{ "Event": { "analysis": "2", "date": "2016-10-11", "extends_uuid": "", "info": "OSINT - How Stampado Ransomware Analysis Led To Yara Improvements", "publish_timestamp": "1476169652", "published": true, "threat_level_id": "3", "timestamp": "1476169628", "uuid": "57fc8ec7-2c10-4c24-8565-452002de0b81", "Orgc": { "name": "CIRCL", "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f" }, "Tag": [ { "colour": "#3b7500", "local": "0", "name": "circl:incident-classification=\"malware\"", "relationship_type": "" }, { "colour": "#420053", "local": "0", "name": "ms-caro-malware:malware-type=\"Ransom\"", "relationship_type": "" }, { "colour": "#ffffff", "local": "0", "name": "tlp:white", "relationship_type": "" }, { "colour": "#00223b", "local": "0", "name": "osint:source-type=\"blog-post\"", "relationship_type": "" }, { "colour": "#006c6c", "local": "0", "name": "ecsirt:malicious-code=\"ransomware\"", "relationship_type": "" } ], "Attribute": [ { "category": "Artifacts dropped", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1476169466", "to_ids": true, "type": "yara", "uuid": "57fc8efa-2754-48b9-a10c-4b9902de0b81", "value": "rule stampado_overlay\r\n{\r\nmeta:\r\ndescription = \"Catches Stampado samples looking for \\\\r at the beginning of PE overlay section\"\r\nreference = \"\"\r\nauthor = \"Fernando Merces, FTR, Trend Micro\"\r\ndate = \"2016-07\"\r\nmd5 = \"a393b9536a1caa34914636d3da7378b5\"\r\nmd5 = \"dbf3707a9cd090853a11dda9cfa78ff0\"\r\nmd5 = \"dd5686ca7ec28815c3cf3ed3dbebdff2\"\r\nmd5 = \"6337f0938e4a9c0ef44ab99deb0ef466\"\r\n\r\ncondition:\r\npe.characteristics == 0x122 and\r\npe.number_of_sections == 5 and\r\npe.imports(\"VERSION.dll\", \"VerQueryValueW\") and uint8(pe.sections[4].raw_data_offset + pe.sections[4].raw_data_size) == 0x0d\r\n\r\n}" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool", "deleted": false, "disable_correlation": false, "timestamp": "1476169490", "to_ids": true, "type": "md5", "uuid": "57fc8f12-fa10-4675-b20e-467e02de0b81", "value": "a393b9536a1caa34914636d3da7378b5" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool", "deleted": false, "disable_correlation": false, "timestamp": "1476169491", "to_ids": true, "type": "md5", "uuid": "57fc8f13-b3ac-4994-a131-45eb02de0b81", "value": "dbf3707a9cd090853a11dda9cfa78ff0" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool", "deleted": false, "disable_correlation": false, "timestamp": "1476169491", "to_ids": true, "type": "md5", "uuid": "57fc8f13-c1d0-45ab-953e-446c02de0b81", "value": "dd5686ca7ec28815c3cf3ed3dbebdff2" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool", "deleted": false, "disable_correlation": false, "timestamp": "1476169491", "to_ids": true, "type": "md5", "uuid": "57fc8f13-02c4-4968-9ceb-465602de0b81", "value": "6337f0938e4a9c0ef44ab99deb0ef466" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1476169616", "to_ids": false, "type": "link", "uuid": "57fc8f90-4bbc-45ef-a3d6-43b902de0b81", "value": "http://blog.trendmicro.com/trendlabs-security-intelligence/stampado-ransomware-analysis-led-yara-improvements" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: 6337f0938e4a9c0ef44ab99deb0ef466", "deleted": false, "disable_correlation": false, "timestamp": "1476169628", "to_ids": true, "type": "sha256", "uuid": "57fc8f9c-0c5c-4198-bc44-4d6802de0b81", "value": "3f147a037baac4220a84b5fed4c167fc75cf331126735d70f67c2c8fb7f50c87" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: 6337f0938e4a9c0ef44ab99deb0ef466", "deleted": false, "disable_correlation": false, "timestamp": "1476169628", "to_ids": true, "type": "sha1", "uuid": "57fc8f9c-c388-426f-af60-488202de0b81", "value": "55e796d55c2938130ededc476ad7c92b42487cfd" }, { "category": "External analysis", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: 6337f0938e4a9c0ef44ab99deb0ef466", "deleted": false, "disable_correlation": false, "timestamp": "1476169629", "to_ids": false, "type": "link", "uuid": "57fc8f9d-4864-487c-ad6c-49d402de0b81", "value": "https://www.virustotal.com/file/3f147a037baac4220a84b5fed4c167fc75cf331126735d70f67c2c8fb7f50c87/analysis/1475531539/" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: dd5686ca7ec28815c3cf3ed3dbebdff2", "deleted": false, "disable_correlation": false, "timestamp": "1476169629", "to_ids": true, "type": "sha256", "uuid": "57fc8f9d-6288-4871-858d-4db402de0b81", "value": "cfe1c48aae527864b3f96fabdc771decf3ba388456010a83a17a52b1d40b88ef" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: dd5686ca7ec28815c3cf3ed3dbebdff2", "deleted": false, "disable_correlation": false, "timestamp": "1476169630", "to_ids": true, "type": "sha1", "uuid": "57fc8f9e-2674-45ad-8e3e-423002de0b81", "value": "d0edac41ba0556e2ba5f334328a4e7888b807065" }, { "category": "External analysis", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: dd5686ca7ec28815c3cf3ed3dbebdff2", "deleted": false, "disable_correlation": false, "timestamp": "1476169630", "to_ids": false, "type": "link", "uuid": "57fc8f9e-7bcc-4f08-9733-40a302de0b81", "value": "https://www.virustotal.com/file/cfe1c48aae527864b3f96fabdc771decf3ba388456010a83a17a52b1d40b88ef/analysis/1475870104/" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: dbf3707a9cd090853a11dda9cfa78ff0", "deleted": false, "disable_correlation": false, "timestamp": "1476169631", "to_ids": true, "type": "sha256", "uuid": "57fc8f9f-eb94-47ef-a5d5-4e4702de0b81", "value": "78db508226ccacd363fc0f02b3ae326a2bdd0baed3ae51ddf59c3fc0fcf60669" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: dbf3707a9cd090853a11dda9cfa78ff0", "deleted": false, "disable_correlation": false, "timestamp": "1476169631", "to_ids": true, "type": "sha1", "uuid": "57fc8f9f-bd9c-4b63-804a-4f4502de0b81", "value": "5af5403d8e003812a34c7b085d878680d7130ad5" }, { "category": "External analysis", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: dbf3707a9cd090853a11dda9cfa78ff0", "deleted": false, "disable_correlation": false, "timestamp": "1476169632", "to_ids": false, "type": "link", "uuid": "57fc8fa0-d80c-4fbb-9765-43d902de0b81", "value": "https://www.virustotal.com/file/78db508226ccacd363fc0f02b3ae326a2bdd0baed3ae51ddf59c3fc0fcf60669/analysis/1474984811/" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: a393b9536a1caa34914636d3da7378b5", "deleted": false, "disable_correlation": false, "timestamp": "1476169632", "to_ids": true, "type": "sha256", "uuid": "57fc8fa0-c834-4580-8703-475b02de0b81", "value": "342933cb4cbb31a2c30ac1733afc318a6e5cd0226160a59197686d635ec71b20" }, { "category": "Payload delivery", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: a393b9536a1caa34914636d3da7378b5", "deleted": false, "disable_correlation": false, "timestamp": "1476169633", "to_ids": true, "type": "sha1", "uuid": "57fc8fa1-83f8-4c65-8633-450d02de0b81", "value": "5aced706d9f6a0bb6a95c8bdf1e123485219a123" }, { "category": "External analysis", "comment": "Imported via the Freetext Import Tool - Xchecked via VT: a393b9536a1caa34914636d3da7378b5", "deleted": false, "disable_correlation": false, "timestamp": "1476169633", "to_ids": false, "type": "link", "uuid": "57fc8fa1-c47c-4095-8a49-46a802de0b81", "value": "https://www.virustotal.com/file/342933cb4cbb31a2c30ac1733afc318a6e5cd0226160a59197686d635ec71b20/analysis/1474984808/" } ] } }