|
| 1 | += Ramsay |
| 2 | + |
| 3 | +For a description of Ramsay, please see the article on |
| 4 | +https://www.welivesecurity.com/2020/05/13/ramsay-cyberespionage-toolkit-airgapped-networks/[WeLiveSecurity]. |
| 5 | + |
| 6 | +== MISP event |
| 7 | + |
| 8 | +link:misp-ramsay.json[MISP event] |
| 9 | + |
| 10 | +== ESET detection names |
| 11 | + |
| 12 | +- Win32/Exploit.CVE-2017-11882.H |
| 13 | +- Win32/HackTool.UACMe.T |
| 14 | +- Win32/HideProc.M |
| 15 | +- Win32/Ramsay.A |
| 16 | +- Win32/Ramsay.B |
| 17 | +- Win32/Ramsay.C |
| 18 | +- Win32/TrojanDropper.Agent.SHM |
| 19 | +- Win32/TrojanDropper.Agent.SHN |
| 20 | +- Win64/HackTool.Inject.A |
| 21 | +- Win64/Ramsay.C |
| 22 | + |
| 23 | +== Host based indicators |
| 24 | +=== SHA-1 hashes |
| 25 | + |
| 26 | +---- |
| 27 | +19bf019fc0bf44828378f008332430a080871274 |
| 28 | +3849e01bff610d155a3153c897bb662f5527c04c |
| 29 | +3bb205698e89955b4bd07a8a7de3fc75f1cb5cde |
| 30 | +50eb291fc37fe05f9e55140b98b68d77bd61149e |
| 31 | +5a5738e2ec8af9f5400952be923e55a5780a8c55 |
| 32 | +5c482bb8623329d4764492ff78b4fbc673b2ef23 |
| 33 | +62d2cc1f6eedba2f35a55beb96cd59a0a6c66880 |
| 34 | +7d85b163d19942bb8d047793ff78ea728da19870 |
| 35 | +87ef7bf00fe6aa928c111c472e2472d2cb047eae |
| 36 | +ae722a90098d1c95829480e056ef8fd4a98eedd7 |
| 37 | +baa20ce99089fc35179802a0cc1149f929bdf0fa |
| 38 | +bd8d0143ec75ef4c369f341c2786facbd9f73256 |
| 39 | +bd97b31998e9d673661ea5697fe436efe026cba1 |
| 40 | +e7987627200d542bb30d6f2386997f668b8a928c |
| 41 | +eb69b45faf3be0135f44293bc95f06dad73bc562 |
| 42 | +f74d86b6e9bd105ab65f2af10d60c4074b8044c9 |
| 43 | +f79da0d8bb1267f9906fad1111bd929a41b18c03 |
| 44 | +---- |
| 45 | + |
| 46 | +=== Ramsay filenames |
| 47 | + |
| 48 | +---- |
| 49 | +%APPDATA%\Microsoft\UserSetting |
| 50 | +%APPDATA%\Microsoft\UserSetting\MediaCache |
| 51 | +%ALLUSERSPROFILE%\NetCache\ |
| 52 | +%ALLUSERSPROFILE%\MediaCache |
| 53 | +%WINDIR%\System32\wimsvc.exe |
| 54 | +%WINDIR%\System32\drivers\hfile.sys |
| 55 | +%WINDIR%\System32\Identities\bindsvc.exe |
| 56 | +%WINDIR%\System32\Identities\wideshut.exe |
| 57 | +%WINDIR%\System32\msfte.dll |
| 58 | +%WINDIR%\System32\oci.dll |
| 59 | +7z920.exe |
| 60 | +dpnom.dll |
| 61 | +netwiz.exe |
| 62 | +racfg.exe |
| 63 | +lmsch.exe |
| 64 | +slmgr.vbs |
| 65 | +sharp.exe |
| 66 | +byinfo.exe |
| 67 | +---- |
0 commit comments