{
  "Event": {
    "analysis": "2",
    "date": "2016-03-10",
    "extends_uuid": "",
    "info": "OSINT - The Cerber Ransomware not only Encrypts Your Data But Also Speaks to You",
    "publish_timestamp": "1457596187",
    "published": true,
    "threat_level_id": "3",
    "timestamp": "1457596013",
    "uuid": "56e123a7-dc1c-4c74-af4a-4d8b950d210f",
    "Orgc": {
      "name": "CIRCL",
      "uuid": "55f6ea5e-2c60-40e5-964f-47a8950d210f"
    },
    "Tag": [
      {
        "colour": "#004646",
        "local": false,
        "name": "type:OSINT",
        "relationship_type": ""
      },
      {
        "colour": "#ffffff",
        "local": false,
        "name": "tlp:white",
        "relationship_type": ""
      },
      {
        "colour": "#006c6c",
        "local": false,
        "name": "ecsirt:malicious-code=\"ransomware\"",
        "relationship_type": ""
      }
    ],
    "Attribute": [
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595388",
        "to_ids": false,
        "type": "link",
        "uuid": "56e123fc-ba64-462a-bff0-46b7950d210f",
        "value": "http://www.bleepingcomputer.com/news/security/the-cerber-ransomware-not-only-encrypts-your-data-but-also-speaks-to-you/"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595598",
        "to_ids": false,
        "type": "comment",
        "uuid": "56e124ce-5acc-496c-8368-457c950d210f",
        "value": "A ransomware called Cerber has been floating around for about a week, but we were not able to retrieve a sample until today. Thanks to @BiebsMalwareGuy and @MeegulWorth, samples were found and further analysis of the ransomware could be done.  When infected, a victim's data files will be encrypted using AES encryption and will be told they need to pay a ransom of 1.24 bitcoins or ~500 USD to get their files back. Unfortunately, at this point there is no known way to decrypt a victim's encrypted files for free.\r\n\r\nAt this time we do not currently know how the Cerber ransomware is being distributed, but according to SenseCy, it is being offered as a service on a closed underground Russian forum. This means that it is probably a new Ransomware as a Service, or RaaS, where affiliates can join in order to distribute the ransomware, while the Cerber developers earn a commission from each ransom payment."
      },
      {
        "category": "Persistence mechanism",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595762",
        "to_ids": false,
        "type": "filename",
        "uuid": "56e12572-a3a4-40de-8e11-4f58950d210f",
        "value": "\"%AppData%\\{2ED2A2FE-872C-D4A0-17AC-E301404F1CBA}\\[random].exe\""
      },
      {
        "category": "Artifacts dropped",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595830",
        "to_ids": true,
        "type": "filename",
        "uuid": "56e125b6-fed8-4d52-a48a-4676950d210f",
        "value": "%AppData%\\{2ED2A2FE-872C-D4A0-17AC-E301404F1CBA}\\"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595970",
        "to_ids": true,
        "type": "sha1",
        "uuid": "56e12642-0dac-454a-bfde-45d7950d210f",
        "value": "920ba9c21b519ad7dfb9075c3860d85061cede15"
      },
      {
        "category": "Payload delivery",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595970",
        "to_ids": true,
        "type": "sha1",
        "uuid": "56e12642-0c94-49b1-8d38-4c97950d210f",
        "value": "0af6bde11eaa699604aa92cce9a6210dfce70f42"
      },
      {
        "category": "Payload delivery",
        "comment": "- Xchecked via VT: 0af6bde11eaa699604aa92cce9a6210dfce70f42",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595983",
        "to_ids": true,
        "type": "sha256",
        "uuid": "56e1264f-5a74-4ab0-9a0e-4e0202de0b81",
        "value": "a5ff5f861bbb1ac7c6fd44f303f735fac01273ce2ae43a8acb683076192fcfcc"
      },
      {
        "category": "Payload delivery",
        "comment": "- Xchecked via VT: 0af6bde11eaa699604aa92cce9a6210dfce70f42",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595983",
        "to_ids": true,
        "type": "md5",
        "uuid": "56e1264f-7cf0-4b35-ad01-4f5402de0b81",
        "value": "2f7059d7b1dda3080e391d99788fff18"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595984",
        "to_ids": false,
        "type": "link",
        "uuid": "56e12650-6508-4a93-8d95-456202de0b81",
        "value": "https://www.virustotal.com/file/a5ff5f861bbb1ac7c6fd44f303f735fac01273ce2ae43a8acb683076192fcfcc/analysis/1457487902/"
      },
      {
        "category": "Payload delivery",
        "comment": "- Xchecked via VT: 920ba9c21b519ad7dfb9075c3860d85061cede15",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595984",
        "to_ids": true,
        "type": "sha256",
        "uuid": "56e12650-dfb4-4ee8-862b-42ce02de0b81",
        "value": "2d08ffeba708fb833404d2c320ea4f29365c791d504181e08e3e9b529f5cf096"
      },
      {
        "category": "Payload delivery",
        "comment": "- Xchecked via VT: 920ba9c21b519ad7dfb9075c3860d85061cede15",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595984",
        "to_ids": true,
        "type": "md5",
        "uuid": "56e12650-94d0-4eb5-be41-4b4b02de0b81",
        "value": "f5146a3bbe6c71e5a0ef2f04f955b1a1"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457595985",
        "to_ids": false,
        "type": "link",
        "uuid": "56e12651-3f8c-43b6-af08-41cd02de0b81",
        "value": "https://www.virustotal.com/file/2d08ffeba708fb833404d2c320ea4f29365c791d504181e08e3e9b529f5cf096/analysis/1457125203/"
      },
      {
        "category": "External analysis",
        "comment": "",
        "deleted": false,
        "disable_correlation": false,
        "timestamp": "1457596013",
        "to_ids": false,
        "type": "link",
        "uuid": "56e1266d-b384-4121-afb8-47bb950d210f",
        "value": "http://blog.trendmicro.com/trendlabs-security-intelligence/cerber-crypto-ransomware-speaks-sold-russian-underground/"
      }
    ]
  }
}