{ "Event": { "analysis": "2", "date": "2017-04-07", "extends_uuid": "", "info": "OSINT - Matrix Ransomware Spreads to Other PCs Using Malicious Shortcuts", "publish_timestamp": "1538401644", "published": true, "threat_level_id": "3", "timestamp": "1538401642", "uuid": "58eb4dde-5254-4163-add1-4d47950d210f", "Orgc": { "name": "CIRCL", "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f" }, "Tag": [ { "colour": "#004646", "local": false, "name": "type:OSINT", "relationship_type": "" }, { "colour": "#ffffff", "local": false, "name": "tlp:white", "relationship_type": "" }, { "colour": "#2c4f00", "local": false, "name": "malware_classification:malware-category=\"Ransomware\"", "relationship_type": "" }, { "colour": "#00223b", "local": false, "name": "osint:source-type=\"blog-post\"", "relationship_type": "" }, { "colour": "#0088cc", "local": false, "name": "misp-galaxy:ransomware=\"Matrix\"", "relationship_type": "" } ], "Attribute": [ { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": false, "type": "link", "uuid": "58eb4dea-9364-46ce-8439-40a9950d210f", "value": "https://www.bleepingcomputer.com/news/security/matrix-ransomware-spreads-to-other-pcs-using-malicious-shortcuts/" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e4d-f894-4d29-95fe-41ac950d210f", "value": "%UserProfile%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\[random].hta" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e4e-980c-433d-b6c4-44ad950d210f", "value": "%UserProfile%\\AppData\\Roaming\\[victim_id].pek" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e4e-fc98-4a37-bcf0-453f950d210f", "value": "%UserProfile%\\AppData\\Roaming\\[victim_id].sek" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e4f-a278-437a-bec0-4829950d210f", "value": "%UserProfile%\\AppData\\Roaming\\errlog.txt" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e50-211c-481d-8df5-4b80950d210f", "value": "%UserProfile%\\AppData\\Roaming\\[random].cmd" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e51-b0f8-4843-a579-45fc950d210f", "value": "%UserProfile%\\AppData\\Roaming\\[random].afn" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e52-9d04-454c-9a72-41ff950d210f", "value": "%UserProfile%\\AppData\\Roaming\\[random].ast" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e53-256c-4d94-a211-4712950d210f", "value": "%UserProfile%\\AppData\\Roaming\\[random].hta" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e54-a770-44a0-ae81-4cba950d210f", "value": "matrix-readme.rtf" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e55-a2d4-4111-8c25-4b7a950d210f", "value": "Bl0cked-ReadMe.rtf" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "filename", "uuid": "58eb4e55-af34-4e10-b1ee-4354950d210f", "value": "WhatHappenedWithFiles.rtf" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "sha256", "uuid": "58eb4ea2-e160-4038-af93-40ba950d210f", "value": "467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "url", "uuid": "58eb4eb1-8ca0-4613-8c1c-4ed8950d210f", "value": "stat3.s76.r53.com.ua/addrecord.php" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "timestamp": "1491848012", "to_ids": true, "type": "url", "uuid": "58eb4eb3-cef4-46fb-90e7-4bac950d210f", "value": "stat3.s76.r53.com.ua/uploadextlist.php" }, { "category": "Payload delivery", "comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be", "deleted": false, "disable_correlation": false, "timestamp": "1491848026", "to_ids": true, "type": "sha1", "uuid": "58ebcb5a-59b8-49f8-85f8-d16c02de0b81", "value": "03ce13b4f60d2fc632b67b41b82b5e8cfaf9939f" }, { "category": "Payload delivery", "comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be", "deleted": false, "disable_correlation": false, "timestamp": "1491848027", "to_ids": true, "type": "md5", "uuid": "58ebcb5b-ec54-4794-a3f7-d16c02de0b81", "value": "36a0cefeb8b0a606358142d4140ea7cf" }, { "category": "External analysis", "comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be", "deleted": false, "disable_correlation": false, "timestamp": "1491848028", "to_ids": false, "type": "link", "uuid": "58ebcb5c-8d78-496c-92b9-d16c02de0b81", "value": "https://www.virustotal.com/file/467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be/analysis/1491798251/" } ], "Object": [ { "comment": "", "deleted": false, "description": "url object describes an url along with its normalized field (like extracted using faup parsing library) and its metadata.", "meta-category": "network", "name": "url", "template_uuid": "60efb77b-40b5-4c46-871b-ed1ed999fce5", "template_version": "6", "timestamp": "1538400598", "uuid": "5bb22156-ff94-4d42-a44d-4b17950d210f", "Attribute": [ { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "url", "timestamp": "1538400598", "to_ids": true, "type": "url", "uuid": "5bb22156-4b54-413e-9eb0-4eb4950d210f", "value": "stat3.s76.r53.com.ua/addrecord.phph" }, { "category": "Network activity", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "host", "timestamp": "1538400600", "to_ids": true, "type": "hostname", "uuid": "5bb22158-9fb0-46b5-bf72-4d99950d210f", "value": "stat3.s76.r53.com.ua" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "scheme", "timestamp": "1538400601", "to_ids": false, "type": "text", "uuid": "5bb22159-3704-4e80-92e8-4711950d210f", "value": "http" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "resource_path", "timestamp": "1538400601", "to_ids": false, "type": "text", "uuid": "5bb22159-9c08-4883-902d-4a61950d210f", "value": "addrecord.php" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "resource_path", "timestamp": "1538400602", "to_ids": false, "type": "text", "uuid": "5bb2215a-3124-44c3-9e34-4188950d210f", "value": "uploadextlist.php" } ] }, { "comment": "", "deleted": false, "description": "File object describing a file with meta-information", "meta-category": "file", "name": "file", "template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215", "template_version": "11", "timestamp": "1538401625", "uuid": "af9b35e1-17b6-4eaf-a7fd-03acafc0f34b", "ObjectReference": [ { "comment": "", "object_uuid": "af9b35e1-17b6-4eaf-a7fd-03acafc0f34b", "referenced_uuid": "391c62fa-5ed3-4e85-b707-8147a7b44c2f", "relationship_type": "analysed-with", "timestamp": "1538401644", "uuid": "5bb2256c-d73c-4fc6-acd8-42a002de0b81" } ], "Attribute": [ { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "md5", "timestamp": "1538401625", "to_ids": true, "type": "md5", "uuid": "8614882f-5819-4d39-8a90-b85df6d6fdb7", "value": "36a0cefeb8b0a606358142d4140ea7cf" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "sha1", "timestamp": "1538401628", "to_ids": true, "type": "sha1", "uuid": "66adc5b1-9a19-4eb7-a67d-cfeaff780ebe", "value": "03ce13b4f60d2fc632b67b41b82b5e8cfaf9939f" }, { "category": "Payload delivery", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "sha256", "timestamp": "1538401631", "to_ids": true, "type": "sha256", "uuid": "809102c1-605b-4035-9f9e-f571a47877de", "value": "467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be" } ] }, { "comment": "", "deleted": false, "description": "VirusTotal report", "meta-category": "misc", "name": "virustotal-report", "template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4", "template_version": "2", "timestamp": "1538401634", "uuid": "391c62fa-5ed3-4e85-b707-8147a7b44c2f", "Attribute": [ { "category": "Other", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "last-submission", "timestamp": "1538401638", "to_ids": false, "type": "datetime", "uuid": "54f701d1-fbf7-495f-878e-fe87b38caa4d", "value": "2018-08-24T19:09:51" }, { "category": "External analysis", "comment": "", "deleted": false, "disable_correlation": false, "object_relation": "permalink", "timestamp": "1538401641", "to_ids": false, "type": "link", "uuid": "a002197b-e738-4b1d-89db-293ff8663675", "value": "https://www.virustotal.com/file/467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be/analysis/1535137791/" }, { "category": "Other", "comment": "", "deleted": false, "disable_correlation": true, "object_relation": "detection-ratio", "timestamp": "1538401644", "to_ids": false, "type": "text", "uuid": "fab4c346-e53e-4b19-a858-2b5069dd299b", "value": "56/68" } ] } ] } }