Commit Graph

318 Commits (15b27f949710ede4fd4f5316017b05c401375f8d)

Author SHA1 Message Date
Alexandre Dulaunoy 769e0002ef
chg: [tools] jq all the things 2019-03-08 08:10:42 +01:00
Alexandre Dulaunoy 31ba566c18
chg: [tool] SLUB Backdoor added 2019-03-07 15:51:16 +01:00
Alexandre Dulaunoy f7367ef887
chg: [tool] Xbash description updated 2019-02-23 09:25:14 +01:00
Alexandre Dulaunoy f621b40263
chg: [threat-actor] jq all the things late in the night 2019-02-22 22:47:25 +01:00
Alexandre Dulaunoy f2c80cbcdd
chg: [tool] BabyShark added 2019-02-22 22:44:44 +01:00
Deborah Servili 5bf18ffd23
Merge branch 'master' into master 2019-02-14 16:29:04 +01:00
Deborah Servili 9c450a80d4
add Gallmaker and other clusters 2019-02-14 16:04:54 +01:00
Deborah Servili 2794a20589
add OSX/Shlayer and some refs 2019-02-14 12:42:28 +01:00
Alexandre Dulaunoy ad0ef66b0a
chg: [tool] jq jq jq jq jq jq jq jq 2019-02-12 21:41:33 +01:00
Thomas Dupuy 95a70d09a5 add ANEL/UPPERCUT in tool cluster 2019-02-12 12:19:23 -05:00
Deborah Servili 45ed56cd61
add LoJax ref 2019-01-17 10:49:23 +01:00
Deborah Servili e6fa06f178
add OSX malwares 2018-12-18 16:26:49 +01:00
Deborah Servili a9265d9858
update toll version 2018-12-13 09:44:09 +01:00
Deborah Servili 9f29f297d2
add shamoon synonym 2018-12-13 09:43:20 +01:00
Deborah Servili 3a2ac48faa
fix tool version 2018-12-12 15:39:34 +01:00
Deborah Servili 169d69871a
add Goden Chickens and affiliates 2018-12-12 13:52:55 +01:00
Deborah Servili 5a725e71ef
add several clusters 2018-12-06 16:13:51 +01:00
Deborah Servili 9f5e10abf6
fix version 2018-11-23 16:16:58 +01:00
Deborah Servili b6b1c7171a
Add Rotexy 2018-11-23 16:15:48 +01:00
Deborah Servili dac1c08491
update version 2018-11-23 12:42:41 +01:00
Deborah Servili b50c8bd805
add PNG Dropper 2018-11-23 10:38:36 +01:00
Deborah Servili 1be4a1cedb
add reference for Emotet/Geodo 2018-11-22 09:00:43 +01:00
Deborah Servili 2f5031b845
add several references for Emotet and others 2018-11-22 08:37:45 +01:00
Deborah Servili 77b556d702
jq and add ref in tool galaxy -hit version 100- 2018-11-16 13:11:55 +01:00
Deborah Servili 14444e4321
add several tools and refs 2018-11-08 10:39:32 +01:00
Deborah Servili af6020077e
add August Stealer 2018-10-23 15:25:37 +02:00
Deborah Servili 32d90a27e1
add GhostMiner 2018-10-22 14:46:44 +02:00
Deborah Servili bd68ee280e Merge branch 'master' of https://github.com/MISP/misp-galaxy 2018-10-22 11:09:37 +02:00
Deborah Servili 504570a298
add tools from https://github.com/misterch0c/shadowbroker 2018-10-22 11:06:25 +02:00
Deborah Servili 4564c5eb37
add DarkPulsar and affiliates + update some refs 2018-10-22 10:14:30 +02:00
Christophe Vandeplas 9dddc4427c jq 2018-10-19 10:23:09 +02:00
Christophe Vandeplas ddccac58c8 chg: categorization of galaxies
This allows relationships to be created.
2018-10-19 10:18:14 +02:00
Christophe Vandeplas 76b1429f10 fix: add missing relations from commit a81bbe288f 2018-10-17 19:13:35 +02:00
Christophe Vandeplas 84af053761 fix: add missing relations from commit 29beb01dc3 2018-10-17 19:07:01 +02:00
Christophe Vandeplas 873bc873b4 Merge remote-tracking branch 'MISP/master' 2018-10-17 18:28:44 +02:00
Christophe Vandeplas 1e90cac717 fix: intrusion is an actor and not a tool 2018-10-17 18:17:33 +02:00
Deborah Servili c134035a6d
add several refs 2018-10-15 11:33:37 +02:00
Deborah Servili 8d0c87c830
add several refs 2018-10-15 11:28:01 +02:00
Christophe Vandeplas f26a4f2806 fix: minor newline difference after jq_all_the 2018-10-12 12:31:29 +02:00
Christophe Vandeplas f14d616e22 chg: magical mapping with malpedia 2018-10-12 11:00:00 +02:00
Christophe Vandeplas 2fbd8ce485 jq sort keys
Allows automation to edit the files
2018-10-12 10:35:31 +02:00
Deborah Servili 655b1619e4 Merge branch 'master' of https://github.com/MISP/misp-galaxy 2018-10-05 16:06:25 +02:00
Deborah Servili 58a86e4e26
fix failed copy-paste 2018-10-05 15:53:03 +02:00
Alexandre Dulaunoy 8149960aa3
Merge pull request #276 from Delta-Sierra/master
add CoalaBot + Kraken Cryptor Ransmware + refs
2018-10-05 15:52:04 +02:00
Deborah Servili 9225666b92
add CoalaBot + Kraken Cryptor Ransmware + refs 2018-10-05 11:09:45 +02:00
Alexandre Dulaunoy ecba2dbdbf
Merge pull request #274 from Delta-Sierra/master
Refs updates
2018-10-04 17:24:57 +02:00
Deborah Servili b45b4ce0b1
add refs 2018-10-04 12:01:26 +02:00
Alexandre Dulaunoy 276992f180
Merge pull request #273 from Delta-Sierra/master
update synonyms & attributions
2018-10-04 11:17:19 +02:00
Deborah Servili 2893d715d6
Add ZEBROCY tool 2018-10-04 10:52:40 +02:00
Deborah Servili 123099cd6d
Merge pull request #272 from Delta-Sierra/master
New clusters based on CIG Circular 66 – FASTCash ATM Cash Out Campaign
2018-10-03 16:38:33 +02:00
Deborah Servili 3dfe8a5a34 add FASTCash 2018-10-03 15:09:14 +02:00
Alexandre Dulaunoy 63b777fc9e
Merge pull request #271 from Delta-Sierra/master
Several updates
2018-10-01 21:51:11 +02:00
Deborah Servili 35582f7ed5
new threat actors & tools 2018-10-01 11:52:40 +02:00
Alexandre Dulaunoy 2402c7d98f
chg: [tool] NOKKI added
ref: https://researchcenter.paloaltonetworks.com/2018/09/unit42-new-konni-malware-attacking-eurasia-southeast-asia/
2018-09-29 09:01:47 +02:00
Deborah Servili 97581d7185
jq 2018-09-28 11:20:38 +02:00
Deborah Servili fbf21487cf
new clusters and informtion 2018-09-28 11:08:21 +02:00
Deborah Servili 29beb01dc3
add relationships on Mirai 2018-09-24 16:06:36 +02:00
Deborah Servili 0a724bee3d
merge 2018-09-19 16:01:46 +02:00
Deborah Servili 3f22dbd17d
add notpetya and update jadeRAT 2018-09-19 15:06:43 +02:00
Alexandre Dulaunoy 4ae0ccd192
chg: [tool] Xbash added
ref: https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/
2018-09-19 07:03:56 +02:00
Deborah Servili fd960bfc1b
Add magentocore malware 2018-09-18 23:10:33 +02:00
Deborah Servili 0843fdfb23
adding and updating clusters 2018-09-13 09:03:41 +02:00
Deborah Servili cb5fa5e822
fix version 2018-09-10 14:21:14 +02:00
Deborah Servili a81bbe288f
fix some relations 2018-09-10 12:27:40 +02:00
Alexandre Dulaunoy f8c5640613
chg: [tool] biscuit biscvt tool BISKVIT
ref: https://www.fortinet.com/blog/threat-research/russian-army-exhibition-decoy-leads-to-new-biskvit-malware.html
2018-08-21 10:48:47 +02:00
Christophe Vandeplas 88162aa44e chg: [mapping] Generated automatic mapping between clusters 2018-08-14 09:35:22 +02:00
Christophe Vandeplas 5478f0aa45 no change: dump files with sort_keys=True
This is needed to keep better track of the changes when other tools load and save the json files.
2018-08-13 17:06:29 +02:00
Alexandre Dulaunoy 9059a85eed
chg: [tool] KEYMARBLE malware added
ref: https://www.us-cert.gov/ncas/analysis-reports/AR18-221A
2018-08-11 16:14:39 +02:00
Deborah Servili 27805ca768
add tools used by SamSam 2018-08-09 15:55:36 +02:00
Deborah Servili e5b185deee
Merge branch 'master' into master 2018-08-03 16:11:16 +02:00
Deborah Servili a9a71ef84c
more clusters 2018-08-03 15:58:54 +02:00
Alexandre Dulaunoy c232b3dd5a
chg: [tool] added based on Carbanak tooling description from Crowdstrike
ref: https://www.crowdstrike.com/blog/arrests-put-new-focus-on-carbon-spider-adversary-group/
2018-08-02 10:30:47 +02:00
Alexandre Dulaunoy 4cf84858e3
chg: [tool] Bisonal malware added (new variant with encryption capabilities) 2018-07-31 15:26:11 +02:00
Deborah Servili fb6b01cc95
Merge branch 'master' into master 2018-06-27 09:39:28 +02:00
Deborah Servili b1aac6b35b cfr update -in progress + add clusters associated to RANCOR 2018-06-27 09:37:43 +02:00
raw-data f649af8ba5 [ADD] x1 new entry in tool.json - Koadic 2018-06-25 15:59:30 +01:00
Deborah Servili dcd159f8ed add olympic destroyer 2018-06-19 15:26:40 +02:00
Deborah Servili cee83f677e more clusters 2018-06-18 14:30:51 +02:00
Deborah Servili ab577afacd add ClipboardWalletHijacker 2018-06-18 09:47:03 +02:00
Deborah Servili 4ac23483b9 add some tools 2018-06-13 11:54:50 +02:00
Deborah Servili cef7d02622 update version 2018-06-13 11:06:31 +02:00
Deborah Servili c17a2aa7cc add some clusters 2018-06-13 10:39:11 +02:00
Deborah Servili 508bb081c8 add BabaYaga Malware 2018-06-08 15:54:30 +02:00
Deborah Servili 2b447585b6 add PLEAD 2018-06-08 10:18:41 +02:00
Deborah Servili 3e91466aea add Brambul worm 2018-06-06 15:07:30 +02:00
Alexandre Dulaunoy 308774755c
add: Iron Backdoor 2018-06-03 18:39:37 +02:00
raw-data 8726e0542d [ADD] VPNFilter in tool.json cluster 2018-05-26 23:49:59 +01:00
Deborah Servili 3d5c697761 add Stalinlocker 2018-05-15 12:27:20 +02:00
Deborah Servili 5e0bd260d6 update some clusters 2018-05-09 16:12:02 +02:00
Deborah Servili 2b16c86687 add maikspy 2018-05-09 09:52:22 +02:00
Deborah Servili d3f7f7b591 jq~ 2018-05-09 09:34:08 +02:00
Deborah Servili 394950379b add Kitty malware 2018-05-07 15:27:29 +02:00
Deborah Servili 83581c62b0 add Rubella Macro Builder 2018-05-03 15:38:06 +02:00
Deborah Servili 11f0963468 add Orangeworm, Kwampirs, Iron ransomware and Ton ransomware 2018-04-24 10:20:11 +02:00
StefanKelm eff4ace398
Remove Chthonic since it's a duplicate (banker.json) 2018-04-16 15:34:59 +02:00
Deborah Servili 1a18ffb3eb add Rovnix 2018-04-11 16:30:58 +02:00
Deborah Servili c773597155 add GoScanSSH tool 2018-04-10 15:56:27 +02:00
Deborah Servili 2bd3344eb6 add 2 -supposed- wipers 2018-04-05 11:51:13 +02:00
Alexandre Dulaunoy f4d7fe0166
add: SHARPKNOT 2018-03-29 16:31:05 +02:00
Raphaël Vinot 24fa5b8b1b Merge branch 'master' of github.com:MISP/misp-galaxy 2018-03-23 10:40:32 +01:00