Snatch is a ransomware which infects victims by rebooting the PC into Safe Mode. Most of the existing security protections do not run in Safe Mode so that it the malware can act without expected countermeasures and it can encrypt as many files as it finds. It uses common packers such as UPX to hide its payload.
Genera un perfil del actor con IA (defensivo) cuando lo pidas.
Este grupo no tiene TTPs curadas. Puedes generar un mapeo MITRE ESTIMADO por IA (no confirmado) a partir de su descripción/notas, solo cuando lo pidas.
Firma de detección defensiva para este grupo (úsala en tu EDR/SIEM). Fuente: ransomware.live.
import "pe"
rule snatch_ransomware_x3_loader {
meta:
description = "snatch-ransomware - file x3.exe"
author = "DFIR Report"
reference = "https://thedfirreport.com/"
date = "2020-06-17"
hash1 = "b9e4299239880961a88875e1265db0ec62a8c4ad6baf7a5de6f02ff4c31fcdb1"
strings:
$s1 = "jd4ob7162ns.dll" wide fullword
$s2 = "kb05987631s.dll" wide fullword
$s3 = "fw0a53482aa.dll" wide fullword
$s4 = "C:\\Builds\\TP\\rtl\\common\\TypInfo.pas" wide fullword
$s5 = "C:\\Builds\\TP\\rtl\\sys\\SysUtils.pas" wide fullword
$s6 = "C:\\Builds\\TP\\rtl\\common\\Classes.pas" wide fullword
$s7 = "/K schtasks /Create /RU SYSTEM /SC DAILY /ST 00:00 /TN \"Regular Idle Maintenance\" /TR \"" wide fullword
$s8 = "/K schtasks /Create /RU SYSTEM /SC ONSTART /TN \"Regular Idle Maintenances\" /TR \"" wide fullword
$s9 = "RootP0C" ascii fullword
$s10 = "Component already destroyed: " wide fullword
$s11 = "Stream write error The specified file was not found2Length of Strings and Objects arrays must be equal#''%s'' is not a valid int" wide
$s12 = "PPackageTypeInfo$\"@" ascii fullword
$s13 = "PositionP0C" ascii fullword
$s14 = "DesignInfoP0C" ascii fullword
$s15 = "OwnerP0C" ascii fullword
$s16 = "3\"4\\4~4" ascii fullword
$s17 = "TComponentClassP0C" ascii fullword
$s18 = ":$:2:6:L:\\:l:t:x:|:" ascii fullword
$s19 = ":P:T:X:\\:t:" ascii fullword
$s20 = ":,:<:@:L:T:X:\\:`:d:h:l:p:t:x:|:" ascii fullword
condition:
uint16(0) == 0x5a4d and filesize < 900KB and (pe.imphash() == "d6136298ea7484a715d40720221233be" or 8 of them)
}
rule snatch_ransomware_safe_go_ransomware {
meta:
description = "snatch-ransomware - file safe.exe"
author = "DFIR Report"
reference = "https://thedfirreport.com/"
date = "2020-06-17"
hash1 = "3160b4308dd9434ebb99e5747ec90d63722a640d329384b1ed536b59352dace6"
strings:
$s1 = "dumpcb" ascii fullword
$s2 = "dfmaftpgc" ascii fullword
$s3 = "ngtrunw" ascii fullword
$s4 = "_dumpV" ascii fullword
$s5 = ".dll3u^" ascii fullword
$s6 = "D0s[Host#\"0" ascii fullword
$s7 = "CPUIRC32D,OPg" ascii fullword
$s8 = "WSAGetOv" ascii fullword
$s9 = "Head9iuA" ascii fullword
$s10 = "SpyL]ZIo" ascii fullword
$s11 = "cmpbody" ascii fullword
$s12 = "necwnamep" ascii fullword
$s13 = "ZonK+ pW" ascii fullword
$s14 = "printabl" ascii fullword
$s15 = "atomicn" ascii fullword
$s16 = "powrprof" ascii fullword
$s17 = "recdvoc" ascii fullword
$s18 = "nopqrsx" ascii fullword
$s19 = "ghijklm" ascii fullword
$s20 = "spdelta" ascii fullword
condition:
uint16(0) == 0x5a4d and filesize < 8000KB and (pe.imphash() == "6ed4f5f04d62b18d96b26d6db7c18840" or 8 of them)
}Hello! All your files are encrypted and only we can decrypt them. We have downloaded more that 500GB of sensitive data from your company servers. Contact us: [redactado] or [redactado] Write us if you want to return your files - we can do it very quickly! The header of letter must contain extension of encrypted files. We always reply within 24 hours. If not - check spam folder, resend your letter or try send letter from another email service (like protonmail.com). Attention! Do not rename or edit encrypted files: you may have permanent data loss. Do not edit or delete any virtual machines files To prove that we can recover your files, we am ready to decrypt any three files (less than 1Mb) for free (except databases, Excel and backups). HURRY UP! If you do not email us in the next 48 hours then your data may be lost permanently.
Grupo Promerica es un conjunto de instituciones financieras enlazadas a través del holding PROMERICA FINANCIAL CORP (PFC), el cual es dirigido por un equipo multinacional de banqueros, con conocimiento puntual de las actividades económicas y financieras que se llevan a cabo en cada uno de
| Organización | País | Sector | Grupo | Descubierta |
|---|---|---|---|---|
| Banco Promerica | CR | Financial Services | — | 13 ene 2024 |
Las direcciones de los sitios de filtración (.onion) se conocen pero no se publican ni se enlazan. Solo se muestran metadatos públicos. ética