diff --git a/detections/endpoint/common_ransomware_extensions.yml b/detections/endpoint/common_ransomware_extensions.yml index d8c9971977..ebd15cc818 100644 --- a/detections/endpoint/common_ransomware_extensions.yml +++ b/detections/endpoint/common_ransomware_extensions.yml @@ -1,18 +1,32 @@ name: Common Ransomware Extensions id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec -version: 7 -date: '2024-10-17' +version: 8 +date: '2024-12-12' author: David Dorsey, Michael Haag, Splunk, Steven Dick status: production -type: Hunting +type: TTP description: The following analytic detects modifications to files with extensions commonly associated with ransomware. It leverages the Endpoint.Filesystem data model to identify changes in file extensions that match known ransomware patterns. This activity is significant because it suggests an attacker is attempting to encrypt or alter files, potentially leading to severe data loss and operational disruption. If confirmed malicious, this activity could result in the encryption of critical data, rendering it inaccessible and causing significant damage to the organization's data integrity and availability. data_source: - Sysmon EventID 11 -search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime count latest(Filesystem.user) as user values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name Filesystem.dest _time span=1h | `drop_dm_object_name(Filesystem)` | rex field=file_name "(?\.[^\.]+)$" | rex field=file_path "(?([^\\\]*\\\)*).*" | stats min(firstTime) as firstTime max(lastTime) as lastTime latest(user) as user dc(true_file_path) as path_count dc(file_name) as file_count latest(file_name) as file_name latest(true_file_path) as file_path by dest file_extension | `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `ransomware_extensions` | where path_count > 1 OR file_count > 20 | `common_ransomware_extensions_filter`' +search: '| tstats `security_content_summariesonly` min(_time) as firstTime max(_time) as lastTime count latest(Filesystem.user) as user values(Filesystem.file_path) as file_path from datamodel=Endpoint.Filesystem by Filesystem.file_name Filesystem.dest _time span=1h +| `drop_dm_object_name(Filesystem)` +| rex field=file_name "(?\.[^\.]+)$" +| rex field=file_path "(?([^\\\]*\\\)*).*" +| stats min(firstTime) as firstTime max(lastTime) as lastTime latest(user) as user dc(true_file_path) as path_count dc(file_name) as file_count latest(true_file_path) as file_path by dest file_name +| `security_content_ctime(lastTime)` | `security_content_ctime(firstTime)` | `ransomware_extensions` | where path_count > 1 OR file_count > 20 | `common_ransomware_extensions_filter`' how_to_implement: 'You must be ingesting data that records the filesystem activity from your hosts to populate the Endpoint Filesystem data model node. To see the additional metadata, add the following fields, if not already present, please review the detailed documentation on how to create a new field within Incident Review may be found here: `https://docs.splunk.com/Documentation/ES/5.3.0/Admin/Customizenotables#Add_a_field_to_the_notable_event_details`' known_false_positives: It is possible for a legitimate file with these extensions to be created. If this is a true ransomware attack, there will be a large number of files created with these extensions. references: - https://github.com/splunk/security_content/issues/2448 +drilldown_searches: +- name: View the detection results for - "$dest$" and "$user$" + search: '%original_detection_search% | search dest = "$dest$" user = "$user$"' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ +- name: View risk events for the last 7 days for - "$dest$" and "$user$" + search: '| from datamodel Risk.All_Risk | search normalized_risk_object IN ("$dest$","$user$") starthoursago=168 | stats count min(_time) as firstTime max(_time) as lastTime values(search_name) as "Search Name" values(risk_message) as "Risk Message" values(analyticstories) as "Analytic Stories" values(annotations._all) as "Annotations" values(annotations.mitre_attack.mitre_tactic) as "ATT&CK Tactics" by normalized_risk_object | `security_content_ctime(firstTime)` | `security_content_ctime(lastTime)`' + earliest_offset: $info_min_time$ + latest_offset: $info_max_time$ tags: analytic_story: - SamSam Ransomware @@ -25,7 +39,7 @@ tags: asset_type: Endpoint confidence: 100 impact: 90 - message: The device $dest$ wrote $file_count$ files to $path_count$ path(s) with the $file_extension$ extension. This extension and behavior may indicate a $Name$ ransomware attack. + message: The device $dest$ wrote $file_count$ files to $path_count$ path(s) with the $Extensions$ extension. This extension and behavior may indicate a $Name$ ransomware attack. mitre_attack_id: - T1485 observable: diff --git a/lookups/ransomware_extensions_20231219.csv b/lookups/ransomware_extensions_20231219.csv deleted file mode 100644 index 85a53a6a11..0000000000 --- a/lookups/ransomware_extensions_20231219.csv +++ /dev/null @@ -1,303 +0,0 @@ -Extensions,Name -.enc,.CryptoHasYou. -.777,777 -.R4A,7ev3n -.R5A,7ev3n -.7h9r,7h9r -.8lock8,8lock8 -.encrypt,Alpha Ransomware -.amba,AMBA -.adk,Angry Duck -.encrypted,Apocalypse -.SecureCrypted,Apocalypse -.FuckYourData,Apocalypse -.unavailable,Apocalypse -.bleepYourFiles,Apocalypse -.Where_my_files.txt,Apocalypse -.encrypted,ApocalypseVM -.locked,ApocalypseVM -.locky,AutoLocky -.adr,BaksoCrypt -.avos,AvosLocker -.avos2,AvosLocker -.avoslinux,AvosLocker -.bart.zip,Bart -.bart,Bart -.perl,Bart -.clf,BitCryptor -.bitstak,BitStak -.Silent,BlackShades Crypter -.blocatto,Blocatto -.cry,Central Security Treatment Organization -.cerber,Cerber -.cerber2,Cerber -.cerber3,Cerber -.clf,CoinVault -.coverton,Coverton -.enigma,Coverton -.czvxce,Coverton -.criptiko,CryFile -.criptoko,CryFile -.criptokod,CryFile -.cripttt,CryFile -.aga,CryFile -.cry,CryLocker -.ENCRYPTED,Crypren -.crypt38,Crypt38 -.scl,CryptFIle2 -.crinf,CryptInfinite -.frtrss,CryptoFortress -.clf,CryptoGraphic Locker -.crjoker,CryptoJoker -.encrypted ,CryptoLocker -.ENC,CryptoLocker -.code,CryptoMix -.scl,CryptoMix -.crptrgr,CryptoRoger -.locked,CryptoShocker -.CryptoTorLocker2015!,CryptoTorLocker2015 -.crypt,CryptXXX -.crypt,CryptXXX 2.0 -.crypt,CryptXXX 3.0 -.cryp1,CryptXXX 3.0 -.crypz,CryptXXX 3.0 -.cryptz,CryptXXX 3.0 -.cryp1,CryptXXX 3.1 -.ctbl,CTB-Locker -.encrypted,CuteRansomware -.ded,DEDCryptor -.domino,Domino -.locked,EDA2 / HiddenTear -.isis,EduCrypt -.locked,EduCrypt -.ha3,El-Polocker -.enigma,Enigma -.1txt,Enigma -.exotic,Exotic -.locked,Fakben -.fantom,Fantom -.Z81928819,GhostCrypt -.purge,Globe v1 -.globe,Globe v3 -.locked,GNL Locker -.crypt,Gomasom -.herbst,Herbst -.cry,Hi Buddy! -.locky,Hucky -.crime,iLock -.crime,iLockLight -.btc,Jigsaw -.kkk,Jigsaw -.fun,Jigsaw -.gws,Jigsaw -.porno,Jigsaw -.payransom,Jigsaw -.payms,Jigsaw -.paymst,Jigsaw -.AFD,Jigsaw -.paybtcs,Jigsaw -.epic,Jigsaw -.xyz,Jigsaw -.locked,Job Crypter -.encrypted,KeRanger -.keybtc@inbox_com,KeyBTC -.rip,Killer Locker -.kimcilware,KimcilWare -.locked,KimcilWare -.kostya,Kostya -.kratos,KratosCrypt -.LeChiffre,LeChiffre -.locky,Locky -.zepto,Locky -.odin,Locky -.shit,Locky -.thor,Locky -.asier,Locky -.zzzzz,Locky -.osiris,Locky -.lock93,Lock93 -.crime,Lortok -.oor,LowLevel04 -.magic,Magic -.Lock,MIRCOP -.fucked,MireWare -.fuck,MireWare -.locked,MM Locker -.KEYZ,Mobef -.KEYH0LES,Mobef -.crypted,Nemucod -.odcodc,ODCODC -.cbf,Offline ransomware -.LOL!,OMG! Ransomware -.OMG!,OMG! Ransomware -.padcrypt,PadCrypt -.locked,Philadelphia -.locked,PokemonGO -.filock,Popcorn Time -.locky,PowerWare -.crypt,R980 -.locked,RAA encryptor -.RDM,Radamant -.RRK,Radamant -.RAD,Radamant -.RADAMANT,Radamant -.locked,Rakhni -.kraken,Rakhni -.darkness,Rakhni -.nochance,Rakhni -.oshit,Rakhni -.oplata@qq_com,Rakhni -.relock@qq_com,Rakhni -.crypto,Rakhni -.helpdecrypt@ukr.net,Rakhni -.pizda@qq_com,Rakhni -.dyatel@qq_com,Rakhni -._ryp,Rakhni -.nalog@qq_com,Rakhni -.chifrator@qq_com,Rakhni -.gruzin@qq_com,Rakhni -.troyancoder@qq_com,Rakhni -.encrypted,Rakhni -.cry,Rakhni -.AES256,Rakhni -.enc,Rakhni -.hb15,Rakhni -.vscrypt,Rector -.infected,Rector -.bloc,Rector -.korrektor,Rector -.rekt,RektLocker -.remind,RemindMe -.crashed,RemindMe -.rokku,Rokku -.encryptedAES,Samas-Samsam -.encryptedRSA,Samas-Samsam -.encedRSA,Samas-Samsam -.justbtcwillhelpyou,Samas-Samsam -.btcbtcbtc,Samas-Samsam -.btc-help-you,Samas-Samsam -.only-we_can-help_you,Samas-Samsam -.iwanthelpuuu,Samas-Samsam -.notfoundrans,Samas-Samsam -.encmywork,Samas-Samsam -.weapologize,Samas-Samsam -.stubbin,Samas-Samsam -.areyoulovemyrans,Samas-Samsam -.loveransisgood,Samas-Samsam -.myransext2017,Samas-Samsam -.disposed2017,Samas-Samsam -.prosperous666,Samas-Samsam -.supported2017,Samas-Samsam -.country82000,Samas-Samsam -.moments2900,Samas-Samsam -.breeding123,Samas-Samsam -.mention9823,Samas-Samsam -.suppose666,Samas-Samsam -.skjdthghh,Samas-Samsam -.cifgksaffsfyghd,Samas-Samsam -.iaufkakfhsaraf,Samas-Samsam -.filegofprencrp,Samas-Samsam -.weencedufiles,Samas-Samsam -.encryptedyourfiles,Samas-Samsam -.letmetrydecfiles,Samas-Samsam -.otherinformation,Samas-Samsam -.weareyourfriends,Samas-Samsam -.noproblemwedecfiles,Samas-Samsam -.powerfulldecrypt,Samas-Samsam -.wowreadfordecryp,Samas-Samsam -.wowwhereismyfiles,Samas-Samsam -.helpmeencedfiles,Samas-Samsam -.theworldisyours,Samas-Samsam -.vekanhelpu,Samas-Samsam -.howcanihelpusir,Samas-Samsam -.VforVendetta,Samas-Samsam -.checkdiskenced,Samas-Samsam -.goforhelp,Samas-Samsam -.iloveworld,Samas-Samsam -.canihelpyou,Samas-Samsam -.AreYouLoveMyRansFile,Samas-Samsam -.fucku,Samas-Samsam -.happenencedfiles,Samas-Samsam -.iwishiyou,Samas-Samsam -.powerfulldecryp,Samas-Samsam -.suppose665,Samas-Samsam -.Whereisyourfiles,Samas-Samsam -.sanction,Sanction -.locked,Shark -.shino,ShinoLocker -.locked,SkidLocker / Pompous -.encrypted,Smrss32 -.RSNSlocked,SNSLocker -.RSplited,SNSLocker -.sport,Sport -.locked,Stampado -.locked,Strictor -.surprise,Surprise -.tzu,Surprise -.szf,SZFLocker -.xcri,TeleCrypt -.vvv,TeslaCrypt 0.x - 2.2.0 -.ecc,TeslaCrypt 0.x - 2.2.0 -.exx,TeslaCrypt 0.x - 2.2.0 -.ezz,TeslaCrypt 0.x - 2.2.0 -.abc,TeslaCrypt 0.x - 2.2.0 -.aaa,TeslaCrypt 0.x - 2.2.0 -.zzz,TeslaCrypt 0.x - 2.2.0 -.xyz,TeslaCrypt 0.x - 2.2.0 -.micro,TeslaCrypt 3.0+ -.xxx,TeslaCrypt 3.0+ -.ttt,TeslaCrypt 3.0+ -.mp3,TeslaCrypt 3.0+ -.Encrypted,TorrentLocker -.enc,TorrentLocker -.toxcrypt,Toxcrypt -.better_call_saul,Troldesh -.xtbl,Troldesh -.da_vinci_code,Troldesh -.windows10,Troldesh -.enc,TrueCrypter -.locked,Turkish Ransom -.H3LL,Ungluk -.0x0,Ungluk -.1999,Ungluk -.CRRRT,Unlock92 -.CCCRRRPPP,Unlock92 -.vault,VaultCrypt -.xort,VaultCrypt -.trun,VaultCrypt -.Venusf,VenusLocker -.Venusp,VenusLocker -.CrySiS,Virus-Encoder -.xtbl,Virus-Encoder -.wflx,WildFire Locker -.EnCiPhErEd,Xorist -.73i87A,Xorist -.p5tkjw,Xorist -.PoAr2w,Xorist -.fileiscryptedhard,Xorist -.encoderpass,Xorist -.zc3791,Xorist -.xrtn,XRTN -.zcrypt,Zcrypt -.crypto,Zimbra -.vault,Zlader / Russian -.zyklon,Zyklon -.wncry,WannaCry -.wcry,WannaCry -.wnry,WannaCry -.wncryt,WannaCry -.WNCRYT,WannaCry -.RYK,Ryuk -.Clop,Clop -.Cllp,Clop -.JSWORM,JSWorm -.NEMTY_*,Nemty -.NEFILIM,Nefilim -.OFFWHITE,Offwhite -.TELEGRAM,Telegram -.FUSION,Fusion -.MILIHPEN,Milihpen -.GANGBANG,Gangbang -.reddot,RedDot -.MEDUSA,Medusa -.rhysida,Rhysida \ No newline at end of file diff --git a/lookups/ransomware_extensions_20241212.csv b/lookups/ransomware_extensions_20241212.csv new file mode 100644 index 0000000000..38cca70a09 --- /dev/null +++ b/lookups/ransomware_extensions_20241212.csv @@ -0,0 +1,303 @@ +Extensions,Name +*.enc,.CryptoHasYou. +*.777,777 +*.R4A,7ev3n +*.R5A,7ev3n +*.7h9r,7h9r +*.8lock8,8lock8 +*.encrypt,Alpha Ransomware +*.amba,AMBA +*.adk,Angry Duck +*.encrypted,Apocalypse +*.SecureCrypted,Apocalypse +*.FuckYourData,Apocalypse +*.unavailable,Apocalypse +*.bleepYourFiles,Apocalypse +*.Where_my_files.txt,Apocalypse +*.encrypted,ApocalypseVM +*.locked,ApocalypseVM +*.locky,AutoLocky +*.adr,BaksoCrypt +*.avos,AvosLocker +*.avos2,AvosLocker +*.avoslinux,AvosLocker +*.bart.zip,Bart +*.bart,Bart +*.perl,Bart +*.clf,BitCryptor +*.bitstak,BitStak +*.Silent,BlackShades Crypter +*.blocatto,Blocatto +*.cry,Central Security Treatment Organization +*.cerber,Cerber +*.cerber2,Cerber +*.cerber3,Cerber +*.clf,CoinVault +*.coverton,Coverton +*.enigma,Coverton +*.czvxce,Coverton +*.criptiko,CryFile +*.criptoko,CryFile +*.criptokod,CryFile +*.cripttt,CryFile +*.aga,CryFile +*.cry,CryLocker +*.ENCRYPTED,Crypren +*.crypt38,Crypt38 +*.scl,CryptFIle2 +*.crinf,CryptInfinite +*.frtrss,CryptoFortress +*.clf,CryptoGraphic Locker +*.crjoker,CryptoJoker +*.encrypted ,CryptoLocker +*.ENC,CryptoLocker +*.code,CryptoMix +*.scl,CryptoMix +*.crptrgr,CryptoRoger +*.locked,CryptoShocker +*.CryptoTorLocker2015!,CryptoTorLocker2015 +*.crypt,CryptXXX +*.crypt,CryptXXX 2.0 +*.crypt,CryptXXX 3.0 +*.cryp1,CryptXXX 3.0 +*.crypz,CryptXXX 3.0 +*.cryptz,CryptXXX 3.0 +*.cryp1,CryptXXX 3.1 +*.ctbl,CTB-Locker +*.encrypted,CuteRansomware +*.ded,DEDCryptor +*.domino,Domino +*.locked,EDA2 / HiddenTear +*.isis,EduCrypt +*.locked,EduCrypt +*.ha3,El-Polocker +*.enigma,Enigma +*.1txt,Enigma +*.exotic,Exotic +*.locked,Fakben +*.fantom,Fantom +*.Z81928819,GhostCrypt +*.purge,Globe v1 +*.globe,Globe v3 +*.locked,GNL Locker +*.crypt,Gomasom +*.herbst,Herbst +*.cry,Hi Buddy! +*.locky,Hucky +*.crime,iLock +*.crime,iLockLight +*.btc,Jigsaw +*.kkk,Jigsaw +*.fun,Jigsaw +*.gws,Jigsaw +*.porno,Jigsaw +*.payransom,Jigsaw +*.payms,Jigsaw +*.paymst,Jigsaw +*.AFD,Jigsaw +*.paybtcs,Jigsaw +*.epic,Jigsaw +*.xyz,Jigsaw +*.locked,Job Crypter +*.encrypted,KeRanger +*.keybtc@inbox_com,KeyBTC +*.rip,Killer Locker +*.kimcilware,KimcilWare +*.locked,KimcilWare +*.kostya,Kostya +*.kratos,KratosCrypt +*.LeChiffre,LeChiffre +*.locky,Locky +*.zepto,Locky +*.odin,Locky +*.shit,Locky +*.thor,Locky +*.asier,Locky +*.zzzzz,Locky +*.osiris,Locky +*.lock93,Lock93 +*.crime,Lortok +*.oor,LowLevel04 +*.magic,Magic +*.Lock,MIRCOP +*.fucked,MireWare +*.fuck,MireWare +*.locked,MM Locker +*.KEYZ,Mobef +*.KEYH0LES,Mobef +*.crypted,Nemucod +*.odcodc,ODCODC +*.cbf,Offline ransomware +*.LOL!,OMG! Ransomware +*.OMG!,OMG! Ransomware +*.padcrypt,PadCrypt +*.locked,Philadelphia +*.locked,PokemonGO +*.filock,Popcorn Time +*.locky,PowerWare +*.crypt,R980 +*.locked,RAA encryptor +*.RDM,Radamant +*.RRK,Radamant +*.RAD,Radamant +*.RADAMANT,Radamant +*.locked,Rakhni +*.kraken,Rakhni +*.darkness,Rakhni +*.nochance,Rakhni +*.oshit,Rakhni +*.oplata@qq_com,Rakhni +*.relock@qq_com,Rakhni +*.crypto,Rakhni +*.helpdecrypt@ukr.net,Rakhni +*.pizda@qq_com,Rakhni +*.dyatel@qq_com,Rakhni +*._ryp,Rakhni +*.nalog@qq_com,Rakhni +*.chifrator@qq_com,Rakhni +*.gruzin@qq_com,Rakhni +*.troyancoder@qq_com,Rakhni +*.encrypted,Rakhni +*.cry,Rakhni +*.AES256,Rakhni +*.enc,Rakhni +*.hb15,Rakhni +*.vscrypt,Rector +*.infected,Rector +*.bloc,Rector +*.korrektor,Rector +*.rekt,RektLocker +*.remind,RemindMe +*.crashed,RemindMe +*.rokku,Rokku +*.encryptedAES,Samas-Samsam +*.encryptedRSA,Samas-Samsam +*.encedRSA,Samas-Samsam +*.justbtcwillhelpyou,Samas-Samsam +*.btcbtcbtc,Samas-Samsam +*.btc-help-you,Samas-Samsam +*.only-we_can_help_you,Samas-Samsam +*.iwanthelpuuu,Samas-Samsam +*.notfoundrans,Samas-Samsam +*.encmywork,Samas-Samsam +*.weapologize,Samas-Samsam +*.stubbin,Samas-Samsam +*.areyoulovemyrans,Samas-Samsam +*.loveransisgood,Samas-Samsam +*.myransext2017,Samas-Samsam +*.disposed2017,Samas-Samsam +*.prosperous666,Samas-Samsam +*.supported2017,Samas-Samsam +*.country82000,Samas-Samsam +*.moments2900,Samas-Samsam +*.breeding123,Samas-Samsam +*.mention9823,Samas-Samsam +*.suppose666,Samas-Samsam +*.skjdthghh,Samas-Samsam +*.cifgksaffsfyghd,Samas-Samsam +*.iaufkakfhsaraf,Samas-Samsam +*.filegofprencrp,Samas-Samsam +*.weencedufiles,Samas-Samsam +*.encryptedyourfiles,Samas-Samsam +*.letmetrydecfiles,Samas-Samsam +*.otherinformation,Samas-Samsam +*.weareyourfriends,Samas-Samsam +*.noproblemwedecfiles,Samas-Samsam +*.powerfulldecrypt,Samas-Samsam +*.wowreadfordecryp,Samas-Samsam +*.wowwhereismyfiles,Samas-Samsam +*.helpmeencedfiles,Samas-Samsam +*.theworldisyours,Samas-Samsam +*.vekanhelpu,Samas-Samsam +*.howcanihelpusir,Samas-Samsam +*.VforVendetta,Samas-Samsam +*.checkdiskenced,Samas-Samsam +*.goforhelp,Samas-Samsam +*.iloveworld,Samas-Samsam +*.canihelpyou,Samas-Samsam +*.AreYouLoveMyRansFile,Samas-Samsam +*.fucku,Samas-Samsam +*.happenencedfiles,Samas-Samsam +*.iwishiyou,Samas-Samsam +*.powerfulldecryp,Samas-Samsam +*.suppose665,Samas-Samsam +*.Whereisyourfiles,Samas-Samsam +*.sanction,Sanction +*.locked,Shark +*.shino,ShinoLocker +*.locked,SkidLocker / Pompous +*.encrypted,Smrss32 +*.RSNSlocked,SNSLocker +*.RSplited,SNSLocker +*.sport,Sport +*.locked,Stampado +*.locked,Strictor +*.surprise,Surprise +*.tzu,Surprise +*.szf,SZFLocker +*.xcri,TeleCrypt +*.vvv,TeslaCrypt 0.x - 2.2.0 +*.ecc,TeslaCrypt 0.x - 2.2.0 +*.exx,TeslaCrypt 0.x - 2.2.0 +*.ezz,TeslaCrypt 0.x - 2.2.0 +*.abc,TeslaCrypt 0.x - 2.2.0 +*.aaa,TeslaCrypt 0.x - 2.2.0 +*.zzz,TeslaCrypt 0.x - 2.2.0 +*.xyz,TeslaCrypt 0.x - 2.2.0 +*.micro,TeslaCrypt 3.0+ +*.xxx,TeslaCrypt 3.0+ +*.ttt,TeslaCrypt 3.0+ +*.mp3,TeslaCrypt 3.0+ +*.Encrypted,TorrentLocker +*.enc,TorrentLocker +*.toxcrypt,Toxcrypt +*.better_call_saul,Troldesh +*.xtbl,Troldesh +*.da_vinci_code,Troldesh +*.windows10,Troldesh +*.enc,TrueCrypter +*.locked,Turkish Ransom +*.H3LL,Ungluk +*.0x0,Ungluk +*.1999,Ungluk +*.CRRRT,Unlock92 +*.CCCRRRPPP,Unlock92 +*.vault,VaultCrypt +*.xort,VaultCrypt +*.trun,VaultCrypt +*.Venusf,VenusLocker +*.Venusp,VenusLocker +*.CrySiS,Virus-Encoder +*.xtbl,Virus-Encoder +*.wflx,WildFire Locker +*.EnCiPhErEd,Xorist +*.73i87A,Xorist +*.p5tkjw,Xorist +*.PoAr2w,Xorist +*.fileiscryptedhard,Xorist +*.encoderpass,Xorist +*.zc3791,Xorist +*.xrtn,XRTN +*.zcrypt,Zcrypt +*.crypto,Zimbra +*.vault,Zlader / Russian +*.zyklon,Zyklon +*.wncry,WannaCry +*.wcry,WannaCry +*.wnry,WannaCry +*.wncryt,WannaCry +*.WNCRYT,WannaCry +*.RYK,Ryuk +*.Clop,Clop +*.Cllp,Clop +*.JSWORM,JSWorm +*.NEMTY_*,Nemty +*.NEFILIM,Nefilim +*.OFFWHITE,Offwhite +*.TELEGRAM,Telegram +*.FUSION,Fusion +*.MILIHPEN,Milihpen +*.GANGBANG,Gangbang +*.reddot,RedDot +*.MEDUSA,Medusa +*.rhysida,Rhysida \ No newline at end of file diff --git a/lookups/ransomware_extensions_lookup.yml b/lookups/ransomware_extensions_lookup.yml index e86befe1c4..41bb4c2b93 100644 --- a/lookups/ransomware_extensions_lookup.yml +++ b/lookups/ransomware_extensions_lookup.yml @@ -1,6 +1,6 @@ default_match: 'false' description: A list of file extensions that are associated with ransomware -filename: ransomware_extensions_20231219.csv +filename: ransomware_extensions_20241212.csv match_type: WILDCARD(Extensions) min_matches: 1 name: ransomware_extensions_lookup diff --git a/macros/ransomware_extensions.yml b/macros/ransomware_extensions.yml index c9de5c4ad0..fde2314d76 100644 --- a/macros/ransomware_extensions.yml +++ b/macros/ransomware_extensions.yml @@ -1,5 +1,4 @@ -definition: lookup update=true ransomware_extensions_lookup Extensions AS file_extension - OUTPUT Name | search Name !=False +definition: lookup update=true ransomware_extensions_lookup Extensions AS file_name OUTPUT Extensions Name | search Name !=False description: This macro limits the output to files that have extensions associated with ransomware name: ransomware_extensions