Commit Graph

370 Commits (217e3eb171abd277edabbea9e53464cc5bdf1489)

Author SHA1 Message Date
Deborah Servili 2893d715d6
Add ZEBROCY tool 2018-10-04 10:52:40 +02:00
Deborah Servili 123099cd6d
Merge pull request #272 from Delta-Sierra/master
New clusters based on CIG Circular 66 – FASTCash ATM Cash Out Campaign
2018-10-03 16:38:33 +02:00
Deborah Servili 3dfe8a5a34 add FASTCash 2018-10-03 15:09:14 +02:00
Alexandre Dulaunoy 63b777fc9e
Merge pull request #271 from Delta-Sierra/master
Several updates
2018-10-01 21:51:11 +02:00
Deborah Servili 35582f7ed5
new threat actors & tools 2018-10-01 11:52:40 +02:00
Alexandre Dulaunoy 2402c7d98f
chg: [tool] NOKKI added
ref: https://researchcenter.paloaltonetworks.com/2018/09/unit42-new-konni-malware-attacking-eurasia-southeast-asia/
2018-09-29 09:01:47 +02:00
Deborah Servili 97581d7185
jq 2018-09-28 11:20:38 +02:00
Deborah Servili fbf21487cf
new clusters and informtion 2018-09-28 11:08:21 +02:00
Deborah Servili 29beb01dc3
add relationships on Mirai 2018-09-24 16:06:36 +02:00
Deborah Servili 0a724bee3d
merge 2018-09-19 16:01:46 +02:00
Deborah Servili 3f22dbd17d
add notpetya and update jadeRAT 2018-09-19 15:06:43 +02:00
Alexandre Dulaunoy 4ae0ccd192
chg: [tool] Xbash added
ref: https://researchcenter.paloaltonetworks.com/2018/09/unit42-xbash-combines-botnet-ransomware-coinmining-worm-targets-linux-windows/
2018-09-19 07:03:56 +02:00
Deborah Servili fd960bfc1b
Add magentocore malware 2018-09-18 23:10:33 +02:00
Deborah Servili 0843fdfb23
adding and updating clusters 2018-09-13 09:03:41 +02:00
Deborah Servili cb5fa5e822
fix version 2018-09-10 14:21:14 +02:00
Deborah Servili a81bbe288f
fix some relations 2018-09-10 12:27:40 +02:00
Alexandre Dulaunoy f8c5640613
chg: [tool] biscuit biscvt tool BISKVIT
ref: https://www.fortinet.com/blog/threat-research/russian-army-exhibition-decoy-leads-to-new-biskvit-malware.html
2018-08-21 10:48:47 +02:00
Christophe Vandeplas 88162aa44e chg: [mapping] Generated automatic mapping between clusters 2018-08-14 09:35:22 +02:00
Christophe Vandeplas 5478f0aa45 no change: dump files with sort_keys=True
This is needed to keep better track of the changes when other tools load and save the json files.
2018-08-13 17:06:29 +02:00
Alexandre Dulaunoy 9059a85eed
chg: [tool] KEYMARBLE malware added
ref: https://www.us-cert.gov/ncas/analysis-reports/AR18-221A
2018-08-11 16:14:39 +02:00
Deborah Servili 27805ca768
add tools used by SamSam 2018-08-09 15:55:36 +02:00
Deborah Servili e5b185deee
Merge branch 'master' into master 2018-08-03 16:11:16 +02:00
Deborah Servili a9a71ef84c
more clusters 2018-08-03 15:58:54 +02:00
Alexandre Dulaunoy c232b3dd5a
chg: [tool] added based on Carbanak tooling description from Crowdstrike
ref: https://www.crowdstrike.com/blog/arrests-put-new-focus-on-carbon-spider-adversary-group/
2018-08-02 10:30:47 +02:00
Alexandre Dulaunoy 4cf84858e3
chg: [tool] Bisonal malware added (new variant with encryption capabilities) 2018-07-31 15:26:11 +02:00
Deborah Servili fb6b01cc95
Merge branch 'master' into master 2018-06-27 09:39:28 +02:00
Deborah Servili b1aac6b35b cfr update -in progress + add clusters associated to RANCOR 2018-06-27 09:37:43 +02:00
raw-data f649af8ba5 [ADD] x1 new entry in tool.json - Koadic 2018-06-25 15:59:30 +01:00
Deborah Servili dcd159f8ed add olympic destroyer 2018-06-19 15:26:40 +02:00
Deborah Servili cee83f677e more clusters 2018-06-18 14:30:51 +02:00
Deborah Servili ab577afacd add ClipboardWalletHijacker 2018-06-18 09:47:03 +02:00
Deborah Servili 4ac23483b9 add some tools 2018-06-13 11:54:50 +02:00
Deborah Servili cef7d02622 update version 2018-06-13 11:06:31 +02:00
Deborah Servili c17a2aa7cc add some clusters 2018-06-13 10:39:11 +02:00
Deborah Servili 508bb081c8 add BabaYaga Malware 2018-06-08 15:54:30 +02:00
Deborah Servili 2b447585b6 add PLEAD 2018-06-08 10:18:41 +02:00
Deborah Servili 3e91466aea add Brambul worm 2018-06-06 15:07:30 +02:00
Alexandre Dulaunoy 308774755c
add: Iron Backdoor 2018-06-03 18:39:37 +02:00
raw-data 8726e0542d [ADD] VPNFilter in tool.json cluster 2018-05-26 23:49:59 +01:00
Deborah Servili 3d5c697761 add Stalinlocker 2018-05-15 12:27:20 +02:00
Deborah Servili 5e0bd260d6 update some clusters 2018-05-09 16:12:02 +02:00
Deborah Servili 2b16c86687 add maikspy 2018-05-09 09:52:22 +02:00
Deborah Servili d3f7f7b591 jq~ 2018-05-09 09:34:08 +02:00
Deborah Servili 394950379b add Kitty malware 2018-05-07 15:27:29 +02:00
Deborah Servili 83581c62b0 add Rubella Macro Builder 2018-05-03 15:38:06 +02:00
Deborah Servili 11f0963468 add Orangeworm, Kwampirs, Iron ransomware and Ton ransomware 2018-04-24 10:20:11 +02:00
StefanKelm eff4ace398
Remove Chthonic since it's a duplicate (banker.json) 2018-04-16 15:34:59 +02:00
Deborah Servili 1a18ffb3eb add Rovnix 2018-04-11 16:30:58 +02:00
Deborah Servili c773597155 add GoScanSSH tool 2018-04-10 15:56:27 +02:00
Deborah Servili 2bd3344eb6 add 2 -supposed- wipers 2018-04-05 11:51:13 +02:00
Alexandre Dulaunoy f4d7fe0166
add: SHARPKNOT 2018-03-29 16:31:05 +02:00
Raphaël Vinot 24fa5b8b1b Merge branch 'master' of github.com:MISP/misp-galaxy 2018-03-23 10:40:32 +01:00
Raphaël Vinot f6695f5b56 fix: Duplicate UUID in tools 2018-03-23 10:40:21 +01:00
Deborah Servili 3ae0e5f113 add several tools 2018-03-23 08:27:14 +01:00
Deborah Servili 8cfd258ee3
Merge branch 'master' into master 2018-03-21 08:31:56 +01:00
Deborah Servili 510347c730 add gamut botnet 2018-03-21 08:29:41 +01:00
Dennis Rand 080e68a30f Added RoyalCli and RoyalDNS related to APT15 based on information from NCC Group 2018-03-15 22:08:06 +00:00
eCrimeLabs bfeb9d772c
Malware Used by APT37
Malware Used by APT37
2018-03-14 22:11:43 +00:00
eCrimeLabs 84215d0003
Added tools from APT37
Malware Used by APT37
2018-03-14 21:53:35 +00:00
Deborah Servili e6a703e359 jq 2018-03-12 11:53:06 +01:00
Deborah Servili e3c6e7e238 add missing uuid 2018-03-12 11:52:51 +01:00
Deborah Servili 4aa73942e7 add ref for BS2005 2018-03-12 11:46:04 +01:00
Deborah Servili 11daa2e1e0 add Nautilus, Neuron and update GandCrab 2018-03-12 10:23:57 +01:00
Deborah Servili ca7034a117 jq all the things 2018-03-09 14:53:31 +01:00
Deborah Servili 0c1e0b86b5 add missing uuid 2018-03-09 14:39:14 +01:00
Deborah Servili ac8dc7122c add Shipup 2018-03-09 14:34:14 +01:00
Deborah Servili 1b19f99f87 add ghotex 2018-03-09 14:29:24 +01:00
Deborah Servili d2ad0f1c09 add miniflame 2018-03-09 12:20:06 +01:00
Deborah Servili 6096c45da5 add Downloader-FGO 2018-03-09 11:32:31 +01:00
Deborah Servili a415a48d71 add Cheshire Cat -hack.lu video as reference! 2018-03-09 10:47:17 +01:00
Deborah Servili 0ad7f06cf6 add Aurora/Hydraq 2018-03-09 10:18:47 +01:00
Deborah Servili 0cfc8907f3 add Rotinom 2018-03-09 09:25:40 +01:00
Deborah Servili 773d764445 add Exforel 2018-03-09 09:21:32 +01:00
Deborah Servili ee3c858e4f Add TSCookie Malware and RAT 2018-03-06 13:28:28 +01:00
Deborah Servili b3574f880a jq ftw 2018-02-28 16:16:28 +01:00
Deborah Servili d88a4a44dc add uuid to every cluster 2018-02-28 15:37:37 +01:00
Alexandre Dulaunoy 4664042400
fix: PureMasuta added to Masuta 2018-01-25 16:06:21 +01:00
Alexandre Dulaunoy 3b61d2c84a
fix: typo in meta field 2018-01-25 15:56:16 +01:00
Alexandre Dulaunoy 5070314aae
add: Matsuta IoT botnet added 2018-01-25 15:39:44 +01:00
Deborah Servili ddffa49b42 add Digmine 2018-01-15 15:45:26 +01:00
Deborah Servili 8c1583b962 add travle/PYLOT 2018-01-15 14:44:36 +01:00
Deborah Servili 130ad39d4c add macOS malwares 2018-01-11 15:19:18 +01:00
Deborah Servili 80d4fd0164 add monero miner 2018-01-10 15:30:47 +01:00
Deborah Servili d6b16b2177 update Sofacy tools 2017-12-22 10:46:18 +01:00
Deborah Servili f737b7fe0a modify SedKit description 2017-12-22 10:08:54 +01:00
Deborah Servili e787efce72 add SedKit 2017-12-22 10:05:52 +01:00
Deborah Servili 51a4868a3f add "Power"tools 2017-12-21 11:18:32 +01:00
Deborah Servili 56d5ab9afa add satori (Mirai Variant) 2017-12-20 11:25:06 +01:00
Deborah Servili 9aa073a1c4 add PRILEX & CUTLET MAKER 2017-12-19 15:38:33 +01:00
Deborah Servili eb9a49df81 add GratefulPOS 2017-12-19 12:17:42 +01:00
Deborah Servili cfaadb0c71 add OSX.Pirrit 2017-12-15 09:57:39 +01:00
Alexandre Dulaunoy d767e43669
TRISIS is the main name of TRITON as discussed in https://twitter.com/DragosInc/status/941355602512613381 2017-12-14 18:56:36 +01:00
Alexandre Dulaunoy 90e37eb272
TRITON added 2017-12-14 17:13:18 +01:00
Deborah Servili 901d624a52 add SSHDoor 2017-12-14 11:37:05 +01:00
Deborah Servili 8836dfdc16 add Quant Loader 2017-12-13 15:51:24 +01:00
Deborah Servili e891373ce8 Add MoneyTaker 2017-12-13 15:15:57 +01:00
Alexandre Dulaunoy c2e2093f29
Merge branch 'master' of https://github.com/Delta-Sierra/misp-galaxy into Delta-Sierra-master 2017-12-10 10:23:37 +01:00
Alexandre Dulaunoy 2578daabf6
merge conflict solved - wp-vcd added 2017-12-10 10:19:17 +01:00
Alexandre Dulaunoy 5f34b618f8
StrongPity2 added 2017-12-10 09:24:32 +01:00
Deborah Servili 12e0af9fa2 add malware/ransomwares 2017-12-08 15:45:44 +01:00
Deborah Servili 6f79153169 add Ordinypt 2017-11-21 12:13:38 +01:00
Deborah Servili ff3cb27a3b jq 2017-11-20 12:33:47 +01:00
Deborah Servili 632f030b28 update tool galaxy 2017-11-20 12:32:35 +01:00
Deborah Servili e2dbd5a9a3 add MuddyWater + Update HIDDEN COBRA and update its tools 2017-11-17 15:41:44 +01:00
Deborah Servili 24e4b15156 add Silence Trojan 2017-11-14 16:20:08 +01:00
Deborah Servili 2ed39f3cee Fix typo - Spaaaace~ 2017-11-09 09:39:45 +01:00
Deborah Servili 880c74f469 add ALMA Communicator 2017-11-09 09:25:16 +01:00
Deborah Servili 2fefd3810d add dimnie 2017-10-27 11:42:01 +02:00
Deborah Servili 2533c1b54e fix typo 2017-10-27 10:33:58 +02:00
Deborah Servili 5597e5af1c add Formbook 2017-10-27 10:30:21 +02:00
Deborah Servili 814c19841f jq 2017-10-20 15:32:01 +02:00
Deborah Servili 2fd3d3221d add IoT_reaper 2017-10-20 15:09:20 +02:00
Deborah Servili a6d5383adf add synonym in tool galaxy 2017-10-18 15:43:12 +02:00
Deborah Servili d07d4fbfa7 fix typo~ 2017-09-06 10:04:57 +02:00
Deborah Servili da5b1d2ed3 add tools and rat 2017-09-06 09:51:52 +02:00
Deborah Servili 15ce9fb85d add fireball malware 2017-08-24 16:10:17 +02:00
Deborah Servili 63b7e62de5 add Joao malware 2017-08-24 08:49:42 +02:00
Alexandre Dulaunoy 760f863f8a
EngineBox malware added 2017-08-19 09:38:45 +02:00
Deborah Servili d29fb670c0 fix space typo 2017-08-16 10:50:12 +02:00
Deborah Servili 693ea7e58a type is array -shh I'm bad with the format, I know 2017-08-08 15:00:06 +02:00
Deborah Servili 6d7ec00907 type is meta 2017-08-08 12:44:37 +02:00
Deborah Servili fa813f0f20 jq~ 2017-08-08 12:40:35 +02:00
Deborah Servili d6a4e3a5a0 add/update tool galaxy 2017-08-08 12:37:14 +02:00
Deborah Servili ca58a2f8b4 jq 2017-08-02 11:16:21 +02:00
Deborah Servili 8573d28493 Merge branch 'master' into master 2017-08-01 10:18:18 +02:00
Deborah Servili c8fa7a919f try to merge 'CowerSnail added' 2017-08-01 10:04:25 +02:00
Deborah Servili 52cd886ceb add svpeng tool 2017-08-01 09:44:38 +02:00
Alexandre Dulaunoy fda915f2f6
CowerSnail added 2017-07-30 18:46:20 +02:00
Deborah Servili 497ecc396a clean tool.json 2017-07-26 09:41:08 +02:00
Deborah Servili a6eb7338b3 adding clusters based on MISP data 2017-07-19 16:25:46 +02:00
Alexandre Dulaunoy 951ed3b9ed jq 2017-06-16 22:18:51 +02:00
Deborah Servili 91cf7b4cee add some rats sand tools 2017-06-16 15:34:20 +02:00
Alexandre Dulaunoy dcfbfdfe47 jq all 2017-05-26 14:59:34 +02:00
Alexandre Dulaunoy d95351a72a Merge branch 'master' of github.com:MISP/misp-galaxy 2017-05-26 14:52:50 +02:00
Alexandre Dulaunoy b562e6b729 Emotet/Geodo added 2017-05-26 14:52:35 +02:00
Deborah Servili c501517e9a add synonym to hancitor 2017-05-17 12:00:26 +02:00
Alexandre Dulaunoy 248eecaef0 Kazuar: Multiplatform Espionage Backdoor with API Access added 2017-05-04 17:22:28 +02:00
Alexandre Dulaunoy 35b94437e8 REDLEAVES malware added 2017-04-28 08:32:34 +02:00
Déborah Servili c08cc781f5 update tools 2017-04-26 12:23:57 +02:00
Alexandre Dulaunoy 3e4973f688 Feodo added 2017-04-25 19:56:06 +02:00
Déborah Servili 6267681362 add Cardinal RAT 2017-04-24 16:04:52 +02:00
Alexandre Dulaunoy 07c82e15a5 FlexiSpy 2017-04-23 23:05:12 +02:00
Alexandre Dulaunoy 52edcb1929 shadow broker leak of NSA tools from https://github.com/misterch0c/shadowbroker 2017-04-15 21:22:32 +02:00
Alexandre Dulaunoy 6149740cd4 First batch of shadow broker leak (NSA name of exploit and tools) from
https://github.com/misterch0c/shadowbroker
2017-04-15 19:40:54 +02:00
Déborah Servili 7163e8c58c add synonyms for Da Vinci RCS 2017-04-14 15:51:39 +02:00
Déborah Servili 54512eb840 Add some tools/threat actor 2017-04-14 14:48:39 +02:00
Déborah Servili 9412519502 correct copypasta mistake 2017-04-12 16:11:57 +02:00
Déborah Servili bbc2b79a5e add tools from https://www.fireeye.com/blog/threat-research/2017/04/apt10_menupass_grou.html 2017-04-12 16:07:48 +02:00
Déborah Servili 8a645f42c9 update tool 2017-04-11 16:06:27 +02:00
Déborah Servili 7b5aaaeff2 json fix 2017-04-11 14:18:29 +02:00
Déborah Servili eee2c6d6b5 update tool's galaxy using http://contagiodump.blogspot.lu/2013/03/mandiant-apt1-samples-categorized-by.html 2017-04-11 14:09:44 +02:00
Alexandre Dulaunoy ab5b73a3cd Sathurbot added 2017-04-06 20:49:53 +02:00
Alexandre Dulaunoy 8c09223477 The product from NSO Group Technologies added to the list of tools.
The Pegasus name is used as synonym of Chrysaor ;-)
2017-04-04 20:42:08 +02:00
Alexandre Dulaunoy b3f1069686 Trochilus and MoonWind RATs added 2017-03-30 15:01:23 +02:00
Alexandre Dulaunoy f0e42a1818 KHRAT added 2017-03-29 16:37:31 +02:00
Alexandre Dulaunoy 71ad9099c4 IMEIJ added 2017-03-13 13:59:46 +01:00
Thanat0s 07cc13feb8 remove duplicate of ratdecode import 2017-02-27 00:38:39 +01:00
Thanat0s 9eb2d097f2 add a bunch of rat from ratdecoder list 2017-02-27 00:23:56 +01:00
Thanat0s 849ca3ebbc Pimp Epic turla 2017-02-26 23:38:50 +01:00
Thanat0s f1ea577e95 pimp and agreggate turla 2017-02-26 23:24:51 +01:00
Thanat0s 2d658a6577 pimp comrat 2017-02-26 22:53:51 +01:00
Thanat0s b865342f2e pimp xneteagle 2017-02-26 22:47:16 +01:00
Thanat0s f4584f3900 pimp xscontrol 2017-02-26 22:41:51 +01:00
Thanat0s b400edbe9b Update Xagent from aptnote Bitdefender-Whitepaper-APT-Mac-A4-en-EN-web(02-23-2017) 2017-02-26 20:40:44 +01:00
Thanat0s 51eee31c21 Pimp lecna/Backspace 2017-02-26 20:16:59 +01:00
Thanat0s 0d0ba42f15 Pimp lecna/Backspace 2017-02-26 20:16:46 +01:00
Thanat0s cdc80e5596 Pimp RarStone 2017-02-26 20:02:34 +01:00
Thanat0s ca68abc0e8 Pimp Pirpi. Hard to say:) 2017-02-26 19:56:17 +01:00
Thanat0s 6e78746a6c pimp webc2 2017-02-26 19:37:10 +01:00
Thanat0s 0775bfce62 pimp winnti 2017-02-26 19:26:21 +01:00
Thanat0s 8de827977c Pimp nettraveler 2017-02-26 19:21:41 +01:00
Thanat0s 7d62d8c3e7 cleanup zeus duplicate in alias and name 2017-02-26 17:08:43 +01:00
Thanat0s 93df12be35 update apt28 tools 2017-02-26 17:06:19 +01:00
Thanat0s afe682cf3f Remove duplicate AlienSpy 2017-02-26 16:52:59 +01:00
Thanat0s 47903f8394 add info to the famous mimikatz 2017-02-25 02:28:43 +01:00
Thanat0s d4e3a08995 add moudor info 2017-02-25 02:22:30 +01:00
Thanat0s 3d79a82bf5 Add Tinba banking 2017-02-25 02:08:51 +01:00
Thanat0s 7eb98609a3 udpate trojan.main 2017-02-25 01:42:33 +01:00
Thanat0s 59b5ed6c1b update evilgrab 2017-02-25 01:30:10 +01:00
Thanat0s 724e836ae9 remove coreshell duplicate 2017-02-25 01:18:03 +01:00
Thanat0s e98de5cb5e add derusbi 2017-02-25 01:12:42 +01:00
Thanat0s bce60b0318 merge IEchecker et sasfi 2017-02-25 01:06:19 +01:00
Thanat0s 50d2b1c871 go for caro, add hi-zor 2017-02-25 00:42:44 +01:00
Thanat0s a29a5afbe8 update 2 array 2017-02-24 23:36:45 +01:00
Thanat0s 7265af6612 go 4 string 2017-02-24 16:24:59 +01:00
Thanat0s b124d8a08d Follow the format 2017-02-24 15:52:08 +01:00
Thanat0s 8240e5f661 json typo 2017-02-24 14:05:57 +01:00
Thanat0s 8c2c47810e Locky removed > ransomware 2017-02-24 14:00:42 +01:00
Thanat0s c1848b1a3a json issue 2017-02-24 13:59:14 +01:00
Thanat0s f496c34fda generic plugx names 2017-02-24 13:57:33 +01:00
Thanat0s bb088f97d1 Update 2017-02-24 13:56:33 +01:00
Thanat0s 0513668fcf Remove JOYRat -> team -> https://www.crowdstrike.com/blog/whois-numbered-panda/ 2017-02-24 13:46:12 +01:00
Thanat0s 796382d4ab Remove Lstudio (group using elise) , add info to PWOBOT 2017-02-24 13:39:53 +01:00
Thanat0s c6ac4d847c Remove EK and Ransomwares 2017-02-24 13:25:38 +01:00
Thanat0s b75e9cf59d Gutemberg on first 10 2017-02-23 10:14:18 +01:00
Alexandre Dulaunoy 644e429110 PupyRAT added 2017-02-20 17:34:55 +01:00
Raphaël Vinot 7db66e05dd Strict schema, update clusters accordingly 2017-02-14 11:34:59 +01:00
Raphaël Vinot 910398fe76 Fix validation, remove duplicate. 2017-02-13 18:52:54 +01:00
Alexandre Dulaunoy 5442a262ab StreamEX added 2017-02-10 10:09:37 +01:00
Alexandre Dulaunoy 30d9233db6 ZeroT added 2017-02-03 22:26:40 +01:00