432 lines
No EOL
14 KiB
JSON
432 lines
No EOL
14 KiB
JSON
{
|
|
"Event": {
|
|
"analysis": "2",
|
|
"date": "2017-04-07",
|
|
"extends_uuid": "",
|
|
"info": "OSINT - Matrix Ransomware Spreads to Other PCs Using Malicious Shortcuts",
|
|
"publish_timestamp": "1538401644",
|
|
"published": true,
|
|
"threat_level_id": "3",
|
|
"timestamp": "1538401642",
|
|
"uuid": "58eb4dde-5254-4163-add1-4d47950d210f",
|
|
"Orgc": {
|
|
"name": "CIRCL",
|
|
"uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
|
|
},
|
|
"Tag": [
|
|
{
|
|
"colour": "#004646",
|
|
"local": false,
|
|
"name": "type:OSINT",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#ffffff",
|
|
"local": false,
|
|
"name": "tlp:white",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#2c4f00",
|
|
"local": false,
|
|
"name": "malware_classification:malware-category=\"Ransomware\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#00223b",
|
|
"local": false,
|
|
"name": "osint:source-type=\"blog-post\"",
|
|
"relationship_type": ""
|
|
},
|
|
{
|
|
"colour": "#0088cc",
|
|
"local": false,
|
|
"name": "misp-galaxy:ransomware=\"Matrix\"",
|
|
"relationship_type": ""
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "58eb4dea-9364-46ce-8439-40a9950d210f",
|
|
"value": "https://www.bleepingcomputer.com/news/security/matrix-ransomware-spreads-to-other-pcs-using-malicious-shortcuts/"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e4d-f894-4d29-95fe-41ac950d210f",
|
|
"value": "%UserProfile%\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\[random].hta"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e4e-980c-433d-b6c4-44ad950d210f",
|
|
"value": "%UserProfile%\\AppData\\Roaming\\[victim_id].pek"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e4e-fc98-4a37-bcf0-453f950d210f",
|
|
"value": "%UserProfile%\\AppData\\Roaming\\[victim_id].sek"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e4f-a278-437a-bec0-4829950d210f",
|
|
"value": "%UserProfile%\\AppData\\Roaming\\errlog.txt"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e50-211c-481d-8df5-4b80950d210f",
|
|
"value": "%UserProfile%\\AppData\\Roaming\\[random].cmd"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e51-b0f8-4843-a579-45fc950d210f",
|
|
"value": "%UserProfile%\\AppData\\Roaming\\[random].afn"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e52-9d04-454c-9a72-41ff950d210f",
|
|
"value": "%UserProfile%\\AppData\\Roaming\\[random].ast"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e53-256c-4d94-a211-4712950d210f",
|
|
"value": "%UserProfile%\\AppData\\Roaming\\[random].hta"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e54-a770-44a0-ae81-4cba950d210f",
|
|
"value": "matrix-readme.rtf"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e55-a2d4-4111-8c25-4b7a950d210f",
|
|
"value": "Bl0cked-ReadMe.rtf"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "filename",
|
|
"uuid": "58eb4e55-af34-4e10-b1ee-4354950d210f",
|
|
"value": "WhatHappenedWithFiles.rtf"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "58eb4ea2-e160-4038-af93-40ba950d210f",
|
|
"value": "467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "58eb4eb1-8ca0-4613-8c1c-4ed8950d210f",
|
|
"value": "stat3.s76.r53.com.ua/addrecord.php"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848012",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "58eb4eb3-cef4-46fb-90e7-4bac950d210f",
|
|
"value": "stat3.s76.r53.com.ua/uploadextlist.php"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848026",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "58ebcb5a-59b8-49f8-85f8-d16c02de0b81",
|
|
"value": "03ce13b4f60d2fc632b67b41b82b5e8cfaf9939f"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848027",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "58ebcb5b-ec54-4794-a3f7-d16c02de0b81",
|
|
"value": "36a0cefeb8b0a606358142d4140ea7cf"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "- Xchecked via VT: 467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"timestamp": "1491848028",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "58ebcb5c-8d78-496c-92b9-d16c02de0b81",
|
|
"value": "https://www.virustotal.com/file/467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be/analysis/1491798251/"
|
|
}
|
|
],
|
|
"Object": [
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "url object describes an url along with its normalized field (like extracted using faup parsing library) and its metadata.",
|
|
"meta-category": "network",
|
|
"name": "url",
|
|
"template_uuid": "60efb77b-40b5-4c46-871b-ed1ed999fce5",
|
|
"template_version": "6",
|
|
"timestamp": "1538400598",
|
|
"uuid": "5bb22156-ff94-4d42-a44d-4b17950d210f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "url",
|
|
"timestamp": "1538400598",
|
|
"to_ids": true,
|
|
"type": "url",
|
|
"uuid": "5bb22156-4b54-413e-9eb0-4eb4950d210f",
|
|
"value": "stat3.s76.r53.com.ua/addrecord.phph"
|
|
},
|
|
{
|
|
"category": "Network activity",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "host",
|
|
"timestamp": "1538400600",
|
|
"to_ids": true,
|
|
"type": "hostname",
|
|
"uuid": "5bb22158-9fb0-46b5-bf72-4d99950d210f",
|
|
"value": "stat3.s76.r53.com.ua"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "scheme",
|
|
"timestamp": "1538400601",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5bb22159-3704-4e80-92e8-4711950d210f",
|
|
"value": "http"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "resource_path",
|
|
"timestamp": "1538400601",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5bb22159-9c08-4883-902d-4a61950d210f",
|
|
"value": "addrecord.php"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "resource_path",
|
|
"timestamp": "1538400602",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "5bb2215a-3124-44c3-9e34-4188950d210f",
|
|
"value": "uploadextlist.php"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "File object describing a file with meta-information",
|
|
"meta-category": "file",
|
|
"name": "file",
|
|
"template_uuid": "688c46fb-5edb-40a3-8273-1af7923e2215",
|
|
"template_version": "11",
|
|
"timestamp": "1538401625",
|
|
"uuid": "af9b35e1-17b6-4eaf-a7fd-03acafc0f34b",
|
|
"ObjectReference": [
|
|
{
|
|
"comment": "",
|
|
"object_uuid": "af9b35e1-17b6-4eaf-a7fd-03acafc0f34b",
|
|
"referenced_uuid": "391c62fa-5ed3-4e85-b707-8147a7b44c2f",
|
|
"relationship_type": "analysed-with",
|
|
"timestamp": "1538401644",
|
|
"uuid": "5bb2256c-d73c-4fc6-acd8-42a002de0b81"
|
|
}
|
|
],
|
|
"Attribute": [
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "md5",
|
|
"timestamp": "1538401625",
|
|
"to_ids": true,
|
|
"type": "md5",
|
|
"uuid": "8614882f-5819-4d39-8a90-b85df6d6fdb7",
|
|
"value": "36a0cefeb8b0a606358142d4140ea7cf"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha1",
|
|
"timestamp": "1538401628",
|
|
"to_ids": true,
|
|
"type": "sha1",
|
|
"uuid": "66adc5b1-9a19-4eb7-a67d-cfeaff780ebe",
|
|
"value": "03ce13b4f60d2fc632b67b41b82b5e8cfaf9939f"
|
|
},
|
|
{
|
|
"category": "Payload delivery",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "sha256",
|
|
"timestamp": "1538401631",
|
|
"to_ids": true,
|
|
"type": "sha256",
|
|
"uuid": "809102c1-605b-4035-9f9e-f571a47877de",
|
|
"value": "467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be"
|
|
}
|
|
]
|
|
},
|
|
{
|
|
"comment": "",
|
|
"deleted": false,
|
|
"description": "VirusTotal report",
|
|
"meta-category": "misc",
|
|
"name": "virustotal-report",
|
|
"template_uuid": "d7dd0154-e04f-4c34-a2fb-79f3a3a52aa4",
|
|
"template_version": "2",
|
|
"timestamp": "1538401634",
|
|
"uuid": "391c62fa-5ed3-4e85-b707-8147a7b44c2f",
|
|
"Attribute": [
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "last-submission",
|
|
"timestamp": "1538401638",
|
|
"to_ids": false,
|
|
"type": "datetime",
|
|
"uuid": "54f701d1-fbf7-495f-878e-fe87b38caa4d",
|
|
"value": "2018-08-24T19:09:51"
|
|
},
|
|
{
|
|
"category": "External analysis",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": false,
|
|
"object_relation": "permalink",
|
|
"timestamp": "1538401641",
|
|
"to_ids": false,
|
|
"type": "link",
|
|
"uuid": "a002197b-e738-4b1d-89db-293ff8663675",
|
|
"value": "https://www.virustotal.com/file/467c2b23b785df7b45758143387e9cc5a588718ae0640b3f01b1c19679b011be/analysis/1535137791/"
|
|
},
|
|
{
|
|
"category": "Other",
|
|
"comment": "",
|
|
"deleted": false,
|
|
"disable_correlation": true,
|
|
"object_relation": "detection-ratio",
|
|
"timestamp": "1538401644",
|
|
"to_ids": false,
|
|
"type": "text",
|
|
"uuid": "fab4c346-e53e-4b19-a858-2b5069dd299b",
|
|
"value": "56/68"
|
|
}
|
|
]
|
|
}
|
|
]
|
|
}
|
|
} |