{ "Event": { "analysis": "2", "date": "2018-06-14", "extends_uuid": "", "info": "OSINT - DBGer Ransomware Uses EternalBlue and Mimikatz to Spread Across Networks", "publish_timestamp": "1529820254", "published": true, "threat_level_id": "3", "timestamp": "1529820217", "uuid": "5b28d191-1100-4688-aa5d-48cd950d210f", "Orgc": { "name": "CIRCL", "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f" }, "Tag": [ { "colour": "#ffffff", "name": "tlp:white" }, { "colour": "#2c4f00", "name": "malware_classification:malware-category=\"Ransomware\"" }, { "colour": "#3b7500", "name": "circl:incident-classification=\"malware\"" }, { "colour": "#00223b", "name": "osint:source-type=\"blog-post\"" }, { "colour": "#0088cc", "name": "misp-galaxy:ransomware=\"DBGer Ransomware\"" }, { "colour": "#0088cc", "name": "misp-galaxy:tool=\"ETERNALBLUE\"" }, { "colour": "#064800", "name": "misp-galaxy:tool=\"Mimikatz\"" }, { "colour": "#0088cc", "name": "misp-galaxy:mitre-enterprise-attack-tool=\"Mimikatz - S0002\"" } ], "Attribute": [ { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1529402161", "to_ids": false, "type": "link", "uuid": "5b28d1a9-25dc-4c1e-9a3d-4b20950d210f", "value": "https://www.bleepingcomputer.com/news/security/dbger-ransomware-uses-eternalblue-and-mimikatz-to-spread-across-networks/", "Tag": [ { "colour": "#00223b", "name": "osint:source-type=\"blog-post\"" } ] }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1529402131", "to_ids": false, "type": "text", "uuid": "5b28d1d3-e93c-4d14-91d6-42d5950d210f", "value": "The authors of the Satan ransomware have rebranded their \"product\" and they now go by the name of DBGer ransomware, according to security researcher MalwareHunter, who spotted this new version earlier today.\r\n\r\nThe change was not only in name but also in the ransomware's modus operandi. According to the researcher, whose discovery was later confirmed by an Intezer code similarity analysis, the new (Satan) DBGer ransomware now also incorporates Mimikatz, an open-source password-dumping utility.\r\n\r\nThe purpose of DBGer incorporating Mimikatz is for lateral movement inside compromised networks. This fits a recently observed trend in Satan's modus operandi.", "Tag": [ { "colour": "#00223b", "name": "osint:source-type=\"blog-post\"" } ] }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1529404690", "to_ids": true, "type": "filename", "uuid": "5b28dd12-f85c-4ca9-96c7-442e950d210f", "value": "_How_to_decrypt_files.txt" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1529404691", "to_ids": true, "type": "email-src", "uuid": "5b28dd13-3b30-458e-a081-4fff950d210f", "value": "dbger@protonmail.com" } ], "Object": [ { "comment": "", "deleted": false, "description": "File object describing a file with meta-information", "meta-category": "file", "name": "file", "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215", "template_version": "11", "timestamp": "1529404667", "uuid": "5b28dcfb-e79c-49c0-97c1-99d5950d210f", "Attribute": [ { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "sha256", "timestamp": "1529406088", "to_ids": true, "type": "sha256", "uuid": "5b28dcfb-e4a8-4a20-b9d3-99d5950d210f", "value": "1f3509cc11ffa1f7d839df93615cf1ba0819d75cafd5ef59110d9b01fb90addd", "Tag": [ { "colour": "#2c4f00", "name": "malware_classification:malware-category=\"Ransomware\"" } ] }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "state", "timestamp": "1529404667", "to_ids": false, "type": "text", "uuid": "5b28dcfb-42f0-4e39-9380-99d5950d210f", "value": "Malicious" } ] }, { "comment": "", "deleted": false, "description": "File object describing a file with meta-information", "meta-category": "file", "name": "file", "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215", "template_version": "11", "timestamp": "1529657040", "uuid": "5a379c38-157a-4c18-9057-75532ff27ea6", "ObjectReference": [ { "comment": "", "object_uuid": "5a379c38-157a-4c18-9057-75532ff27ea6", "referenced_uuid": "3c02a421-faf6-4b7a-a208-8b505f2a78f7", "relationship_type": "analysed-with", "timestamp": "1529657040", "uuid": "5b2cb6d0-3454-4168-9c1f-4b2f02de0b81" } ], "Attribute": [] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1529657039", "uuid": "3c02a421-faf6-4b7a-a208-8b505f2a78f7", "Attribute": [] } ] } }