mirror of
https://github.com/MISP/misp-galaxy.git
synced 2025-01-19 02:56:16 +00:00
Add SOREBRECT ransomware
This commit is contained in:
parent
dd2a51037a
commit
d01cfb8d1e
1 changed files with 16 additions and 1 deletions
|
@ -8474,12 +8474,27 @@
|
||||||
],
|
],
|
||||||
"encryption": "may be a mixture of AES and RC4.",
|
"encryption": "may be a mixture of AES and RC4.",
|
||||||
"ransomnotes": [
|
"ransomnotes": [
|
||||||
"_DECODE_FILES.txt"
|
"DECODE_FILES.txt"
|
||||||
],
|
],
|
||||||
"refs": [
|
"refs": [
|
||||||
"https://www.bleepingcomputer.com/news/security/uiwix-ransomware-using-eternalblue-smb-exploit-to-infect-victims/"
|
"https://www.bleepingcomputer.com/news/security/uiwix-ransomware-using-eternalblue-smb-exploit-to-infect-victims/"
|
||||||
]
|
]
|
||||||
}
|
}
|
||||||
|
},
|
||||||
|
{
|
||||||
|
"value": "SOREBRECT",
|
||||||
|
"description": "Fileless, Code-injecting Ransomware",
|
||||||
|
"meta": {
|
||||||
|
"extensions": [
|
||||||
|
".pr0tect"
|
||||||
|
],
|
||||||
|
"ransomnotes": [
|
||||||
|
"http://blog.trendmicro.com/trendlabs-security-intelligence/files/2017/06/SOREBRECT-3.jpg"
|
||||||
|
],
|
||||||
|
"refs": [
|
||||||
|
"http://blog.trendmicro.com/trendlabs-security-intelligence/analyzing-fileless-code-injecting-sorebrect-ransomware/"
|
||||||
|
]
|
||||||
|
}
|
||||||
}
|
}
|
||||||
],
|
],
|
||||||
"source": "Various",
|
"source": "Various",
|
||||||
|
|
Loading…
Add table
Reference in a new issue