Skip to content

Commit 56f61eb

Browse files
committed
Added IoCs for Ramsay.
1 parent 36a6707 commit 56f61eb

File tree

5 files changed

+1876
-0
lines changed

5 files changed

+1876
-0
lines changed

ramsay/README.adoc

Lines changed: 67 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,67 @@
1+
= Ramsay
2+
3+
For a description of Ramsay, please see the article on
4+
https://www.welivesecurity.com/2020/05/13/ramsay-cyberespionage-toolkit-airgapped-networks/[WeLiveSecurity].
5+
6+
== MISP event
7+
8+
link:misp-ramsay.json[MISP event]
9+
10+
== ESET detection names
11+
12+
- Win32/Exploit.CVE-2017-11882.H
13+
- Win32/HackTool.UACMe.T
14+
- Win32/HideProc.M
15+
- Win32/Ramsay.A
16+
- Win32/Ramsay.B
17+
- Win32/Ramsay.C
18+
- Win32/TrojanDropper.Agent.SHM
19+
- Win32/TrojanDropper.Agent.SHN
20+
- Win64/HackTool.Inject.A
21+
- Win64/Ramsay.C
22+
23+
== Host based indicators
24+
=== SHA-1 hashes
25+
26+
----
27+
19bf019fc0bf44828378f008332430a080871274
28+
3849e01bff610d155a3153c897bb662f5527c04c
29+
3bb205698e89955b4bd07a8a7de3fc75f1cb5cde
30+
50eb291fc37fe05f9e55140b98b68d77bd61149e
31+
5a5738e2ec8af9f5400952be923e55a5780a8c55
32+
5c482bb8623329d4764492ff78b4fbc673b2ef23
33+
62d2cc1f6eedba2f35a55beb96cd59a0a6c66880
34+
7d85b163d19942bb8d047793ff78ea728da19870
35+
87ef7bf00fe6aa928c111c472e2472d2cb047eae
36+
ae722a90098d1c95829480e056ef8fd4a98eedd7
37+
baa20ce99089fc35179802a0cc1149f929bdf0fa
38+
bd8d0143ec75ef4c369f341c2786facbd9f73256
39+
bd97b31998e9d673661ea5697fe436efe026cba1
40+
e7987627200d542bb30d6f2386997f668b8a928c
41+
eb69b45faf3be0135f44293bc95f06dad73bc562
42+
f74d86b6e9bd105ab65f2af10d60c4074b8044c9
43+
f79da0d8bb1267f9906fad1111bd929a41b18c03
44+
----
45+
46+
=== Ramsay filenames
47+
48+
----
49+
%APPDATA%\Microsoft\UserSetting
50+
%APPDATA%\Microsoft\UserSetting\MediaCache
51+
%ALLUSERSPROFILE%\NetCache\
52+
%ALLUSERSPROFILE%\MediaCache
53+
%WINDIR%\System32\wimsvc.exe
54+
%WINDIR%\System32\drivers\hfile.sys
55+
%WINDIR%\System32\Identities\bindsvc.exe
56+
%WINDIR%\System32\Identities\wideshut.exe
57+
%WINDIR%\System32\msfte.dll
58+
%WINDIR%\System32\oci.dll
59+
7z920.exe
60+
dpnom.dll
61+
netwiz.exe
62+
racfg.exe
63+
lmsch.exe
64+
slmgr.vbs
65+
sharp.exe
66+
byinfo.exe
67+
----

0 commit comments

Comments
 (0)