2023-04-21 13:25:09 +00:00
{
2023-12-14 14:30:15 +00:00
"Event" : {
"analysis" : "2" ,
"date" : "2016-03-10" ,
"extends_uuid" : "" ,
"info" : "OSINT - The Cerber Ransomware not only Encrypts Your Data But Also Speaks to You" ,
"publish_timestamp" : "1457596187" ,
"published" : true ,
"threat_level_id" : "3" ,
"timestamp" : "1457596013" ,
"uuid" : "56e123a7-dc1c-4c74-af4a-4d8b950d210f" ,
"Orgc" : {
"name" : "CIRCL" ,
"uuid" : "55f6ea5e-2c60-40e5-964f-47a8950d210f"
} ,
"Tag" : [
{
"colour" : "#004646" ,
"local" : "0" ,
"name" : "type:OSINT" ,
"relationship_type" : ""
} ,
{
"colour" : "#ffffff" ,
"local" : "0" ,
"name" : "tlp:white" ,
"relationship_type" : ""
} ,
{
"colour" : "#006c6c" ,
"local" : "0" ,
"name" : "ecsirt:malicious-code=\"ransomware\"" ,
"relationship_type" : ""
}
] ,
"Attribute" : [
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595388" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "56e123fc-ba64-462a-bff0-46b7950d210f" ,
"value" : "http://www.bleepingcomputer.com/news/security/the-cerber-ransomware-not-only-encrypts-your-data-but-also-speaks-to-you/"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595598" ,
"to_ids" : false ,
"type" : "comment" ,
"uuid" : "56e124ce-5acc-496c-8368-457c950d210f" ,
"value" : "A ransomware called Cerber has been floating around for about a week, but we were not able to retrieve a sample until today. Thanks to @BiebsMalwareGuy and @MeegulWorth, samples were found and further analysis of the ransomware could be done. When infected, a victim's data files will be encrypted using AES encryption and will be told they need to pay a ransom of 1.24 bitcoins or ~500 USD to get their files back. Unfortunately, at this point there is no known way to decrypt a victim's encrypted files for free.\r\n\r\nAt this time we do not currently know how the Cerber ransomware is being distributed, but according to SenseCy, it is being offered as a service on a closed underground Russian forum. This means that it is probably a new Ransomware as a Service, or RaaS, where affiliates can join in order to distribute the ransomware, while the Cerber developers earn a commission from each ransom payment."
} ,
{
"category" : "Persistence mechanism" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595762" ,
"to_ids" : false ,
"type" : "filename" ,
"uuid" : "56e12572-a3a4-40de-8e11-4f58950d210f" ,
"value" : "\"%AppData%\\{2ED2A2FE-872C-D4A0-17AC-E301404F1CBA}\\[random].exe\""
} ,
{
"category" : "Artifacts dropped" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595830" ,
"to_ids" : true ,
"type" : "filename" ,
"uuid" : "56e125b6-fed8-4d52-a48a-4676950d210f" ,
"value" : "%AppData%\\{2ED2A2FE-872C-D4A0-17AC-E301404F1CBA}\\"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595970" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "56e12642-0dac-454a-bfde-45d7950d210f" ,
"value" : "920ba9c21b519ad7dfb9075c3860d85061cede15"
} ,
{
"category" : "Payload delivery" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595970" ,
"to_ids" : true ,
"type" : "sha1" ,
"uuid" : "56e12642-0c94-49b1-8d38-4c97950d210f" ,
"value" : "0af6bde11eaa699604aa92cce9a6210dfce70f42"
} ,
{
"category" : "Payload delivery" ,
"comment" : "- Xchecked via VT: 0af6bde11eaa699604aa92cce9a6210dfce70f42" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595983" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "56e1264f-5a74-4ab0-9a0e-4e0202de0b81" ,
"value" : "a5ff5f861bbb1ac7c6fd44f303f735fac01273ce2ae43a8acb683076192fcfcc"
} ,
{
"category" : "Payload delivery" ,
"comment" : "- Xchecked via VT: 0af6bde11eaa699604aa92cce9a6210dfce70f42" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595983" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "56e1264f-7cf0-4b35-ad01-4f5402de0b81" ,
"value" : "2f7059d7b1dda3080e391d99788fff18"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595984" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "56e12650-6508-4a93-8d95-456202de0b81" ,
"value" : "https://www.virustotal.com/file/a5ff5f861bbb1ac7c6fd44f303f735fac01273ce2ae43a8acb683076192fcfcc/analysis/1457487902/"
} ,
{
"category" : "Payload delivery" ,
"comment" : "- Xchecked via VT: 920ba9c21b519ad7dfb9075c3860d85061cede15" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595984" ,
"to_ids" : true ,
"type" : "sha256" ,
"uuid" : "56e12650-dfb4-4ee8-862b-42ce02de0b81" ,
"value" : "2d08ffeba708fb833404d2c320ea4f29365c791d504181e08e3e9b529f5cf096"
} ,
{
"category" : "Payload delivery" ,
"comment" : "- Xchecked via VT: 920ba9c21b519ad7dfb9075c3860d85061cede15" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595984" ,
"to_ids" : true ,
"type" : "md5" ,
"uuid" : "56e12650-94d0-4eb5-be41-4b4b02de0b81" ,
"value" : "f5146a3bbe6c71e5a0ef2f04f955b1a1"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457595985" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "56e12651-3f8c-43b6-af08-41cd02de0b81" ,
"value" : "https://www.virustotal.com/file/2d08ffeba708fb833404d2c320ea4f29365c791d504181e08e3e9b529f5cf096/analysis/1457125203/"
} ,
{
"category" : "External analysis" ,
"comment" : "" ,
"deleted" : false ,
"disable_correlation" : false ,
"timestamp" : "1457596013" ,
"to_ids" : false ,
"type" : "link" ,
"uuid" : "56e1266d-b384-4121-afb8-47bb950d210f" ,
"value" : "http://blog.trendmicro.com/trendlabs-security-intelligence/cerber-crypto-ransomware-speaks-sold-russian-underground/"
}
2023-04-21 13:25:09 +00:00
]
2023-12-14 14:30:15 +00:00
}
2023-04-21 13:25:09 +00:00
}