatecontext: true
    continueonerrortype: ""
    loop:
      iscommand: false
      exitCondition: ""
      wait: 1
      max: 100
    view: |-
      {
        "position": {
          "x": 980,
          "y": 1380
        }
      }
    note: false
    timertriggers: []
    ignoreworker: false
    skipunavailable: false
    quietmode: 0
    isoversize: false
    isautoswitchedtoquietmode: false
view: |-
  {
    "linkLabelsPosition": {
      "106_110_yes": 0.7,
      "106_37_#default#": 0.22,
      "110_111_yes": 0.17,
      "110_37_#default#": 0.17,
      "117_37_#default#": 0.14,
      "120_37_#default#": 0.1
    },
    "paper": {
      "dimensions": {
        "height": 4125,
        "width": 3960,
        "x": -250,
        "y": -1570
      }
    }
  }
inputs:
- key: PlaybookDescription
  value:
    simple: "- On January 14th, 2022, reports began on a malware operation dubbed\
      \ \"WhisperGate\" targeting multiple -organizations in Ukraine.\n\n- On February\
      \ 23, 2022, a new wiper malware known as \"HermeticWiper\" was disclosed by\
      \ several cybersecurity researchers. The new wiper \"HermeticWiper\" was also\
      \ being used against organizations in Ukraine.\n\nCVE-2021-32648 vulnerability\
      \ has a CVSS score of 9.1 and was found in octobercms, which is a CMS platform\
      \ based on the Laravel PHP Framework. \nIn affected versions of the october/system\
      \ package an attacker can request an account password reset and then gain access\
      \ to the account using a specially crafted request. \nThe issue has been patched\
      \ in Build 472 and v1.1.5.\n\n**The playbook includes the following tasks:**\n\
      - Collect related known indicators from Unit 42, CISA and Malware News blog.\n\
      -  Search for possible vulnerable servers using Xpanse.\n- Indicators and exploitation\
      \ patterns hunting using PAN-OS, Cortex XDR and SIEM products.\n- Block indicators\
      \ automatically or manually.\n\n**Mitigations:**\n* October CMS security recommendations\n\
      * Deploy YARA detection Rules.\n\nMore information:\n[UNIT42 Blog - Ongoing\
      \ Russia and Ukraine Cyber Conflict](https://unit42.paloaltonetworks.com/ukraine-cyber-conflict-cve-2021-32648-whispergate/)\n\
      [Russia-Ukraine Cyberattacks: How to Protect Against Related Cyberthreats Including\
      \ DDoS, HermeticWiper, Gamaredon and Website Defacement](https://unit42.paloaltonetworks.com/preparing-for-cyber-impact-russia-ukraine-crisis/)\n\
      [Microsoft Blog](https://www.microsoft.com/security/blog/2022/01/15/destructive-malware-targeting-ukrainian-organizations/)\n\
      [CVE-2021-32648 NVD](https://nvd.nist.gov/vuln/detail/CVE-2021-32648#vulnCurrentDescriptionTitle)\n\
      \nNote: This is a beta playbook, which lets you implement and test pre-release\
      \ software. Since the playbook is beta, it might contain bugs. Updates to the\
      \ pack during the beta phase might include non-backward compatible features.\
      \ We appreciate your feedback on the quality and usability of the pack to help\
      \ us identify issues, fix them, and continually improve."
  required: false
  description: The playbook description for Rapid Breach Response layout.
  playbookInputQuery:
- key: BlockIndicatorsAutomatically
  value:
    simple: "False"
  required: false
  description: Whether to block the indicators automatically or not.
  playbookInputQuery:
- key: CollectedIndicatorsSeverity
  value:
    simple: Malicious
  required: false
  description: "The verdict of the collected indicators. Default is \"Malicious\"\
    . \nOther options can be \"Suspicious\" and \"Unknown\"."
  playbookInputQuery:
- key: RelatedCVE
  value:
    simple: CVE-2021-32648
  required: false
  description: The WhisperGate malware related CVE.
  playbookInputQuery:
- key: RunXQLHuntingQueries
  value:
    simple: "False"
  required: false
  description: Whether to perform XQL hunting queries. Default is "False".
  playbookInputQuery:
- key: UserVerification
  value:
    simple: "False"
  required: false
  description: 'Possible values: True/False.\nWhether to provide user verification for blocking IPs. \n\nFalse - No prompt will be displayed to the user.\nTrue - The server will ask the user for blocking verification and will display the blocking list'
  playbookInputQuery:
- key: AutoBlockIndicators
  value:
    simple: "True"
  required: false
  description: |-
    Should the given indicators be automatically blocked, or should the user be given the option to choose?
    If set to True - no prompt will appear, and all provided indicators will be blocked automatically.
    If set to False - the user will be prompted to select which indicators to block.
  playbookInputQuery:
outputs: []
tests:
- No tests (auto formatted)
fromversion: 6.5.0