medusa_ransomware

This commit is contained in:
Teoderick Contreras
2025-04-01 12:54:03 +02:00
parent 414b521cc4
commit b31f246793
9 changed files with 50 additions and 10 deletions
@@ -1,7 +1,7 @@
name: Common Ransomware Extensions
id: a9e5c5db-db11-43ca-86a8-c852d1b2c0ec
version: '13'
date: '2025-03-25'
date: '2025-04-01'
author: David Dorsey, Michael Haag, Splunk, Steven Dick
status: production
type: TTP
@@ -70,6 +70,7 @@ tags:
- Clop Ransomware
- Ryuk Ransomware
- Black Basta Ransomware
- Termite Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1485
@@ -1,7 +1,7 @@
name: Common Ransomware Notes
id: ada0f478-84a8-4641-a3f1-d82362d6bd71
version: '9'
date: '2025-03-14'
date: '2025-04-01'
author: David Dorsey, Splunk
status: production
type: Hunting
@@ -38,6 +38,7 @@ tags:
- Clop Ransomware
- Ryuk Ransomware
- Black Basta Ransomware
- Termite Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1485
@@ -1,7 +1,7 @@
name: Deleting Shadow Copies
id: b89919ed-ee5f-492c-b139-95dbb162039e
version: '12'
date: '2025-03-25'
date: '2025-04-01'
author: David Dorsey, Splunk
status: production
type: TTP
@@ -83,6 +83,7 @@ tags:
- Clop Ransomware
- Medusa Ransomware
- VanHelsing Ransomware
- Termite Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1490
@@ -58,6 +58,7 @@ tags:
- Crypto Stealer
- Snake Keylogger
- Clop Ransomware
- Termite Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1486
@@ -1,8 +1,8 @@
name: Ransomware Notes bulk creation
id: eff7919a-8330-11eb-83f8-acde48001122
version: '6'
date: '2025-03-14'
author: Teoderick Contreras
version: '7'
date: '2025-04-01'
author: Teoderick Contreras, Splunk
status: production
type: Anomaly
description: The following analytic identifies the bulk creation of ransomware notes
@@ -59,6 +59,7 @@ tags:
- Medusa Ransomware
- Black Basta Ransomware
- Clop Ransomware
- Termite Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1486
@@ -1,7 +1,7 @@
name: Windows Security And Backup Services Stop
id: 9c24aef6-cad9-4931-acce-74318aa5663b
version: 1
date: '2025-02-07'
version: 2
date: '2025-04-01'
author: Teoderick Contreras, Splunk
status: production
type: TTP
@@ -61,6 +61,7 @@ tags:
- Ransomware
- Compromised Windows Host
- BlackMatter Ransomware
- Termite Ransomware
asset_type: Endpoint
mitre_attack_id:
- T1490
+2 -1
View File
@@ -303,4 +303,5 @@ Extensions,Name
*.rhysida,Rhysida
*.basta, BlackBasta
*.vanhelsing,Vanhelsing
*.vanlocker,Vanhelsing
*.vanlocker,Vanhelsing
*.termite,Termite
1 Extensions Name
303 *.rhysida Rhysida
304 *.basta BlackBasta
305 *.vanhelsing Vanhelsing
306 *.vanlocker Vanhelsing
307 *.termite Termite
+2 -1
View File
@@ -72,4 +72,5 @@ read_it.txt,True
*.README.txt, True
*READ_ME_MEDUSA*.TXT,True
How_to_back_files.HTML,True
CriticalBreachDetected.pdf,True
CriticalBreachDetected.pdf,True
How To Restore Your Files.txt, True
1 ransomware_notes status
72 *.README.txt True
73 *READ_ME_MEDUSA*.TXT True
74 How_to_back_files.HTML True
75 CriticalBreachDetected.pdf True
76 How To Restore Your Files.txt True
+32
View File
@@ -0,0 +1,32 @@
name: Termite Ransomware
id: 3dec6aec-3d1a-44f0-affc-31bb201eaec5
version: 1
date: '2025-04-01'
author: Teoderick Contreras, Splunk
status: production
description: Termite Ransomware is a malicious software strain that recently targeted the supply chain management platform Blue Yonder.
It is a sophisticated threat that employs a multi-stage attack strategy. It typically initiates infection via phishing campaigns or
compromised websites, exploiting system vulnerabilities to gain access. Once inside the network, Termite Ransomware escalates privileges
and deploys robust encryption algorithms to lock down critical files, rendering them inaccessible. A ransom note is then left,
instructing victims to pay, even though payment does not guarantee data recovery. The malware is engineered with
defense evasion techniques, such as anti-analysis and anti-virtual machine features, complicating detection and forensic analysis.
narrative: Termite Ransomware is a malicious software strain designed to infiltrate computer systems, encrypt files,
and demand ransom payments from victims. Like a colony of termites silently eating away at wood, this ransomware
spreads stealthily, often spreading through phishing emails, malicious attachments, or exploit kits.
Once activated, Termite Ransomware locks critical files using strong encryption,
rendering them inaccessible to users. Victims typically receive a ransom note demanding payment—usually in
cryptocurrency—to regain access to their files. However, paying the ransom does not guarantee file recovery,
and it often funds further cybercrime. To mitigate risks, users should maintain regular backups, avoid suspicious links,
and employ robust security measures such as antivirus software and endpoint protection.
Cybersecurity experts recommend not paying the ransom and instead seeking professional assistance to attempt data recovery.
references:
- https://www.bleepingcomputer.com/news/security/cisa-confirms-critical-cleo-bug-exploitation-in-ransomware-attacks/
- https://www.darkreading.com/cyberattacks-data-breaches/termite-ransomware-behind-cleo-zero-day-attacks
tags:
category:
- Malware
product:
- Splunk Enterprise
- Splunk Enterprise Security
- Splunk Cloud
usecase: Advanced Threat Detection