249 lines
No EOL
9.5 KiB
JSON
249 lines
No EOL
9.5 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "2",
|
|
"date": "2016-10-11",
|
|
"extends_uuid": "",
|
|
"info": "OSINT - How Stampado Ransomware Analysis Led To Yara Improvements",
|
|
"publish_timestamp": "1476169652",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1476169628",
|
|
"uuid": "57fc8ec7-2c10-4c24-8565-452002de0b81",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#3a7300",
|
|
"local": false,
|
|
"name": "circl:incident-classification=\"malware\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#420053",
|
|
"local": false,
|
|
"name": "ms-caro-malware:malware-type=\"Ransom\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": false,
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#00223b",
|
|
"local": false,
|
|
"name": "osint:source-type=\"blog-post\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#006c6c",
|
|
"local": false,
|
|
"name": "ecsirt:malicious-code=\"ransomware\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Artifacts dropped",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169466",
|
|
"to_ids": true,
|
|
"type": "yara",
|
|
"uuid": "57fc8efa-2754-48b9-a10c-4b9902de0b81",
|
|
"value": "rule stampado_overlay\r\n{\r\nmeta:\r\ndescription = \"Catches Stampado samples looking for \\\\r at the beginning of PE overlay section\"\r\nreference = \"\"\r\nauthor = \"Fernando Merces, FTR, Trend Micro\"\r\ndate = \"2016-07\"\r\nmd5 = \"a393b9536a1caa34914636d3da7378b5\"\r\nmd5 = \"dbf3707a9cd090853a11dda9cfa78ff0\"\r\nmd5 = \"dd5686ca7ec28815c3cf3ed3dbebdff2\"\r\nmd5 = \"6337f0938e4a9c0ef44ab99deb0ef466\"\r\n\r\ncondition:\r\npe.characteristics == 0x122 and\r\npe.number_of_sections == 5 and\r\npe.imports(\"VERSION.dll\", \"VerQueryValueW\") and uint8(pe.sections[4].raw_data_offset + pe.sections[4].raw_data_size) == 0x0d\r\n\r\n}"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169490",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "57fc8f12-fa10-4675-b20e-467e02de0b81",
|
|
"value": "a393b9536a1caa34914636d3da7378b5"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169491",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "57fc8f13-b3ac-4994-a131-45eb02de0b81",
|
|
"value": "dbf3707a9cd090853a11dda9cfa78ff0"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169491",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "57fc8f13-c1d0-45ab-953e-446c02de0b81",
|
|
"value": "dd5686ca7ec28815c3cf3ed3dbebdff2"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169491",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "57fc8f13-02c4-4968-9ceb-465602de0b81",
|
|
"value": "6337f0938e4a9c0ef44ab99deb0ef466"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169616",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "57fc8f90-4bbc-45ef-a3d6-43b902de0b81",
|
|
"value": "http://blog.trendmicro.com/trendlabs-security-intelligence/stampado-ransomware-analysis-led-yara-improvements"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: 6337f0938e4a9c0ef44ab99deb0ef466",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169628",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "57fc8f9c-0c5c-4198-bc44-4d6802de0b81",
|
|
"value": "3f147a037baac4220a84b5fed4c167fc75cf331126735d70f67c2c8fb7f50c87"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: 6337f0938e4a9c0ef44ab99deb0ef466",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169628",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "57fc8f9c-c388-426f-af60-488202de0b81",
|
|
"value": "55e796d55c2938130ededc476ad7c92b42487cfd"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: 6337f0938e4a9c0ef44ab99deb0ef466",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169629",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "57fc8f9d-4864-487c-ad6c-49d402de0b81",
|
|
"value": "https://www.virustotal.com/file/3f147a037baac4220a84b5fed4c167fc75cf331126735d70f67c2c8fb7f50c87/analysis/1475531539/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: dd5686ca7ec28815c3cf3ed3dbebdff2",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169629",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "57fc8f9d-6288-4871-858d-4db402de0b81",
|
|
"value": "cfe1c48aae527864b3f96fabdc771decf3ba388456010a83a17a52b1d40b88ef"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: dd5686ca7ec28815c3cf3ed3dbebdff2",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169630",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "57fc8f9e-2674-45ad-8e3e-423002de0b81",
|
|
"value": "d0edac41ba0556e2ba5f334328a4e7888b807065"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: dd5686ca7ec28815c3cf3ed3dbebdff2",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169630",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "57fc8f9e-7bcc-4f08-9733-40a302de0b81",
|
|
"value": "https://www.virustotal.com/file/cfe1c48aae527864b3f96fabdc771decf3ba388456010a83a17a52b1d40b88ef/analysis/1475870104/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: dbf3707a9cd090853a11dda9cfa78ff0",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169631",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "57fc8f9f-eb94-47ef-a5d5-4e4702de0b81",
|
|
"value": "78db508226ccacd363fc0f02b3ae326a2bdd0baed3ae51ddf59c3fc0fcf60669"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: dbf3707a9cd090853a11dda9cfa78ff0",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169631",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "57fc8f9f-bd9c-4b63-804a-4f4502de0b81",
|
|
"value": "5af5403d8e003812a34c7b085d878680d7130ad5"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: dbf3707a9cd090853a11dda9cfa78ff0",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169632",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "57fc8fa0-d80c-4fbb-9765-43d902de0b81",
|
|
"value": "https://www.virustotal.com/file/78db508226ccacd363fc0f02b3ae326a2bdd0baed3ae51ddf59c3fc0fcf60669/analysis/1474984811/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: a393b9536a1caa34914636d3da7378b5",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169632",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "57fc8fa0-c834-4580-8703-475b02de0b81",
|
|
"value": "342933cb4cbb31a2c30ac1733afc318a6e5cd0226160a59197686d635ec71b20"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: a393b9536a1caa34914636d3da7378b5",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169633",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "57fc8fa1-83f8-4c65-8633-450d02de0b81",
|
|
"value": "5aced706d9f6a0bb6a95c8bdf1e123485219a123"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "Imported via the Freetext Import Tool - Xchecked via VT: a393b9536a1caa34914636d3da7378b5",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1476169633",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "57fc8fa1-c47c-4095-8a49-46a802de0b81",
|
|
"value": "https://www.virustotal.com/file/342933cb4cbb31a2c30ac1733afc318a6e5cd0226160a59197686d635ec71b20/analysis/1474984808/"
|
|
}
|
|
]
|
|
}
|
|
} |