{ "Event": { "analysis": "1", "date": "2017-09-26", "extends_uuid": "", "info": "M2M - Locky 2017-09-26 : Affid=3, offline, \".ykcol\":\"INVOICE\" - \"A1234567890.7z\"", "publish_timestamp": "1513180991", "published": true, "threat_level_id": "3", "timestamp": "1513180979", "uuid": "59ca3ba5-b2b0-4473-b296-ff74950d210f", "Orgc": { "name": "CIRCL", "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f" }, "Tag": [ { "colour": "#ffffff", "name": "tlp:white" }, { "colour": "#006c6c", "name": "ecsirt:malicious-code=\"ransomware\"" }, { "colour": "#0088cc", "name": "misp-galaxy:ransomware=\"Locky\"" } ], "Attribute": [ { "category": "Artifacts dropped", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1506425765", "to_ids": true, "type": "md5", "uuid": "59ca3ba5-5094-4e1b-8af0-4037950d210f", "value": "da9e78d691e18dfa299c805cbf497118" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "url", "uuid": "59ca3ba6-1624-4fd4-be1e-4ac0950d210f", "value": "http://bodywork-sf.net/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "hostname", "uuid": "59ca3ba6-fc90-421f-88a8-41b6950d210f", "value": "bodywork-sf.net" }, { "category": "Network activity", "comment": "bodywork-sf.net", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": false, "type": "ip-dst", "uuid": "59ca3ba6-cdc4-43ec-b29f-4e26950d210f", "value": "98.124.251.167" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "url", "uuid": "59ca3ba6-b1f4-4ad9-9818-4f2e950d210f", "value": "http://boetsebiltong.co.za/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "hostname", "uuid": "59ca3ba7-2514-48e0-8122-4da1950d210f", "value": "boetsebiltong.co.za" }, { "category": "Network activity", "comment": "boetsebiltong.co.za", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": false, "type": "ip-dst", "uuid": "59ca3ba7-7bd4-41bd-8f91-4461950d210f", "value": "41.72.154.153" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "url", "uuid": "59ca3ba7-9528-498e-a37a-4eb2950d210f", "value": "http://bouwpartnerzaagenschaaf.nl/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "hostname", "uuid": "59ca3ba7-0cc4-44a2-8270-498f950d210f", "value": "bouwpartnerzaagenschaaf.nl" }, { "category": "Network activity", "comment": "bouwpartnerzaagenschaaf.nl", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": false, "type": "ip-dst", "uuid": "59ca3ba8-f01c-43f6-bacb-499a950d210f", "value": "84.38.226.161" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "url", "uuid": "59ca3ba8-32bc-4c4b-9b9f-4fa3950d210f", "value": "http://brand-online.eu/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "hostname", "uuid": "59ca3ba8-dbec-47eb-81c8-4e19950d210f", "value": "brand-online.eu" }, { "category": "Network activity", "comment": "brand-online.eu", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": false, "type": "ip-dst", "uuid": "59ca3ba8-af3c-4d69-b69d-4460950d210f", "value": "85.214.253.117" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180940", "to_ids": true, "type": "url", "uuid": "59ca3ba8-2484-4b0d-affb-46fa950d210f", "value": "http://brascopperchile.cl/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3ba9-03f8-49f6-af33-46c0950d210f", "value": "brascopperchile.cl" }, { "category": "Network activity", "comment": "brascopperchile.cl", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": false, "type": "ip-dst", "uuid": "59ca3ba9-c138-4061-8ef3-48d8950d210f", "value": "72.249.104.96" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "url", "uuid": "59ca3ba9-d438-4c81-8f39-4df7950d210f", "value": "http://bredabeckerle.com/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3ba9-87e0-4f15-aec1-4c65950d210f", "value": "bredabeckerle.com" }, { "category": "Network activity", "comment": "bredabeckerle.com", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": false, "type": "ip-dst", "uuid": "59ca3ba9-7fcc-43c5-ba9e-491a950d210f", "value": "65.44.220.51" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "url", "uuid": "59ca3baa-bd90-4e10-a342-4f52950d210f", "value": "http://brendo.biz/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3baa-da48-4758-a542-4233950d210f", "value": "brendo.biz" }, { "category": "Network activity", "comment": "brendo.biz", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": false, "type": "ip-dst", "uuid": "59ca3baa-3988-43a7-b6db-4a36950d210f", "value": "103.53.172.3" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "url", "uuid": "59ca3baa-4688-40f3-914c-45e6950d210f", "value": "http://broadcastaudiodevices.com/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3baa-c624-4af0-b200-4038950d210f", "value": "broadcastaudiodevices.com" }, { "category": "Network activity", "comment": "broadcastaudiodevices.com", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": false, "type": "ip-dst", "uuid": "59ca3bab-31e8-40cd-b2a1-48ed950d210f", "value": "87.106.187.207" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "url", "uuid": "59ca3bab-99fc-41e8-a12c-492f950d210f", "value": "http://bsfotodesign.com/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3bab-da08-43ae-8498-4502950d210f", "value": "bsfotodesign.com" }, { "category": "Network activity", "comment": "bsfotodesign.com", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": false, "type": "ip-dst", "uuid": "59ca3bab-73a0-48dc-80ad-4a05950d210f", "value": "80.172.241.44" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "url", "uuid": "59ca3bab-dcec-4031-a8d6-493c950d210f", "value": "http://cadsangiorgio.com/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3bac-e6cc-4a1b-9c27-ff74950d210f", "value": "cadsangiorgio.com" }, { "category": "Network activity", "comment": "cadsangiorgio.com", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": false, "type": "ip-dst", "uuid": "59ca3bac-46cc-4534-8dd1-4cbc950d210f", "value": "94.23.218.112" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "url", "uuid": "59ca3bac-8c90-434b-8efd-4ae6950d210f", "value": "http://caldas-cca.com/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3bac-4c60-4e26-88de-4db7950d210f", "value": "caldas-cca.com" }, { "category": "Network activity", "comment": "caldas-cca.com", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": false, "type": "ip-dst", "uuid": "59ca3bad-7010-44e6-b0b4-43f0950d210f", "value": "31.47.73.147" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "url", "uuid": "59ca3bad-1e34-4a8d-a62f-418c950d210f", "value": "http://playbrief.info/p66/dg6rerg" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3bad-c788-4860-bc9f-4325950d210f", "value": "playbrief.info" }, { "category": "Network activity", "comment": "payment url", "deleted": false, "disable_correlation": false, "timestamp": "1513180939", "to_ids": true, "type": "hostname", "uuid": "59ca3c3e-1afc-4177-8a36-4012950d210f", "value": "g46mbrrzpfszonuk.onion" } ], "Object": [ { "comment": "", "deleted": false, "description": "File object describing a file with meta-information", "meta-category": "file", "name": "file", "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215", "template_version": "7", "timestamp": "1513180943", "uuid": "d6a29259-b755-4577-8e9e-aa469b450d09", "ObjectReference": [ { "comment": "", "object_uuid": "d6a29259-b755-4577-8e9e-aa469b450d09", "referenced_uuid": "3d7a6ad5-2ce1-4c80-a7e1-5320084a5c18", "relationship_type": "analysed-with", "timestamp": "1513180940", "uuid": "5a314f0c-f378-49c3-baf8-41f602de0b81" } ], "Attribute": [ { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "md5", "timestamp": "1513180940", "to_ids": true, "type": "md5", "uuid": "5a314f0c-c5f0-45fc-8a59-4f2e02de0b81", "value": "da9e78d691e18dfa299c805cbf497118" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "sha256", "timestamp": "1513180940", "to_ids": true, "type": "sha256", "uuid": "5a314f0c-fea4-4f85-8998-42b402de0b81", "value": "6a90cce461369432d65ec7a8ba9c79eec9884660b02de5bef6b1d02e31553f15" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "sha1", "timestamp": "1513180940", "to_ids": true, "type": "sha1", "uuid": "5a314f0c-07b0-45a4-a51e-43f902de0b81", "value": "ef03943f1a90a11dbc87ad2d99d4644e452643c4" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "1", "timestamp": "1513180940", "uuid": "3d7a6ad5-2ce1-4c80-a7e1-5320084a5c18", "Attribute": [ { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1513180940", "to_ids": false, "type": "link", "uuid": "5a314f0c-3ab4-41e6-aa82-454002de0b81", "value": "https://www.virustotal.com/file/6a90cce461369432d65ec7a8ba9c79eec9884660b02de5bef6b1d02e31553f15/analysis/1512655657/" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1513180940", "to_ids": false, "type": "text", "uuid": "5a314f0c-ea20-4830-a510-4d3302de0b81", "value": "56/68" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1513180940", "to_ids": false, "type": "datetime", "uuid": "5a314f0c-8a00-46cc-a003-42a302de0b81", "value": "2017-12-07T14:07:37" } ] } ] } }