Fix validation, remove duplicate.

This commit is contained in:
Raphaël Vinot 2017-02-13 18:52:54 +01:00
parent 47ac01ee96
commit 910398fe76
8 changed files with 483 additions and 451 deletions

View file

@ -1,453 +1,447 @@
{ {
"values": [ "values": [
{ "value": "Astrum", {
"value": "Astrum",
"description": "Astrum Exploit Kit is a private Exploit Kit used in massive scale malvertising campaigns. It's notable by its use of Steganography", "description": "Astrum Exploit Kit is a private Exploit Kit used in massive scale malvertising campaigns. It's notable by its use of Steganography",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2014/09/astrum-ek.html", "http://malware.dontneedcoffee.com/2014/09/astrum-ek.html",
"http://www.welivesecurity.com/2016/12/06/readers-popular-websites-targeted-stealthy-stegano-exploit-kit-hiding-pixels-malicious-ads/" "http://www.welivesecurity.com/2016/12/06/readers-popular-websites-targeted-stealthy-stegano-exploit-kit-hiding-pixels-malicious-ads/"
], ],
"synonyms": [ "synonyms": [
"Stegano EK" "Stegano EK"
], ],
"status": "Unknown - Last Seen 2016-12-07" "status": "Unknown - Last Seen 2016-12-07"
} }
} },
, {
{ "value": "DealersChoice", "value": "DealersChoice",
"description": "DealersChoice is a Flash Player Exploit platform triggered by RTF", "description": "DealersChoice is a Flash Player Exploit platform triggered by RTF",
"meta": { "meta": {
"refs": [ "refs": [
"http://researchcenter.paloaltonetworks.com/2016/10/unit42-dealerschoice-sofacys-flash-player-exploit-platform/", "http://researchcenter.paloaltonetworks.com/2016/10/unit42-dealerschoice-sofacys-flash-player-exploit-platform/",
"http://blog.trendmicro.com/trendlabs-security-intelligence/pawn-storm-ramps-up-spear-phishing-before-zero-days-get-patched/" "http://blog.trendmicro.com/trendlabs-security-intelligence/pawn-storm-ramps-up-spear-phishing-before-zero-days-get-patched/"
], ],
"synonyms": [ "synonyms": [
"Sednit RTF EK" "Sednit RTF EK"
], ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "DNSChanger", "value": "DNSChanger",
"description": "DNSChanger Exploit Kit is an exploit kit targeting Routers via the browser", "description": "DNSChanger Exploit Kit is an exploit kit targeting Routers via the browser",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2015/05/an-exploit-kit-dedicated-to-csrf.html", "http://malware.dontneedcoffee.com/2015/05/an-exploit-kit-dedicated-to-csrf.html",
"https://www.proofpoint.com/us/threat-insight/post/home-routers-under-attack-malvertising-windows-android-devices" "https://www.proofpoint.com/us/threat-insight/post/home-routers-under-attack-malvertising-windows-android-devices"
], ],
"synonyms": [ "synonyms": [
"RouterEK" "RouterEK"
], ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "Empire", "value": "Empire",
"description": "The Empire Pack is a variation of RIG operated by a load seller. It's being fed by many traffic actors", "description": "The Empire Pack is a variation of RIG operated by a load seller. It's being fed by many traffic actors",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2016/10/rig-evolves-neutrino-waves-goodbye.html" "http://malware.dontneedcoffee.com/2016/10/rig-evolves-neutrino-waves-goodbye.html"
], ],
"synonyms": [ "synonyms": [
"RIG-E" "RIG-E"
] ],
, "status": "Unknown - Last seen: 2016-12-29"
"status": "Unknown - Last seen: 2016-12-29" }
} },
} {
, "value": "Hunter",
{ "value": "Hunter",
"description": "Hunter EK is an evolution of 3Ros EK", "description": "Hunter EK is an evolution of 3Ros EK",
"meta": { "meta": {
"refs": [ "refs": [
"https://www.proofpoint.com/us/threat-insight/post/Hunter-Exploit-Kit-Targets-Brazilian-Banking-Customers" "https://www.proofpoint.com/us/threat-insight/post/Hunter-Exploit-Kit-Targets-Brazilian-Banking-Customers"
], ],
"synonyms": [ "synonyms": [
"3ROS Exploit Kit" "3ROS Exploit Kit"
] ],
, "status": "Active"
"status": "Active" }
} },
} {
, "value": "Kaixin",
{ "value": "Kaixin",
"description": "Kaixin is an exploit kit mainly seen behind compromised website in Asia", "description": "Kaixin is an exploit kit mainly seen behind compromised website in Asia",
"meta": { "meta": {
"refs": [ "refs": [
"http://www.kahusecurity.com/2013/deobfuscating-the-ck-exploit-kit/", "http://www.kahusecurity.com/2013/deobfuscating-the-ck-exploit-kit/",
"http://www.kahusecurity.com/2012/new-chinese-exploit-pack/" "http://www.kahusecurity.com/2012/new-chinese-exploit-pack/"
], ],
"synonyms": [ "synonyms": [
"CK vip" "CK vip"
] , ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "Magnitude", "value": "Magnitude",
"description": "Magnitude EK", "description": "Magnitude EK",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2013/10/Magnitude.html", "http://malware.dontneedcoffee.com/2013/10/Magnitude.html",
"https://www.trustwave.com/Resources/SpiderLabs-Blog/A-Peek-Into-the-Lion-s-Den-%E2%80%93-The-Magnitude--aka-PopAds--Exploit-Kit/", "https://www.trustwave.com/Resources/SpiderLabs-Blog/A-Peek-Into-the-Lion-s-Den-%E2%80%93-The-Magnitude--aka-PopAds--Exploit-Kit/",
"http://malware.dontneedcoffee.com/2014/02/and-real-name-of-magnitude-is.html" "http://malware.dontneedcoffee.com/2014/02/and-real-name-of-magnitude-is.html"
], ],
"synonyms": [ "synonyms": [
"Popads EK", "Popads EK",
"TopExp" "TopExp"
], ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "MWI", "value": "MWI",
"description": "Microsoft Word Intruder is an exploit kit focused on Word and embedded flash exploits. The author wants to avoid their customer to use it in mass spam campaign, so it's most often connected to semi-targeted attacks", "description": "Microsoft Word Intruder is an exploit kit focused on Word and embedded flash exploits. The author wants to avoid their customer to use it in mass spam campaign, so it's most often connected to semi-targeted attacks",
"meta": { "meta": {
"refs": [ "refs": [
"https://www.fireeye.com/blog/threat-research/2015/04/a_new_word_document.html", "https://www.fireeye.com/blog/threat-research/2015/04/a_new_word_document.html",
"https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-microsoft-word-intruder-revealed.pdf" "https://www.sophos.com/en-us/medialibrary/PDFs/technical%20papers/sophos-microsoft-word-intruder-revealed.pdf"
], ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "Neutrino", "value": "Neutrino",
"description": "Neutrino Exploit Kit has been one of the major exploit kit from its launch in 2013 till september 2016 when it become private (defense name for this variation is Neutrino-v). This EK vanished from march 2014 till november 2014.", "description": "Neutrino Exploit Kit has been one of the major exploit kit from its launch in 2013 till september 2016 when it become private (defense name for this variation is Neutrino-v). This EK vanished from march 2014 till november 2014.",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2013/03/hello-neutrino-just-one-more-exploit-kit.html", "http://malware.dontneedcoffee.com/2013/03/hello-neutrino-just-one-more-exploit-kit.html",
"http://malware.dontneedcoffee.com/2014/11/neutrino-come-back.html" "http://malware.dontneedcoffee.com/2014/11/neutrino-come-back.html"
], ],
"synonyms": [ "synonyms": [
"Job314", "Job314",
"Neutrino Rebooted", "Neutrino Rebooted",
"Neutrino-v" "Neutrino-v"
] ],
, "status": "Active"
"status": "Active" }
} },
} {
, "value": "RIG",
{ "value": "RIG",
"description": "RIG is an exploit kit that takes its source in Infinity EK itself an evolution of Redkit. It became dominant after the fall of Angler, Nuclear Pack and the end of public access to Neutrino. RIG-v is the name given to RIG 4 when it was only accessible by \"vip\" customers and when RIG 3 was still in use.", "description": "RIG is an exploit kit that takes its source in Infinity EK itself an evolution of Redkit. It became dominant after the fall of Angler, Nuclear Pack and the end of public access to Neutrino. RIG-v is the name given to RIG 4 when it was only accessible by \"vip\" customers and when RIG 3 was still in use.",
"meta": { "meta": {
"refs": [ "refs": [
"http://www.kahusecurity.com/2014/rig-exploit-pack/", "http://www.kahusecurity.com/2014/rig-exploit-pack/",
"https://www.trustwave.com/Resources/SpiderLabs-Blog/RIG-Reloaded---Examining-the-Architecture-of-RIG-Exploit-Kit-3-0/", "https://www.trustwave.com/Resources/SpiderLabs-Blog/RIG-Reloaded---Examining-the-Architecture-of-RIG-Exploit-Kit-3-0/",
"https://www.trustwave.com/Resources/SpiderLabs-Blog/RIG-Exploit-Kit-%E2%80%93-Diving-Deeper-into-the-Infrastructure/", "https://www.trustwave.com/Resources/SpiderLabs-Blog/RIG-Exploit-Kit-%E2%80%93-Diving-Deeper-into-the-Infrastructure/",
"http://malware.dontneedcoffee.com/2016/10/rig-evolves-neutrino-waves-goodbye.html" "http://malware.dontneedcoffee.com/2016/10/rig-evolves-neutrino-waves-goodbye.html"
], ],
"synonyms": [ "synonyms": [
"RIG 3", "RIG 3",
"RIG-v", "RIG-v",
"RIG 4", "RIG 4",
"Meadgive" "Meadgive"
], ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "Sednit EK", "value": "Sednit EK",
"description": "Sednit EK is the exploit kit used by APT28", "description": "Sednit EK is the exploit kit used by APT28",
"meta": { "meta": {
"refs": [ "refs": [
"http://www.welivesecurity.com/2014/10/08/sednit-espionage-group-now-using-custom-exploit-kit/", "http://www.welivesecurity.com/2014/10/08/sednit-espionage-group-now-using-custom-exploit-kit/",
"http://blog.trendmicro.com/trendlabs-security-intelligence/new-adobe-flash-zero-day-used-in-pawn-storm-campaign/" "http://blog.trendmicro.com/trendlabs-security-intelligence/new-adobe-flash-zero-day-used-in-pawn-storm-campaign/"
], ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "Bizarro Sundown", "value": "Bizarro Sundown",
"description": "Bizarro Sundown appears to be a fork of Sundown with added anti-analysis features", "description": "Bizarro Sundown appears to be a fork of Sundown with added anti-analysis features",
"meta": { "meta": {
"refs": [ "refs": [
"http://blog.trendmicro.com/trendlabs-security-intelligence/new-bizarro-sundown-exploit-kit-spreads-locky/", "http://blog.trendmicro.com/trendlabs-security-intelligence/new-bizarro-sundown-exploit-kit-spreads-locky/",
"https://blog.malwarebytes.com/cybercrime/exploits/2016/10/yet-another-sundown-ek-variant/" "https://blog.malwarebytes.com/cybercrime/exploits/2016/10/yet-another-sundown-ek-variant/"
], ],
"synonyms": [ "synonyms": [
"Sundown-b" "Sundown-b"
], ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "GreenFlash Sundown", "value": "GreenFlash Sundown",
"description": "GreenFlash Sundown is a variation of Bizarro Sundown without landing", "description": "GreenFlash Sundown is a variation of Bizarro Sundown without landing",
"meta": { "meta": {
"refs": [ "refs": [
"http://blog.trendmicro.com/trendlabs-security-intelligence/new-bizarro-sundown-exploit-kit-spreads-locky/" "http://blog.trendmicro.com/trendlabs-security-intelligence/new-bizarro-sundown-exploit-kit-spreads-locky/"
], ],
"synonyms": [ "synonyms": [
"Sundown-GF" "Sundown-GF"
], ],
"status": "Active" "status": "Active"
} }
} },
, {
{ "value": "Sundown", "value": "Sundown",
"description": "Sundown Exploit Kit is mainly built out of stolen code from other exploit kits", "description": "Sundown Exploit Kit is mainly built out of stolen code from other exploit kits",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2015/06/fast-look-at-sundown-ek.html", "http://malware.dontneedcoffee.com/2015/06/fast-look-at-sundown-ek.html",
"https://www.virusbulletin.com/virusbulletin/2015/06/beta-exploit-pack-one-more-piece-crimeware-infection-road" "https://www.virusbulletin.com/virusbulletin/2015/06/beta-exploit-pack-one-more-piece-crimeware-infection-road"
], ],
"synonyms": [ "synonyms": [
"Beps", "Beps",
"Xer", "Xer",
"Beta" "Beta"
], ],
"status": "Active", "status": "Active",
"colour": "#C03701" "colour": "#C03701"
} }
} },
, {
{ "value": "Angler", "value": "Angler",
"description": "The Angler Exploit Kit has been the most popular and evolved exploit kit from 2014 to middle of 2016. There was several variation. The historical \"indexm\" variant was used to spread Lurk. A vip version used notabily to spread Poweliks, the \"standard\" commercial version, and a declinaison tied to load selling (mostly bankers) that can be associated to EmpirePPC", "description": "The Angler Exploit Kit has been the most popular and evolved exploit kit from 2014 to middle of 2016. There was several variation. The historical \"indexm\" variant was used to spread Lurk. A vip version used notabily to spread Poweliks, the \"standard\" commercial version, and a declinaison tied to load selling (mostly bankers) that can be associated to EmpirePPC",
"meta": { "meta": {
"refs": [ "refs": [
"https://blogs.sophos.com/2015/07/21/a-closer-look-at-the-angler-exploit-kit/", "https://blogs.sophos.com/2015/07/21/a-closer-look-at-the-angler-exploit-kit/",
"http://malware.dontneedcoffee.com/2015/12/xxx-is-angler-ek.html", "http://malware.dontneedcoffee.com/2015/12/xxx-is-angler-ek.html",
"http://malware.dontneedcoffee.com/2016/06/is-it-end-of-angler.html" "http://malware.dontneedcoffee.com/2016/06/is-it-end-of-angler.html"
], ],
"synonyms": [ "synonyms": [
"XXX", "XXX",
"AEK", "AEK",
"Axpergle" "Axpergle"
], ],
"status": "Retired - Last seen: 2016-06-07" "status": "Retired - Last seen: 2016-06-07"
} }
} },
, {
{ "value": "Archie", "value": "Archie",
"description": "Archie EK", "description": "Archie EK",
"meta": { "meta": {
"refs": [ "refs": [
"https://www.alienvault.com/blogs/labs-research/archie-just-another-exploit-kit" "https://www.alienvault.com/blogs/labs-research/archie-just-another-exploit-kit"
], ],
"status": "Retired" "status": "Retired"
} }
} },
, {
{ "value": "BlackHole", "value": "BlackHole",
"description": "The BlackHole Exploit Kit has been the most popular exploit kit from 2011 to 2013. Its activity stopped with Paunch's arrest (all activity since then is anecdotal and based on an old leak)", "description": "The BlackHole Exploit Kit has been the most popular exploit kit from 2011 to 2013. Its activity stopped with Paunch's arrest (all activity since then is anecdotal and based on an old leak)",
"meta": { "meta": {
"refs": [ "refs": [
"https://www.trustwave.com/Resources/SpiderLabs-Blog/Blackhole-Exploit-Kit-v2/", "https://www.trustwave.com/Resources/SpiderLabs-Blog/Blackhole-Exploit-Kit-v2/",
"https://nakedsecurity.sophos.com/exploring-the-blackhole-exploit-kit/" "https://nakedsecurity.sophos.com/exploring-the-blackhole-exploit-kit/"
], ],
"synonyms": [ "synonyms": [
"BHEK" "BHEK"
], ],
"status": "Retired - Last seen: 2013-10-07" "status": "Retired - Last seen: 2013-10-07"
} }
} },
, {
{ "value": "Bleeding Life", "value": "Bleeding Life",
"description": "Bleeding Life is an exploit kit that became open source with its version 2", "description": "Bleeding Life is an exploit kit that became open source with its version 2",
"meta": { "meta": {
"refs": [ "refs": [
"http://www.kahusecurity.com/2011/flash-used-in-idol-malvertisement/", "http://www.kahusecurity.com/2011/flash-used-in-idol-malvertisement/",
"http://thehackernews.com/2011/10/bleeding-life-2-exploit-pack-released.html" "http://thehackernews.com/2011/10/bleeding-life-2-exploit-pack-released.html"
], ],
"synonyms": [ "synonyms": [
"BL", "BL",
"BL2" "BL2"
] ],
, "status": "Retired"
"status": "Retired" }
} },
} {
, "value": "Cool",
{ "value": "Cool",
"description": "The Cool Exploit Kit was a kind of BlackHole VIP in 2012/2013", "description": "The Cool Exploit Kit was a kind of BlackHole VIP in 2012/2013",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2012/10/newcoolek.html", "http://malware.dontneedcoffee.com/2012/10/newcoolek.html",
"http://malware.dontneedcoffee.com/2013/07/a-styxy-cool-ek.html", "http://malware.dontneedcoffee.com/2013/07/a-styxy-cool-ek.html",
"http://blog.trendmicro.com/trendlabs-security-intelligence/styx-exploit-pack-how-it-works/" "http://blog.trendmicro.com/trendlabs-security-intelligence/styx-exploit-pack-how-it-works/"
], ],
"synonyms": [ "synonyms": [
"CEK", "CEK",
"Styxy Cool" "Styxy Cool"
], ],
"status": "Retired - Last seen: 2013-10-07" "status": "Retired - Last seen: 2013-10-07"
} }
} },
, {
{ "value": "Fiesta", "value": "Fiesta",
"description": "Fiesta Exploit Kit", "description": "Fiesta Exploit Kit",
"meta": { "meta": {
"refs": [ "refs": [
"http://blog.0x3a.com/post/110052845124/an-in-depth-analysis-of-the-fiesta-exploit-kit-an", "http://blog.0x3a.com/post/110052845124/an-in-depth-analysis-of-the-fiesta-exploit-kit-an",
"http://www.kahusecurity.com/2011/neosploit-is-back/" "http://www.kahusecurity.com/2011/neosploit-is-back/"
], ],
"synonyms": [ "synonyms": [
"NeoSploit", "NeoSploit",
"Fiexp" "Fiexp"
] ],
, "status": "Retired - Last Seen: beginning of 2015-07"
"status": "Retired - Last Seen: beginning of 2015-07" }
} },
} {
, "value": "FlashPack",
{ "value": "FlashPack",
"description": "FlashPack EK got multiple fork. The most common variant seen was the standalone Flash version", "description": "FlashPack EK got multiple fork. The most common variant seen was the standalone Flash version",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2012/11/meet-critxpack-previously-vintage-pack.html", "http://malware.dontneedcoffee.com/2012/11/meet-critxpack-previously-vintage-pack.html",
"http://malware.dontneedcoffee.com/2013/04/meet-safe-pack-v20-again.html" "http://malware.dontneedcoffee.com/2013/04/meet-safe-pack-v20-again.html"
], ],
"synonyms": [ "synonyms": [
"FlashEK", "FlashEK",
"SafePack", "SafePack",
"CritXPack", "CritXPack",
"Vintage Pack" "Vintage Pack"
] ],
, "status": "Retired - Last seen: middle of 2015-04"
"status": "Retired - Last seen: middle of 2015-04" }
} },
} {
, "value": "GrandSoft",
{ "value": "GrandSoft",
"description": "GrandSoft Exploit Kit was a quite common exploit kit used in 2012/2013", "description": "GrandSoft Exploit Kit was a quite common exploit kit used in 2012/2013",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2013/09/FinallyGrandSoft.html", "http://malware.dontneedcoffee.com/2013/09/FinallyGrandSoft.html",
"http://malware.dontneedcoffee.com/2012/10/neosploit-now-showing-bh-ek-20-like.html", "http://malware.dontneedcoffee.com/2012/10/neosploit-now-showing-bh-ek-20-like.html",
"https://nakedsecurity.sophos.com/2012/08/24/sophos-sucks-malware/" "https://nakedsecurity.sophos.com/2012/08/24/sophos-sucks-malware/"
], ],
"synonyms": [ "synonyms": [
"StampEK", "StampEK",
"SofosFO" "SofosFO"
] , ],
"status": "Retired - Last seen: 2014-03" "status": "Retired - Last seen: 2014-03"
} }
} },
, {
{ "value": "HanJuan", "value": "HanJuan",
"description": "Hanjuan EK was a one actor fed variation of Angler EK used in evolved malvertising chain targeting USA. It has been using a 0day (CVE-2015-0313) from beginning of December 2014 till beginning of February 2015", "description": "Hanjuan EK was a one actor fed variation of Angler EK used in evolved malvertising chain targeting USA. It has been using a 0day (CVE-2015-0313) from beginning of December 2014 till beginning of February 2015",
"meta": { "meta": {
"refs": [ "refs": [
"http://www.malwaresigs.com/2013/10/14/unknown-ek/", "http://www.malwaresigs.com/2013/10/14/unknown-ek/",
"https://blog.malwarebytes.com/threat-analysis/2014/08/shining-some-light-on-the-unknown-exploit-kit/", "https://blog.malwarebytes.com/threat-analysis/2014/08/shining-some-light-on-the-unknown-exploit-kit/",
"http://blog.trendmicro.com/trendlabs-security-intelligence/a-closer-look-at-the-exploit-kit-in-cve-2015-0313-attack", "http://blog.trendmicro.com/trendlabs-security-intelligence/a-closer-look-at-the-exploit-kit-in-cve-2015-0313-attack",
"https://twitter.com/kafeine/status/562575744501428226" "https://twitter.com/kafeine/status/562575744501428226"
], ],
"status": "Retired - Last seen: 2015-07" "status": "Retired - Last seen: 2015-07"
} }
} },
, {
{ "value": "Himan", "value": "Himan",
"description": "Himan Exploit Kit", "description": "Himan Exploit Kit",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2013/10/HiMan.html" "http://malware.dontneedcoffee.com/2013/10/HiMan.html"
], ],
"synonyms": [ "synonyms": [
"High Load" "High Load"
], ],
"status": "Retired - Last seen: 2014-04" "status": "Retired - Last seen: 2014-04"
} }
} },
, {
{ "value": "Impact", "value": "Impact",
"description": "Impact EK", "description": "Impact EK",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2012/12/inside-impact-exploit-kit-back-on-track.html" "http://malware.dontneedcoffee.com/2012/12/inside-impact-exploit-kit-back-on-track.html"
] ],
, "status": "Retired"
"status": "Retired" }
} },
} {
, "value": "Infinity",
{ "value": "Infinity",
"description": "Infinity is an evolution of Redkit", "description": "Infinity is an evolution of Redkit",
"meta": { "meta": {
"refs": [ "refs": [
"http://blog.talosintel.com/2013/11/im-calling-this-goon-exploit-kit-for-now.html", "http://blog.talosintel.com/2013/11/im-calling-this-goon-exploit-kit-for-now.html",
"http://www.kahusecurity.com/2014/the-resurrection-of-redkit/" "http://www.kahusecurity.com/2014/the-resurrection-of-redkit/"
], ],
"synonyms": [ "synonyms": [
"Redkit v2.0", "Redkit v2.0",
"Goon" "Goon"
], ],
"status": "Retired - Last seen: 2014-07" "status": "Retired - Last seen: 2014-07"
} }
} },
, {
{ "value": "Lightsout", "value": "Lightsout",
"description": "Lightsout Exploit Kit has been used in Watering Hole attack performed by the APT Group havex", "description": "Lightsout Exploit Kit has been used in Watering Hole attack performed by the APT Group havex",
"meta": { "meta": {
"refs": [ "refs": [
"http://blog.talosintel.com/2014/03/hello-new-exploit-kit.html", "http://blog.talosintel.com/2014/03/hello-new-exploit-kit.html",
"http://blog.talosintel.com/2014/05/continued-analysis-of-lightsout-exploit.html", "http://blog.talosintel.com/2014/05/continued-analysis-of-lightsout-exploit.html",
"http://malwageddon.blogspot.fr/2013/09/unknown-ek-by-way-how-much-is-fish.html" "http://malwageddon.blogspot.fr/2013/09/unknown-ek-by-way-how-much-is-fish.html"
], ],
"status": "Unknown - Last seen: 2014-03" "status": "Unknown - Last seen: 2014-03"
} }
} },
, {
{ "value": "Niteris", "value": "Niteris",
"description": "Niteris was used mainly to target Russian.", "description": "Niteris was used mainly to target Russian.",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2014/06/cottoncastle.html", "http://malware.dontneedcoffee.com/2014/06/cottoncastle.html",
"http://malware.dontneedcoffee.com/2015/05/another-look-at-niteris-post.html" "http://malware.dontneedcoffee.com/2015/05/another-look-at-niteris-post.html"
], ],
"synonyms": [ "synonyms": [
"CottonCastle" "CottonCastle"
], ],
"status": "Unknown - Last seen: 2015-11" "status": "Unknown - Last seen: 2015-11"
} }
} },
, {
{ "value": "Nuclear", "value": "Nuclear",
"description": "The Nuclear Pack appeared in 2009 and has been one of the longer living one. Spartan EK was a landing less variation of Nuclear Pack", "description": "The Nuclear Pack appeared in 2009 and has been one of the longer living one. Spartan EK was a landing less variation of Nuclear Pack",
"meta": { "meta": {
"refs": [ "refs": [
"http://blog.checkpoint.com/2016/05/17/inside-nuclears-core-unraveling-a-ransomware-as-a-service-infrastructure/" "http://blog.checkpoint.com/2016/05/17/inside-nuclears-core-unraveling-a-ransomware-as-a-service-infrastructure/"
], ],
"synonyms": [ "synonyms": [
"NEK", "NEK",
"Nuclear Pack", "Nuclear Pack",
"Spartan", "Spartan",
"Neclu" "Neclu"
] , ],
"status": "Retired - Last seen: 2015-04-30" "status": "Retired - Last seen: 2015-04-30"
} }
} },
, {
{ "value": "Phoenix", "value": "Phoenix",
"description": "Phoenix Exploit Kit", "description": "Phoenix Exploit Kit",
"meta": { "meta": {
"refs": [ "refs": [
"http://malwareint.blogspot.fr/2010/09/phoenix-exploits-kit-v21-inside.html", "http://malwareint.blogspot.fr/2010/09/phoenix-exploits-kit-v21-inside.html",
"http://blog.trendmicro.com/trendlabs-security-intelligence/now-exploiting-phoenix-exploit-kit-version-2-5/" "http://blog.trendmicro.com/trendlabs-security-intelligence/now-exploiting-phoenix-exploit-kit-version-2-5/"
], ],
"synonyms": [ "synonyms": [
"PEK" "PEK"
], ],
"status": "Retired" "status": "Retired"
} }
} },
, {
{ "value": "Private Exploit Pack", "value": "Private Exploit Pack",
"description": "Private Exploit Pack", "description": "Private Exploit Pack",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2013/07/pep-new-bep.html", "http://malware.dontneedcoffee.com/2013/07/pep-new-bep.html",
"http://malwageddon.blogspot.fr/2013/07/unknown-ek-well-hey-hey-i-wanna-be.html" "http://malwageddon.blogspot.fr/2013/07/unknown-ek-well-hey-hey-i-wanna-be.html"
], ],
"synonyms": [ "synonyms": [
"PEP" "PEP"
], ],
"status": "Retired" "status": "Retired"
} }
} },
, {
{ "value": "Redkit", "value": "Redkit",
"description": "Redkit has been a major exploit kit in 2012. One of its specific features was to allow its access against a share of a percentage of the customer's traffic", "description": "Redkit has been a major exploit kit in 2012. One of its specific features was to allow its access against a share of a percentage of the customer's traffic",
"meta": { "meta": {
"refs": [ "refs": [
@ -455,35 +449,35 @@
"http://malware.dontneedcoffee.com/2012/05/inside-redkit.html", "http://malware.dontneedcoffee.com/2012/05/inside-redkit.html",
"https://nakedsecurity.sophos.com/2013/05/09/redkit-exploit-kit-part-2/" "https://nakedsecurity.sophos.com/2013/05/09/redkit-exploit-kit-part-2/"
], ],
"status": "Retired" "status": "Retired"
} }
} },
, {
{ "value": "Sakura", "value": "Sakura",
"description": "Description Here", "description": "Description Here",
"meta": { "meta": {
"refs": [ "refs": [
"http://www.xylibox.com/2012/01/sakura-exploit-pack-10.html" "http://www.xylibox.com/2012/01/sakura-exploit-pack-10.html"
], ],
"status": "Retired - Last seen: 2013-09" "status": "Retired - Last seen: 2013-09"
} }
} },
, {
{ "value": "Sweet-Orange", "value": "Sweet-Orange",
"description": "Sweet Orange", "description": "Sweet Orange",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2012/12/juice-sweet-orange-2012-12.html" "http://malware.dontneedcoffee.com/2012/12/juice-sweet-orange-2012-12.html"
], ],
"synonyms": [ "synonyms": [
"SWO", "SWO",
"Anogre" "Anogre"
], ],
"status": "Retired - Last seen: 2015-04-05" "status": "Retired - Last seen: 2015-04-05"
} }
} },
, {
{ "value": "Styx", "value": "Styx",
"description": "Styx Exploit Kit", "description": "Styx Exploit Kit",
"meta": { "meta": {
"refs": [ "refs": [
@ -491,11 +485,11 @@
"https://krebsonsecurity.com/2013/07/styx-exploit-pack-domo-arigato-pc-roboto/", "https://krebsonsecurity.com/2013/07/styx-exploit-pack-domo-arigato-pc-roboto/",
"http://malware.dontneedcoffee.com/2013/05/inside-styx-2013-05.html" "http://malware.dontneedcoffee.com/2013/05/inside-styx-2013-05.html"
], ],
"status":"Retired - Last seen: 2014-06" "status": "Retired - Last seen: 2014-06"
} }
} },
, {
{ "value": "Unknown", "value": "Unknown",
"description": "Unknown Exploit Kit. This is a place holder for any undocumented Exploit Kit. If you use this tag, we will be more than happy to give the associated EK a deep look.", "description": "Unknown Exploit Kit. This is a place holder for any undocumented Exploit Kit. If you use this tag, we will be more than happy to give the associated EK a deep look.",
"meta": { "meta": {
"refs": [ "refs": [
@ -503,9 +497,9 @@
"https://twitter.com/node5", "https://twitter.com/node5",
"https://twitter.com/kahusecurity" "https://twitter.com/kahusecurity"
] ]
} }
} }
], ],
"version": 3, "version": 3,
"uuid": "454f4e78-bd7c-11e6-a4a6-cec0c932ce01", "uuid": "454f4e78-bd7c-11e6-a4a6-cec0c932ce01",
"description": "Exploit-Kit is an enumeration of some exploitation kits used by adversaries. The list includes document, browser and router exploit kits.It's not meant to be totally exhaustive but aim at covering the most seen in the past 5 years", "description": "Exploit-Kit is an enumeration of some exploitation kits used by adversaries. The list includes document, browser and router exploit kits.It's not meant to be totally exhaustive but aim at covering the most seen in the past 5 years",

View file

@ -4,21 +4,27 @@
"value": "PROMETHIUM", "value": "PROMETHIUM",
"description": "PROMETHIUM is an activity group that has been active as early as 2012. The group primarily uses Truvasys, a first-stage malware that has been in circulation for several years. Truvasys has been involved in several attack campaigns, where it has masqueraded as one of server common computer utilities, including WinUtils, TrueCrypt, WinRAR, or SanDisk. In each of the campaigns, Truvasys malware evolved with additional features—this shows a close relationship between the activity groups behind the campaigns and the developers of the malware.", "description": "PROMETHIUM is an activity group that has been active as early as 2012. The group primarily uses Truvasys, a first-stage malware that has been in circulation for several years. Truvasys has been involved in several attack campaigns, where it has masqueraded as one of server common computer utilities, including WinUtils, TrueCrypt, WinRAR, or SanDisk. In each of the campaigns, Truvasys malware evolved with additional features—this shows a close relationship between the activity groups behind the campaigns and the developers of the malware.",
"meta": { "meta": {
"refs": ["https://blogs.technet.microsoft.com/mmpc/2016/12/14/twin-zero-day-attacks-promethium-and-neodymium-target-individuals-in-europe/"] "refs": [
} "https://blogs.technet.microsoft.com/mmpc/2016/12/14/twin-zero-day-attacks-promethium-and-neodymium-target-individuals-in-europe/"
]
}
}, },
{ {
"value": "NEODYMIUM", "value": "NEODYMIUM",
"description": "NEODYMIUM is an activity group that is known to use a backdoor malware detected by Microsoft as Wingbird. This backdoors characteristics closely match FinFisher, a government-grade commercial surveillance package. Data about Wingbird activity indicate that it is typically used to attack individual computers instead of networks.", "description": "NEODYMIUM is an activity group that is known to use a backdoor malware detected by Microsoft as Wingbird. This backdoors characteristics closely match FinFisher, a government-grade commercial surveillance package. Data about Wingbird activity indicate that it is typically used to attack individual computers instead of networks.",
"meta": { "meta": {
"refs": ["https://blogs.technet.microsoft.com/mmpc/2016/12/14/twin-zero-day-attacks-promethium-and-neodymium-target-individuals-in-europe/"] "refs": [
} "https://blogs.technet.microsoft.com/mmpc/2016/12/14/twin-zero-day-attacks-promethium-and-neodymium-target-individuals-in-europe/"
]
}
}, },
{ {
"value": "TERBIUM", "value": "TERBIUM",
"description": "Microsoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to organizations in the energy sector. Microsoft Threat Intelligence refers to the activity group behind these attacks as TERBIUM, following our internal practice of assigning rogue actors chemical element names.", "description": "Microsoft Threat Intelligence identified similarities between this recent attack and previous 2012 attacks against tens of thousands of computers belonging to organizations in the energy sector. Microsoft Threat Intelligence refers to the activity group behind these attacks as TERBIUM, following our internal practice of assigning rogue actors chemical element names.",
"meta" : { "meta": {
"refs": ["https://blogs.technet.microsoft.com/mmpc/2016/12/09/windows-10-protection-detection-and-response-against-recent-attacks/"] "refs": [
"https://blogs.technet.microsoft.com/mmpc/2016/12/09/windows-10-protection-detection-and-response-against-recent-attacks/"
]
} }
}, },
{ {
@ -36,7 +42,7 @@
"Group-4127", "Group-4127",
"Sofacy", "Sofacy",
"Grey-Cloud" "Grey-Cloud"
], ],
"country": "RU", "country": "RU",
"refs": [ "refs": [
"https://blogs.technet.microsoft.com/mmpc/2016/11/01/our-commitment-to-our-customers-security/", "https://blogs.technet.microsoft.com/mmpc/2016/11/01/our-commitment-to-our-customers-security/",
@ -74,14 +80,19 @@
"value": "BARIUM", "value": "BARIUM",
"description": "Microsoft Threat Intelligence associates Winnti with multiple activity groups—collections of malware, supporting infrastructure, online personas, victimology, and other attack artifacts that the Microsoft intelligent security graph uses to categorize and attribute threat activity. Microsoft labels activity groups using code names derived from elements in the periodic table. In the case of this malware, the activity groups strongly associated with Winnti are BARIUM and LEAD. But even though they share the use of Winnti, the BARIUM and LEAD activity groups are involved in very different intrusion scenarios. BARIUM begins its attacks by cultivating relationships with potential victims—particularly those working in Business Development or Human Resources—on various social media platforms. Once BARIUM has established rapport, they spear-phish the victim using a variety of unsophisticated malware installation vectors, including malicious shortcut (.lnk) files with hidden payloads, compiled HTML help (.chm) files, or Microsoft Office documents containing macros or exploits. Initial intrusion stages feature the Win32/Barlaiy implant—notable for its use of social network profiles, collaborative document editing sites, and blogs for C&C. Later stages of the intrusions rely upon Winnti for persistent access. The majority of victims recorded to date have been in electronic gaming, multimedia, and Internet content industries, although occasional intrusions against technology companies have occurred.", "description": "Microsoft Threat Intelligence associates Winnti with multiple activity groups—collections of malware, supporting infrastructure, online personas, victimology, and other attack artifacts that the Microsoft intelligent security graph uses to categorize and attribute threat activity. Microsoft labels activity groups using code names derived from elements in the periodic table. In the case of this malware, the activity groups strongly associated with Winnti are BARIUM and LEAD. But even though they share the use of Winnti, the BARIUM and LEAD activity groups are involved in very different intrusion scenarios. BARIUM begins its attacks by cultivating relationships with potential victims—particularly those working in Business Development or Human Resources—on various social media platforms. Once BARIUM has established rapport, they spear-phish the victim using a variety of unsophisticated malware installation vectors, including malicious shortcut (.lnk) files with hidden payloads, compiled HTML help (.chm) files, or Microsoft Office documents containing macros or exploits. Initial intrusion stages feature the Win32/Barlaiy implant—notable for its use of social network profiles, collaborative document editing sites, and blogs for C&C. Later stages of the intrusions rely upon Winnti for persistent access. The majority of victims recorded to date have been in electronic gaming, multimedia, and Internet content industries, although occasional intrusions against technology companies have occurred.",
"meta": { "meta": {
"refs": ["https://blogs.technet.microsoft.com/mmpc/2017/01/25/detecting-threat-actors-in-recent-german-industrial-attacks-with-windows-defender-atp/"] "refs": [
"https://blogs.technet.microsoft.com/mmpc/2017/01/25/detecting-threat-actors-in-recent-german-industrial-attacks-with-windows-defender-atp/"
]
} }
}, },
{ {
"value": "LEAD", "value": "LEAD",
"description": "In contrast, LEAD has established a far greater reputation for industrial espionage. In the past few years, LEADs victims have included: Multinational, multi-industry companies involved in the manufacture of textiles, chemicals, and electronics Pharmaceutical companies A company in the chemical industry University faculty specializing in aeronautical engineering and research A company involved in the design and manufacture of motor vehicles A cybersecurity company focusing on protecting industrial control systems During these intrusions, LEADs objective was to steal sensitive data, including research materials, process documents, and project plans. LEAD also steals code-signing certificates to sign its malware in subsequent attacks. In most cases, LEADs attacks do not feature any advanced exploit techniques. The group also does not make special effort to cultivate victims prior to an attack. Instead, the group often simply emails a Winnti installer to potential victims, relying on basic social engineering tactics to convince recipients to run the attached malware. In some other cases, LEAD gains access to a target by brute-forcing remote access login credentials, performing SQL injection, or exploiting unpatched web servers, and then they copy the Winnti installer directly to compromised machines.", "description": "In contrast, LEAD has established a far greater reputation for industrial espionage. In the past few years, LEADs victims have included: Multinational, multi-industry companies involved in the manufacture of textiles, chemicals, and electronics Pharmaceutical companies A company in the chemical industry University faculty specializing in aeronautical engineering and research A company involved in the design and manufacture of motor vehicles A cybersecurity company focusing on protecting industrial control systems During these intrusions, LEADs objective was to steal sensitive data, including research materials, process documents, and project plans. LEAD also steals code-signing certificates to sign its malware in subsequent attacks. In most cases, LEADs attacks do not feature any advanced exploit techniques. The group also does not make special effort to cultivate victims prior to an attack. Instead, the group often simply emails a Winnti installer to potential victims, relying on basic social engineering tactics to convince recipients to run the attached malware. In some other cases, LEAD gains access to a target by brute-forcing remote access login credentials, performing SQL injection, or exploiting unpatched web servers, and then they copy the Winnti installer directly to compromised machines.",
"meta": { "meta": {
"refs": ["https://blogs.technet.microsoft.com/mmpc/2017/01/25/detecting-threat-actors-in-recent-german-industrial-attacks-with-windows-defender-atp/"] } "refs": [
"https://blogs.technet.microsoft.com/mmpc/2017/01/25/detecting-threat-actors-in-recent-german-industrial-attacks-with-windows-defender-atp/"
]
}
} }
], ],
"name": "Microsoft Activity Group actor", "name": "Microsoft Activity Group actor",
@ -94,4 +105,3 @@
"uuid": "28b5e55d-acba-4748-a79d-0afa3512689a", "uuid": "28b5e55d-acba-4748-a79d-0afa3512689a",
"version": 2 "version": 2
} }

View file

@ -1,72 +1,73 @@
{ {
"values": [ "values": [
{ "value": "Keitaro", {
"value": "Keitaro",
"description": "Keitaro TDS is among the mostly used TDS in drive by infection chains", "description": "Keitaro TDS is among the mostly used TDS in drive by infection chains",
"meta": { "meta": {
"refs": [ "refs": [
"https://keitarotds.com/" "https://keitarotds.com/"
] ]
}, },
"type":"Commercial" "type": "Commercial"
} },
, {
{ "value": "Sutra", "value": "Sutra",
"description": "Sutra TDS was dominant from 2012 till 2015", "description": "Sutra TDS was dominant from 2012 till 2015",
"meta": { "meta": {
"refs": [ "refs": [
"http://kytoon.com/sutra-tds.html" "http://kytoon.com/sutra-tds.html"
], ],
"type":"Commercial" "type": "Commercial"
} }
} },
, {
{ "value": "SimpleTDS", "value": "SimpleTDS",
"description": "SimpleTDS is a basic open source TDS", "description": "SimpleTDS is a basic open source TDS",
"meta": { "meta": {
"refs": [ "refs": [
"https://sourceforge.net/projects/simpletds/" "https://sourceforge.net/projects/simpletds/"
], ],
"synonyms": [ "synonyms": [
"Stds" "Stds"
], ],
"type":"OpenSource" "type": "OpenSource"
} }
} },
, {
{ "value": "BossTDS", "value": "BossTDS",
"description": "BossTDS", "description": "BossTDS",
"meta": { "meta": {
"refs": [ "refs": [
"http://bosstds.com/" "http://bosstds.com/"
], ],
"type":"Commercial" "type": "Commercial"
} }
} },
, {
{ "value": "BlackHat TDS", "value": "BlackHat TDS",
"description": "BlackHat TDS is sold underground.", "description": "BlackHat TDS is sold underground.",
"meta": { "meta": {
"refs": [ "refs": [
"http://malware.dontneedcoffee.com/2014/04/meet-blackhat-tds.html" "http://malware.dontneedcoffee.com/2014/04/meet-blackhat-tds.html"
], ],
"type":"Underground" "type": "Underground"
} }
} },
, {
{ "value": "Futuristic TDS", "value": "Futuristic TDS",
"description": "Futuristic TDS is the TDS component of BlackOS/CookieBomb/NorthTale Iframer", "description": "Futuristic TDS is the TDS component of BlackOS/CookieBomb/NorthTale Iframer",
"meta": { "meta": {
"type":"Underground" "type": "Underground"
} }
} },
, {
{ "value": "Orchid TDS", "value": "Orchid TDS",
"description": "Orchid TDS was sold underground. Rare usage", "description": "Orchid TDS was sold underground. Rare usage",
"meta": { "meta": {
"type":"Underground" "type": "Underground"
} }
} }
], ],
"version": 1, "version": 1,
"uuid": "ab5fffaa-c5f6-11e6-9d9d-cec0c932ce01", "uuid": "ab5fffaa-c5f6-11e6-9d9d-cec0c932ce01",
"description": "TDS is a list of Traffic Direction System used by adversaries", "description": "TDS is a list of Traffic Direction System used by adversaries",

View file

@ -435,7 +435,7 @@
"Motive": "Espionage" "Motive": "Espionage"
}, },
"value": "Anchor Panda", "value": "Anchor Panda",
"Description": "PLA Navy" "description": "PLA Navy"
}, },
{ {
"meta": { "meta": {
@ -990,24 +990,28 @@
"description": "Group targeting Indian Army or related assets in India. Attribution to a Pakistani connection has been made by TrendMicro." "description": "Group targeting Indian Army or related assets in India. Attribution to a Pakistani connection has been made by TrendMicro."
}, },
{ {
"refs": [ "meta": {
"https://citizenlab.org/2016/05/stealth-falcon/" "refs": [
], "https://citizenlab.org/2016/05/stealth-falcon/"
"country": "UAE", ],
"synonyms": [
"FruityArmor"
],
"country": "UAE"
},
"value": "Stealth Falcon", "value": "Stealth Falcon",
"description": "Group targeting Emirati journalists, activists, and dissidents.", "description": "Group targeting Emirati journalists, activists, and dissidents."
"synonyms": [
"FruityArmor"
]
}, },
{ {
"synonyms": [ "meta": {
"Operation Daybreak", "synonyms": [
"Operation Erebus" "Operation Daybreak",
], "Operation Erebus"
"refs": [ ],
"https://securelist.com/blog/research/75082/cve-2016-4171-adobe-flash-zero-day-used-in-targeted-attacks/" "refs": [
], "https://securelist.com/blog/research/75082/cve-2016-4171-adobe-flash-zero-day-used-in-targeted-attacks/"
]
},
"value": "ScarCruft", "value": "ScarCruft",
"description": "ScarCruft is a relatively new APT group; victims have been observed in several countries, including Russia, Nepal, South Korea, China, India, Kuwait and Romania. The group has several ongoing operations utilizing multiple exploits — two for Adobe Flash and one for Microsoft Internet Explorer." "description": "ScarCruft is a relatively new APT group; victims have been observed in several countries, including Russia, Nepal, South Korea, China, India, Kuwait and Romania. The group has several ongoing operations utilizing multiple exploits — two for Adobe Flash and one for Microsoft Internet Explorer."
}, },
@ -1356,14 +1360,18 @@
"description": "The Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophisticated cyber attack groups in the world, operating alongside but always from a position of superiority with the creators of Stuxnet and Flame", "description": "The Equation Group is a highly sophisticated threat actor described by its discoverers at Kaspersky Labs as one of the most sophisticated cyber attack groups in the world, operating alongside but always from a position of superiority with the creators of Stuxnet and Flame",
"meta": { "meta": {
"country": "US", "country": "US",
"refs": ["https://en.wikipedia.org/wiki/Equation_Group"] "refs": [
"https://en.wikipedia.org/wiki/Equation_Group"
]
} }
}, },
{ {
"value": "Greenbug", "value": "Greenbug",
"description": "Greenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, government, investment, and education sectors.", "description": "Greenbug was discovered targeting a range of organizations in the Middle East including companies in the aviation, energy, government, investment, and education sectors.",
"meta": { "meta": {
"refs": ["https://www.symantec.com/connect/blogs/greenbug-cyberespionage-group-targeting-middle-east-possible-links-shamoon"] "refs": [
"https://www.symantec.com/connect/blogs/greenbug-cyberespionage-group-targeting-middle-east-possible-links-shamoon"
]
} }
} }
], ],
@ -1379,5 +1387,5 @@
], ],
"description": "Known or estimated adversary groups targeting organizations and employees. Adversary groups are regularly confused with their initial operation or campaign.", "description": "Known or estimated adversary groups targeting organizations and employees. Adversary groups are regularly confused with their initial operation or campaign.",
"uuid": "7cdff317-a673-4474-84ec-4f1754947823", "uuid": "7cdff317-a673-4474-84ec-4f1754947823",
"version": 13 "version": 14
} }

View file

@ -48,23 +48,13 @@
"value": "ZeGhost" "value": "ZeGhost"
}, },
{ {
"value": "Backdoor.Dripion", "value": "Elise Backdoor",
"description": "Backdoor.Dripion was custom developed, deployed in a highly targeted fashion, and used command and control servers disguised as antivirus company websites.",
"meta": { "meta": {
"refs": [
"http://www.symantec.com/connect/blogs/taiwan-targeted-new-cyberespionage-back-door-trojan"
],
"synonyms": [ "synonyms": [
"Dripion" "Elise"
] ]
} }
}, },
{
"value": "Elise Backdoor",
"synonyms": [
"Elise"
]
},
{ {
"value": "Trojan.Laziok", "value": "Trojan.Laziok",
"meta": { "meta": {
@ -104,7 +94,7 @@
}, },
{ {
"value": "Lost Door RAT", "value": "Lost Door RAT",
"descriptions": "We recently came across a cyber attack that used a remote access Trojan (RAT) called Lost Door, a tool currently offered on social media sites. What also struck us the most about this RAT (detected as BKDR_LODORAT.A) is how it abuses the Port Forward feature in routers.", "description": "We recently came across a cyber attack that used a remote access Trojan (RAT) called Lost Door, a tool currently offered on social media sites. What also struck us the most about this RAT (detected as BKDR_LODORAT.A) is how it abuses the Port Forward feature in routers.",
"meta": { "meta": {
"synonyms": [ "synonyms": [
"LostDoor RAT" "LostDoor RAT"
@ -210,8 +200,13 @@
"value": "Wipbot", "value": "Wipbot",
"description": "Waterbug is the name given to the actors who use the malware tools Trojan.Wipbot (also known as Tavdig and Epic Turla)", "description": "Waterbug is the name given to the actors who use the malware tools Trojan.Wipbot (also known as Tavdig and Epic Turla)",
"meta": { "meta": {
"synonyms": ["Tavdig", "Epic Turla"], "synonyms": [
"refs": ["https://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/waterbug-attack-group.pdf"] "Tavdig",
"Epic Turla"
],
"refs": [
"https://www.symantec.com/content/en/us/enterprise/media/security_response/whitepapers/waterbug-attack-group.pdf"
]
} }
}, },
{ {
@ -440,9 +435,14 @@
"value": "Regin", "value": "Regin",
"description": "Regin (also known as Prax or WarriorPride) is a sophisticated malware toolkit revealed by Kaspersky Lab, Symantec, and The Intercept in November 2014. The malware targets specific users of Microsoft Windows-based computers and has been linked to the US intelligence gathering agency NSA and its British counterpart, the GCHQ. The Intercept provided samples of Regin for download including malware discovered at Belgian telecommunications provider, Belgacom. Kaspersky Lab says it first became aware of Regin in spring 2012, but that some of the earliest samples date from 2003. The name Regin is first found on the VirusTotal website on 9 March 2011.", "description": "Regin (also known as Prax or WarriorPride) is a sophisticated malware toolkit revealed by Kaspersky Lab, Symantec, and The Intercept in November 2014. The malware targets specific users of Microsoft Windows-based computers and has been linked to the US intelligence gathering agency NSA and its British counterpart, the GCHQ. The Intercept provided samples of Regin for download including malware discovered at Belgian telecommunications provider, Belgacom. Kaspersky Lab says it first became aware of Regin in spring 2012, but that some of the earliest samples date from 2003. The name Regin is first found on the VirusTotal website on 9 March 2011.",
"meta": { "meta": {
"refs": ["https://en.wikipedia.org/wiki/Regin_(malware)"], "refs": [
"synonyms": ["Prax","WarriorPride"] "https://en.wikipedia.org/wiki/Regin_(malware)"
} ],
"synonyms": [
"Prax",
"WarriorPride"
]
}
}, },
{ {
"value": "Duqu" "value": "Duqu"
@ -925,9 +925,11 @@
{ {
"value": "Odinaff", "value": "Odinaff",
"description": "Odinaff is typically deployed in the first stage of an attack, to gain a foothold onto the network, providing a persistent presence and the ability to install additional tools onto the target network. These additional tools bear the hallmarks of a sophisticated attacker which has plagued the financial industry since at least 2013Carbanak. This new wave of attacks has also used some infrastructure that has previously been used in Carbanak campaigns.", "description": "Odinaff is typically deployed in the first stage of an attack, to gain a foothold onto the network, providing a persistent presence and the ability to install additional tools onto the target network. These additional tools bear the hallmarks of a sophisticated attacker which has plagued the financial industry since at least 2013Carbanak. This new wave of attacks has also used some infrastructure that has previously been used in Carbanak campaigns.",
"refs": [ "meta": {
"https://www.symantec.com/connect/blogs/odinaff-new-trojan-used-high-level-financial-attacks" "refs": [
] "https://www.symantec.com/connect/blogs/odinaff-new-trojan-used-high-level-financial-attacks"
]
}
}, },
{ {
"value": "Hworm", "value": "Hworm",
@ -1167,13 +1169,13 @@
}, },
{ {
"value": "DownRage", "value": "DownRage",
"synonyms": [
"Carberplike"
],
"meta": { "meta": {
"refs": [ "refs": [
"https://labsblog.f-secure.com/2015/09/08/sofacy-recycles-carberp-and-metasploit-code/", "https://labsblog.f-secure.com/2015/09/08/sofacy-recycles-carberp-and-metasploit-code/",
"https://twitter.com/Timo_Steffens/status/814781584536719360" "https://twitter.com/Timo_Steffens/status/814781584536719360"
],
"synonyms": [
"Carberplike"
] ]
} }
}, },
@ -1247,61 +1249,78 @@
"value": "MM Core" "value": "MM Core"
}, },
{ {
"meta": { "meta": {
"refs": ["https://en.wikipedia.org/wiki/Shamoon"] "refs": [
}, "https://en.wikipedia.org/wiki/Shamoon"
"description": "Shamoon,[a] also known as Disttrack, is a modular computer virus discovered by Seculert[1] in 2012, targeting recent NT kernel-based versions of Microsoft Windows. The virus has been used for cyber espionage in the energy sector.[2][3][4] Its discovery was announced on 16 August 2012 by Symantec,[3] Kaspersky Lab,[5] and Seculert.[6] Similarities have been highlighted by Kaspersky Lab and Seculert between Shamoon and the Flame malware.[5][6]", ]
"value": "Shamoon" },
}, "description": "Shamoon,[a] also known as Disttrack, is a modular computer virus discovered by Seculert[1] in 2012, targeting recent NT kernel-based versions of Microsoft Windows. The virus has been used for cyber espionage in the energy sector.[2][3][4] Its discovery was announced on 16 August 2012 by Symantec,[3] Kaspersky Lab,[5] and Seculert.[6] Similarities have been highlighted by Kaspersky Lab and Seculert between Shamoon and the Flame malware.[5][6]",
{ "value": "Shamoon"
"value": "GhostAdmin",
"description": "According to MalwareHunterTeam and other researchers that have looked at the malware's source code, GhostAdmin seems to be a reworked version of CrimeScene, another botnet malware family that was active around 3-4 years ago.",
"meta": {
"refs": ["https://www.bleepingcomputer.com/news/security/new-ghostadmin-malware-used-for-data-theft-and-exfiltration/"]
}
}, },
{ {
"value": " EyePyramid Malware", "value": "GhostAdmin",
"description": "Two Italians referred to as the “Occhionero brothers” have been arrested and accused of using malware and a carefully-prepared spear-phishing scheme to spy on high-profile politicians and businessmen. This case has been called “EyePyramid”, which we first discussed last week. (Conspiracy theories aside, the name came from a domain name and directory path that was found during the research.)", "description": "According to MalwareHunterTeam and other researchers that have looked at the malware's source code, GhostAdmin seems to be a reworked version of CrimeScene, another botnet malware family that was active around 3-4 years ago.",
"meta": { "meta": {
"refs": ["http://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-inner-workings-eyepyramid/"], "refs": [
"country": "IT" "https://www.bleepingcomputer.com/news/security/new-ghostadmin-malware-used-for-data-theft-and-exfiltration/"
} ]
}
}, },
{ {
"value": "LuminosityLink", "value": " EyePyramid Malware",
"description": "LuminosityLink is a malware family costing $40 that purports to be a system administration utility", "description": "Two Italians referred to as the “Occhionero brothers” have been arrested and accused of using malware and a carefully-prepared spear-phishing scheme to spy on high-profile politicians and businessmen. This case has been called “EyePyramid”, which we first discussed last week. (Conspiracy theories aside, the name came from a domain name and directory path that was found during the research.)",
"meta": { "meta": {
"refs": ["http://researchcenter.paloaltonetworks.com/2016/07/unit42-investigating-the-luminositylink-remote-access-trojan-configuration/"] "refs": [
} "http://blog.trendmicro.com/trendlabs-security-intelligence/uncovering-inner-workings-eyepyramid/"
],
"country": "IT"
}
}, },
{ {
"value": "Flokibot", "value": "LuminosityLink",
"description": "Floki Bot, described recently by Dr. Peter Stephenson from SC Magazine, is yet another bot based on the leaked Zeus code. However, the author came up with various custom modifications that makes it more interesting.", "description": "LuminosityLink is a malware family costing $40 that purports to be a system administration utility",
"meta": { "meta": {
"refs": ["https://www.arbornetworks.com/blog/asert/flokibot-flock-bots/", "https://blog.malwarebytes.com/threat-analysis/2016/11/floki-bot-and-the-stealthy-dropper/"], "refs": [
"synonyms": ["Floki Bot"] "http://researchcenter.paloaltonetworks.com/2016/07/unit42-investigating-the-luminositylink-remote-access-trojan-configuration/"
} ]
}
}, },
{ {
"value": "ZeroT", "value": "Flokibot",
"description": "Most recently, we have observed the same group targeting military and aerospace interests in Russia and Belarus. Since the summer of 2016, this group began using a new downloader known as ZeroT to install the PlugX remote access Trojan (RAT) and added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails.", "description": "Floki Bot, described recently by Dr. Peter Stephenson from SC Magazine, is yet another bot based on the leaked Zeus code. However, the author came up with various custom modifications that makes it more interesting.",
"meta": { "meta": {
"refs": ["https://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx"] "refs": [
} "https://www.arbornetworks.com/blog/asert/flokibot-flock-bots/",
"https://blog.malwarebytes.com/threat-analysis/2016/11/floki-bot-and-the-stealthy-dropper/"
],
"synonyms": [
"Floki Bot"
]
}
}, },
{ {
"value": "StreamEx", "value": "ZeroT",
"description": "Cylance dubbed this family of malware StreamEx, based upon a common exported function used across all samples stream, combined with the dropper functionality to append ex to the DLL file name. The StreamEx family has the ability to access and modify the users file system, modify the registry, create system services, enumerate process and system information, enumerate network resources and drive types, scan for security tools such as firewall products and antivirus products, change browser security settings, and remotely execute commands. The malware documented in this post was predominantly 64-bit, however, there are 32-bit versions of the malware in the wild. ", "description": "Most recently, we have observed the same group targeting military and aerospace interests in Russia and Belarus. Since the summer of 2016, this group began using a new downloader known as ZeroT to install the PlugX remote access Trojan (RAT) and added Microsoft Compiled HTML Help (.chm) as one of the initial droppers delivered in spear-phishing emails.",
"meta": { "meta": {
"refs": ["https://blog.cylance.com/shell-crew-variants-continue-to-fly-under-big-avs-radar"] "refs": [
} "https://www.proofpoint.com/us/threat-insight/post/APT-targets-russia-belarus-zerot-plugx"
]
}
},
{
"value": "StreamEx",
"description": "Cylance dubbed this family of malware StreamEx, based upon a common exported function used across all samples stream, combined with the dropper functionality to append ex to the DLL file name. The StreamEx family has the ability to access and modify the users file system, modify the registry, create system services, enumerate process and system information, enumerate network resources and drive types, scan for security tools such as firewall products and antivirus products, change browser security settings, and remotely execute commands. The malware documented in this post was predominantly 64-bit, however, there are 32-bit versions of the malware in the wild. ",
"meta": {
"refs": [
"https://blog.cylance.com/shell-crew-variants-continue-to-fly-under-big-avs-radar"
]
}
} }
], ],
"version": 19, "version": 21,
"uuid": "0d821b68-9d82-4c6d-86a6-1071a9e0f79f", "uuid": "0d821b68-9d82-4c6d-86a6-1071a9e0f79f",
"description": "threat-actor-tools is an enumeration of tools used by adversaries. The list includes malware but also common software regularly used by the adversaries.", "description": "threat-actor-tools is an enumeration of tools used by adversaries. The list includes malware but also common software regularly used by the adversaries.",
"author": [ "authors": [
"Alexandre Dulaunoy", "Alexandre Dulaunoy",
"Florian Roth", "Florian Roth",
"Timo Steffens", "Timo Steffens",

View file

@ -5,7 +5,7 @@ set -x
# Seeds sponge, from moreutils # Seeds sponge, from moreutils
for dir in galaxies/*.json for dir in clusters/*.json
do do
cat ${dir} | jq . | sponge ${dir} cat ${dir} | jq . | sponge ${dir}
done done

View file

@ -12,7 +12,7 @@ if ! [ $diffs -eq 0 ]; then
exit 1 exit 1
fi fi
for dir in galaxies/*.json for dir in clusters/*.json
do do
echo -n "${dir}: " echo -n "${dir}: "
jsonschema -i ${dir} schema.json jsonschema -i ${dir} schema.json