"value":"Ransomware is often in the headlines as new families are discovered on an almost weekly basis. Historically, these families have shared one similarity \u00e2\u20ac\u201c they have all been deployed by attackers casting a wide net and largely being victim-agnostic. In most cases, the adversaries have used phishing emails and exploit kits in a \u00e2\u20ac\u02dcspray and pray\u00e2\u20ac\u2122 style tactic.\r\n\r\nHowever, in recent months, a new trend seems to be emerging: targeted attacks where ransomware is deployed by threat actors after successfully gaining unauthorized access to an organization\u00e2\u20ac\u2122s network. One malware family seen in such attacks is known as \u00e2\u20ac\u02dcSamSa\u00e2\u20ac\u2122, \u00e2\u20ac\u02dcSamas\u00e2\u20ac\u2122, \u00e2\u20ac\u02dcsamsam\u00e2\u20ac\u2122, or most recently, \u00e2\u20ac\u02dcMOKOPONI\u00e2\u20ac\u2122. Reports on this malware family have previously been published by both Intel Security and Microsoft.\r\n\r\nPalo Alto Networks has collected over 20 samples of this particular malware family, and we have identified over $70,000 USD in Bitcoin payments to the attacker (Cisco Talos yesterday reported this figure to be closer to $115,000 USD). This blog details the evolution of this malware family, which was first witnessed in December 2015, as well as provides various indicators of compromise (IOCs) that can be used by the security community."
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850433",
"to_ids":false,
"type":"btc",
"uuid":"56f44a81-2460-4719-ab16-47d9950d210f",
"value":"1Gmjyb9wd6Ju9phn5tREmLYwPsPFusqEx6"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850433",
"to_ids":false,
"type":"btc",
"uuid":"56f44a81-65c4-45bb-be49-4b78950d210f",
"value":"1FpZFUGqAkyjAGVgHXhaHrSmThJHxd2a7v"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850434",
"to_ids":false,
"type":"btc",
"uuid":"56f44a82-f890-4703-8d34-4ff3950d210f",
"value":"19CbDoaZDLTzkkT1uQrMPM42AUvfQN4Kds"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850434",
"to_ids":false,
"type":"btc",
"uuid":"56f44a82-defc-4edc-968e-475e950d210f",
"value":"1FESb2caoXp27gEgVhyoCGHSkGhGwkzJbF"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850434",
"to_ids":false,
"type":"btc",
"uuid":"56f44a82-ee80-415b-8091-44bc950d210f",
"value":"1JnxLRQSHkCw5aEhu5VQptUq4XmxntAvL2"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850435",
"to_ids":false,
"type":"btc",
"uuid":"56f44a83-5d6c-40b8-8785-459e950d210f",
"value":"1KVvqPi5QivfH3SKFpFWbeRwjdKREPYoAv"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850435",
"to_ids":false,
"type":"btc",
"uuid":"56f44a83-a97c-497a-8292-4983950d210f",
"value":"175wjzT5M7XvYYW447ry4TQmHUfzTrBUcN"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850435",
"to_ids":false,
"type":"btc",
"uuid":"56f44a83-7318-4439-8f24-41f5950d210f",
"value":"1Cn4YXWmjARbK459hGQz54g3KTQLB7XYZs"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850435",
"to_ids":false,
"type":"btc",
"uuid":"56f44a83-ad88-4eab-bce4-4939950d210f",
"value":"1KwgwwWdoL9VFcg9VuCDGBiVZ2LNzGnrov"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850436",
"to_ids":false,
"type":"btc",
"uuid":"56f44a84-2a24-4375-8d54-4623950d210f",
"value":"1ETLG9xnFwZ1H9xaHz6u4MX8KYvWJesMab"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850436",
"to_ids":false,
"type":"btc",
"uuid":"56f44a84-0d70-4ca3-b2c8-4638950d210f",
"value":"1D6ScsG2BmZu3VFDEgfnMC6CzjnWtZi6Kj"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850436",
"to_ids":false,
"type":"btc",
"uuid":"56f44a84-8c44-44a7-9ce5-4070950d210f",
"value":"1C9YUWk2iKAxjdvcysyA1C7xzR7evhr2qA"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850437",
"to_ids":false,
"type":"btc",
"uuid":"56f44a85-1374-4bf1-aa35-4637950d210f",
"value":"1AFoh41i1s56Tc2cRnwvJv1Hx8YfvbWxbh"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850437",
"to_ids":false,
"type":"btc",
"uuid":"56f44a85-2fd4-4c49-8bde-4361950d210f",
"value":"136hcUpNwhpKQQL7iXXWmwUnikX7n98xsL"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850437",
"to_ids":false,
"type":"btc",
"uuid":"56f44a85-0c9c-4953-b132-45b4950d210f",
"value":"1KakTJ8dpYFSnBohLakqMHKonZ4HGo3ur5"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850437",
"to_ids":false,
"type":"btc",
"uuid":"56f44a85-42cc-4547-9cf9-4062950d210f",
"value":"1FDj6HsedzPNgVKTAHznsHUg4pKnGRarH6"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850438",
"to_ids":false,
"type":"btc",
"uuid":"56f44a86-4cfc-4b9c-bdc3-4581950d210f",
"value":"15HUUDBjLD34XfCu6YtafT7ARSt2TBrLBe"
},
{
"category":"Financial fraud",
"comment":"By tracking the unique BTC addresses found within all of the collected samples, we were able to determine when victims made specific payments. The following table shows payments made to the various BTC wallets:",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850438",
"to_ids":false,
"type":"btc",
"uuid":"56f44a86-566c-4c88-ac6d-4b11950d210f",
"value":"1EzpHEojHsLkHTExyz45Tw6L7FNiaeyZdm"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850543",
"to_ids":true,
"type":"hostname",
"uuid":"56f44aef-5d90-41b6-ad31-4c4c950d210f",
"value":"zeushelpu.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850543",
"to_ids":true,
"type":"hostname",
"uuid":"56f44aef-7e58-4c79-99bb-4b81950d210f",
"value":"lordsecure4u.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850543",
"to_ids":true,
"type":"hostname",
"uuid":"56f44aef-dc20-4d01-9602-4380950d210f",
"value":"key88secu7.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850544",
"to_ids":true,
"type":"hostname",
"uuid":"56f44af0-2020-4c66-8360-4952950d210f",
"value":"helpbyangel0.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850544",
"to_ids":true,
"type":"hostname",
"uuid":"56f44af0-5a34-42a8-8426-47fa950d210f",
"value":"payforsecure7.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850544",
"to_ids":true,
"type":"hostname",
"uuid":"56f44af0-f7d0-4823-a54b-43d3950d210f",
"value":"followsec7.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850545",
"to_ids":true,
"type":"hostname",
"uuid":"56f44af1-8b80-4f88-9078-4bfe950d210f",
"value":"union83939k.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850545",
"to_ids":true,
"type":"hostname",
"uuid":"56f44af1-ac98-463e-be8d-48ef950d210f",
"value":"evilsecure9.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850545",
"to_ids":true,
"type":"hostname",
"uuid":"56f44af1-5d70-4317-8245-4eac950d210f",
"value":"keytwocode.wordpress.com"
},
{
"category":"Network activity",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850545",
"to_ids":true,
"type":"hostname",
"uuid":"56f44af1-cf70-401f-9c80-4b6e950d210f",
"value":"secangel7d.wordpress.com"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850745",
"to_ids":true,
"type":"md5",
"uuid":"56f44bb9-d190-43a7-b1ca-44ac950d210f",
"value":"eafe6a35062cc12378c08f9dd10cd396"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850745",
"to_ids":true,
"type":"md5",
"uuid":"56f44bb9-d964-4ea3-923d-4eb0950d210f",
"value":"2c49a8fdc32be8983c67ea4fd0faac4d"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850746",
"to_ids":true,
"type":"md5",
"uuid":"56f44bba-0ce4-4cc3-b768-41bc950d210f",
"value":"4851e63304b03dc8e941840186c11679"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850746",
"to_ids":true,
"type":"md5",
"uuid":"56f44bba-edbc-4e74-a873-44d0950d210f",
"value":"be25dffca730684e4db0ed04f809f6c0"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850747",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbb-0594-4fab-9152-4e76950d210f",
"value":"555051b46fe667131d5e873e2e59f1b1"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850747",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbb-0f88-4d19-b8f6-40e8950d210f",
"value":"4bdab54848d8fcb10aa9daba62459334"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850748",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbc-df7c-4168-9484-468a950d210f",
"value":"a14ea969014b1145382ffcd508d10156"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850749",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbd-16ac-4e7a-a92f-4e1a950d210f",
"value":"fe998080463665412b65850828bce41f"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850749",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbd-b934-448f-9b5d-431f950d210f",
"value":"acaafbd881b130aba95ccbc2689f07db"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850750",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbe-5330-40ba-892b-4f1c950d210f",
"value":"5fd2db03fffa15744274e61479cc7ce1"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850750",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbe-0ca4-41ae-85ce-4c93950d210f",
"value":"e26c6a20139f7a45e94ce0b16e62bd03"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850751",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbf-c4e4-4577-9a4c-480b950d210f",
"value":"def637beb3911dce96fda8cdd36c1985"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850751",
"to_ids":true,
"type":"md5",
"uuid":"56f44bbf-5b84-4a45-a6dc-4ec4950d210f",
"value":"14721036e16587594ad950d4f2db5f27"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850752",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc0-f12c-40c2-95d2-453f950d210f",
"value":"3e2642aa59753ecbe82514daf2ea4e88"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850753",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc1-5800-4987-8925-4dd5950d210f",
"value":"64082dd282a8ca6b9b7c71de14a827c4"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850753",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc1-661c-4e8f-b6ea-4e64950d210f",
"value":"7eee34be62b3d03c8c9d697b1fe6d8a8"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850754",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc2-e230-4088-84dd-4df1950d210f",
"value":"4c8fb28a68168430fd447ba1b92f4f42"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850754",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc2-e850-4ff2-9a59-45f1950d210f",
"value":"1e22c58a8b677fac51cf6c1d2cd1a0e2"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850755",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc3-9fc8-4f9f-801b-4165950d210f",
"value":"9585f0c7dc287d07755e6818e1fa204c"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850755",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc3-fb18-4ead-afc4-4aae950d210f",
"value":"43049c582db85b94feed9afa7419d78c"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850756",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc4-7ff4-467e-8a64-413c950d210f",
"value":"02dce579d95a57f9e5ca0cde800dfb0f"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850757",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc5-0f24-4962-a871-4325950d210f",
"value":"868c351e29be8c6c1edde315505d938b"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import.",
"deleted":false,
"disable_correlation":false,
"timestamp":"1458850757",
"to_ids":true,
"type":"md5",
"uuid":"56f44bc5-1174-4f8b-b980-4b2d950d210f",
"value":"0d2505ce7838bb22fcd973bf3895fd27"
},
{
"category":"Payload delivery",
"comment":"Imported via the freetext import. - Xchecked via VT: 0d2505ce7838bb22fcd973bf3895fd27",