2023-02-17 10:33:59 +01:00
|
|
|
{
|
|
|
|
"attributes": {
|
2024-04-24 15:19:02 +02:00
|
|
|
"actor-geo-stats-30d": {
|
|
|
|
"description": "actor-geo-stats-30d",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
|
|
|
"actor-total-stats-30d": {
|
|
|
|
"description": "actor-total-stats-30d",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
2023-02-17 10:33:59 +01:00
|
|
|
"date": {
|
|
|
|
"description": "Last update of the post as seen on the ransomware group blog. Different than the first/last seen from the crawling.",
|
2024-04-24 15:19:02 +02:00
|
|
|
"disable_correlation": true,
|
|
|
|
"misp-attribute": "datetime",
|
|
|
|
"ui-priority": 0
|
|
|
|
},
|
|
|
|
"date-published": {
|
|
|
|
"description": "Initial published date of the post on the ransomware group blog.",
|
|
|
|
"disable_correlation": true,
|
2023-02-17 10:33:59 +01:00
|
|
|
"misp-attribute": "datetime",
|
|
|
|
"ui-priority": 0
|
|
|
|
},
|
|
|
|
"description": {
|
|
|
|
"description": "Raw post.",
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
2024-04-24 15:19:02 +02:00
|
|
|
"entity-name": {
|
|
|
|
"description": "Entity name of the victim referenced in the post of the ransomware group.",
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
|
|
|
"geo": {
|
|
|
|
"description": "Geographic (main) location of the victim referenced in the post of the ransomware group.",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
|
|
|
"leak-site-url": {
|
|
|
|
"description": "Link to the post.",
|
|
|
|
"misp-attribute": "link",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
2023-02-17 10:33:59 +01:00
|
|
|
"link": {
|
|
|
|
"description": "Original URL location of the post.",
|
|
|
|
"misp-attribute": "link",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
2024-04-24 15:19:02 +02:00
|
|
|
"ransomware-group": {
|
|
|
|
"description": "Ransomware group where the post is mentioned.",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
|
|
|
"sector": {
|
|
|
|
"description": "Sector (main) of the victim referenced in the post of the ransomware group.",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
|
|
|
},
|
|
|
|
"severity": {
|
|
|
|
"description": "Severity of the post mentioned.",
|
|
|
|
"disable_correlation": true,
|
|
|
|
"misp-attribute": "text",
|
2024-04-24 16:42:39 +02:00
|
|
|
"sane_default": [
|
|
|
|
"critical",
|
|
|
|
"high",
|
|
|
|
"medium",
|
|
|
|
"low",
|
|
|
|
"info"
|
|
|
|
],
|
2024-04-24 15:19:02 +02:00
|
|
|
"ui-priority": 1
|
|
|
|
},
|
2023-02-17 10:33:59 +01:00
|
|
|
"title": {
|
|
|
|
"description": "Title of blog post.",
|
|
|
|
"misp-attribute": "text",
|
|
|
|
"ui-priority": 1
|
2024-04-24 15:19:02 +02:00
|
|
|
},
|
|
|
|
"website": {
|
|
|
|
"description": "Website of the victim referenced in the post of the ransomware group.",
|
|
|
|
"misp-attribute": "link",
|
|
|
|
"ui-priority": 1
|
2023-02-17 10:33:59 +01:00
|
|
|
}
|
|
|
|
},
|
2024-04-24 15:19:02 +02:00
|
|
|
"description": "Ransomware group post as monitored by ransomlook.io or others",
|
2023-02-17 10:33:59 +01:00
|
|
|
"meta-category": "misc",
|
|
|
|
"name": "ransomware-group-post",
|
|
|
|
"requiredOneOf": [
|
|
|
|
"title",
|
|
|
|
"description",
|
2024-04-24 15:19:02 +02:00
|
|
|
"link",
|
|
|
|
"website",
|
|
|
|
"leak-site-url"
|
2023-02-17 10:33:59 +01:00
|
|
|
],
|
|
|
|
"uuid": "52a0e179-4942-41e6-90f5-7db856fd6f39",
|
2024-04-24 16:42:39 +02:00
|
|
|
"version": 3
|
2023-02-17 10:33:59 +01:00
|
|
|
}
|