misp-circl-feed/feeds/circl/misp/58eb4dde-5254-4163-add1-4d47950d210f.json

432 lines
No EOL
14 KiB
JSON

{
"Event": {
"analysis": "2",
"date": "2017-04-07",
"extends_uuid": "",
"info": "OSINT - Matrix Ransomware Spreads to Other PCs Using Malicious Shortcuts",
"publish_timestamp": "1538401644",
"published": true,
"threat_level_id": "3",
"timestamp": "1538401642",
"uuid": "58eb4dde-5254-4163-add1-4d47950d210f",
"Orgc": {
"name": "CIRCL",
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
},
"Tag": [
{
"colour": "#004646",
"local": false,
"name": "type:OSINT",
"relationship_type": ""
},
{
"colour": "#ffffff",
"local": false,
"name": "tlp:white",
"relationship_type": ""
},
{
"colour": "#2c4f00",
"local": false,
"name": "malware_classification:malware-category=\"Ransomware\"",
"relationship_type": ""
},
{
"colour": "#00223b",
"local": false,
"name": "osint:source-type=\"blog-post\"",
"relationship_type": ""
},
{
"colour": "#0088cc",
"local": false,
"name": "misp-galaxy:ransomware=\"Matrix\"",
"relationship_type": ""
}
],
"Attribute": [
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": false,
"type": "link",
"uuid": "58eb4dea-9364-46ce-8439-40a9950d210f",
"value": "https://www.bleepingcomputer.com/news/security/matrix-ransomware-spreads-to-other-pcs-using-malicious-shortcuts/"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e4d-f894-4d29-95fe-41ac950d210f",
"value": "%UserProfile%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\[random].hta"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e4e-980c-433d-b6c4-44ad950d210f",
"value": "%UserProfile%\\AppData\\Roaming\\[victim_id].pek"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e4e-fc98-4a37-bcf0-453f950d210f",
"value": "%UserProfile%\\AppData\\Roaming\\[victim_id].sek"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e4f-a278-437a-bec0-4829950d210f",
"value": "%UserProfile%\\AppData\\Roaming\\errlog.txt"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e50-211c-481d-8df5-4b80950d210f",
"value": "%UserProfile%\\AppData\\Roaming\\[random].cmd"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e51-b0f8-4843-a579-45fc950d210f",
"value": "%UserProfile%\\AppData\\Roaming\\[random].afn"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e52-9d04-454c-9a72-41ff950d210f",
"value": "%UserProfile%\\AppData\\Roaming\\[random].ast"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e53-256c-4d94-a211-4712950d210f",
"value": "%UserProfile%\\AppData\\Roaming\\[random].hta"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e54-a770-44a0-ae81-4cba950d210f",
"value": "matrix-readme.rtf"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e55-a2d4-4111-8c25-4b7a950d210f",
"value": "Bl0cked-ReadMe.rtf"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "filename",
"uuid": "58eb4e55-af34-4e10-b1ee-4354950d210f",
"value": "WhatHappenedWithFiles.rtf"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "sha256",
"uuid": "58eb4ea2-e160-4038-af93-40ba950d210f",
"value": "467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "url",
"uuid": "58eb4eb1-8ca0-4613-8c1c-4ed8950d210f",
"value": "stat3.s76.r53.com.ua/addrecord.php"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848012",
"to_ids": true,
"type": "url",
"uuid": "58eb4eb3-cef4-46fb-90e7-4bac950d210f",
"value": "stat3.s76.r53.com.ua/uploadextlist.php"
},
{
"category": "Payload delivery",
"comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848026",
"to_ids": true,
"type": "sha1",
"uuid": "58ebcb5a-59b8-49f8-85f8-d16c02de0b81",
"value": "03ce13b4f60d2fc632b67b41b82b5e8cfaf9939f"
},
{
"category": "Payload delivery",
"comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848027",
"to_ids": true,
"type": "md5",
"uuid": "58ebcb5b-ec54-4794-a3f7-d16c02de0b81",
"value": "36a0cefeb8b0a606358142d4140ea7cf"
},
{
"category": "External analysis",
"comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be",
"deleted": false,
"disable_correlation": false,
"timestamp": "1491848028",
"to_ids": false,
"type": "link",
"uuid": "58ebcb5c-8d78-496c-92b9-d16c02de0b81",
"value": "https://www.virustotal.com/file/467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be/analysis/1491798251/"
}
],
"Object": [
{
"comment": "",
"deleted": false,
"description": "url object describes an url along with its normalized field (like extracted using faup parsing library) and its metadata.",
"meta-category": "network",
"name": "url",
"template_uuid": "60efb77b-40b5-4c46-871b-ed1ed999fce5",
"template_version": "6",
"timestamp": "1538400598",
"uuid": "5bb22156-ff94-4d42-a44d-4b17950d210f",
"Attribute": [
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "url",
"timestamp": "1538400598",
"to_ids": true,
"type": "url",
"uuid": "5bb22156-4b54-413e-9eb0-4eb4950d210f",
"value": "stat3.s76.r53.com.ua/addrecord.phph"
},
{
"category": "Network activity",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "host",
"timestamp": "1538400600",
"to_ids": true,
"type": "hostname",
"uuid": "5bb22158-9fb0-46b5-bf72-4d99950d210f",
"value": "stat3.s76.r53.com.ua"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "scheme",
"timestamp": "1538400601",
"to_ids": false,
"type": "text",
"uuid": "5bb22159-3704-4e80-92e8-4711950d210f",
"value": "http"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "resource_path",
"timestamp": "1538400601",
"to_ids": false,
"type": "text",
"uuid": "5bb22159-9c08-4883-902d-4a61950d210f",
"value": "addrecord.php"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "resource_path",
"timestamp": "1538400602",
"to_ids": false,
"type": "text",
"uuid": "5bb2215a-3124-44c3-9e34-4188950d210f",
"value": "uploadextlist.php"
}
]
},
{
"comment": "",
"deleted": false,
"description": "File object describing a file with meta-information",
"meta-category": "file",
"name": "file",
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
"template_version": "11",
"timestamp": "1538401625",
"uuid": "af9b35e1-17b6-4eaf-a7fd-03acafc0f34b",
"ObjectReference": [
{
"comment": "",
"object_uuid": "af9b35e1-17b6-4eaf-a7fd-03acafc0f34b",
"referenced_uuid": "391c62fa-5ed3-4e85-b707-8147a7b44c2f",
"relationship_type": "analysed-with",
"timestamp": "1538401644",
"uuid": "5bb2256c-d73c-4fc6-acd8-42a002de0b81"
}
],
"Attribute": [
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "md5",
"timestamp": "1538401625",
"to_ids": true,
"type": "md5",
"uuid": "8614882f-5819-4d39-8a90-b85df6d6fdb7",
"value": "36a0cefeb8b0a606358142d4140ea7cf"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha1",
"timestamp": "1538401628",
"to_ids": true,
"type": "sha1",
"uuid": "66adc5b1-9a19-4eb7-a67d-cfeaff780ebe",
"value": "03ce13b4f60d2fc632b67b41b82b5e8cfaf9939f"
},
{
"category": "Payload delivery",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "sha256",
"timestamp": "1538401631",
"to_ids": true,
"type": "sha256",
"uuid": "809102c1-605b-4035-9f9e-f571a47877de",
"value": "467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be"
}
]
},
{
"comment": "",
"deleted": false,
"description": "VirusTotal report",
"meta-category": "misc",
"name": "virustotal-report",
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
"template_version": "2",
"timestamp": "1538401634",
"uuid": "391c62fa-5ed3-4e85-b707-8147a7b44c2f",
"Attribute": [
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "last-submission",
"timestamp": "1538401638",
"to_ids": false,
"type": "datetime",
"uuid": "54f701d1-fbf7-495f-878e-fe87b38caa4d",
"value": "2018-08-24T19:09:51"
},
{
"category": "External analysis",
"comment": "",
"deleted": false,
"disable_correlation": false,
"object_relation": "permalink",
"timestamp": "1538401641",
"to_ids": false,
"type": "link",
"uuid": "a002197b-e738-4b1d-89db-293ff8663675",
"value": "https://www.virustotal.com/file/467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be/analysis/1535137791/"
},
{
"category": "Other",
"comment": "",
"deleted": false,
"disable_correlation": true,
"object_relation": "detection-ratio",
"timestamp": "1538401644",
"to_ids": false,
"type": "text",
"uuid": "fab4c346-e53e-4b19-a858-2b5069dd299b",
"value": "56/68"
}
]
}
]
}
}