File size: 2,383 Bytes
5fe70fd
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
{
    "type": "bundle",
    "id": "bundle--f2f9e75a-b164-4712-bb6a-e01970e9cac4",
    "spec_version": "2.0",
    "objects": [
        {
            "object_marking_refs": [
                "marking-definition--fa42a846-8d90-4e51-bc29-71d5b4802168"
            ],
            "id": "relationship--00192a5f-9dc0-445a-b010-d77bd08aac93",
            "type": "relationship",
            "created": "2021-05-26T14:50:00.881Z",
            "created_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5",
            "external_references": [
                {
                    "source_name": "BlackBerry CostaRicto November 2020",
                    "url": "https://blogs.blackberry.com/en/2020/11/the-costaricto-campaign-cyber-espionage-outsourced",
                    "description": "The BlackBerry Research and Intelligence Team. (2020, November 12). The CostaRicto Campaign: Cyber-Espionage Outsourced. Retrieved May 24, 2021."
                },
                {
                    "source_name": "FireEye FiveHands April 2021",
                    "url": "https://www.fireeye.com/blog/threat-research/2021/04/unc2447-sombrat-and-fivehands-ransomware-sophisticated-financial-threat.html",
                    "description": "McLellan, T.  and Moore, J. et al. (2021, April 29). UNC2447 SOMBRAT and FIVEHANDS Ransomware: A Sophisticated Financial Threat. Retrieved June 2, 2021."
                },
                {
                    "source_name": "CISA AR21-126A FIVEHANDS May 2021",
                    "url": "https://us-cert.cisa.gov/ncas/analysis-reports/ar21-126a",
                    "description": "CISA. (2021, May 6). Analysis Report (AR21-126A) FiveHands Ransomware. Retrieved June 7, 2021."
                }
            ],
            "modified": "2021-06-08T13:29:06.838Z",
            "description": "[SombRAT](https://attack.mitre.org/software/S0615) can SSL encrypt C2 traffic.(Citation: BlackBerry CostaRicto November 2020)(Citation: FireEye FiveHands April 2021)(Citation: CISA AR21-126A FIVEHANDS May 2021)",
            "relationship_type": "uses",
            "source_ref": "malware--425771c5-48b4-4ecd-9f95-74ed3fc9da59",
            "target_ref": "attack-pattern--bf176076-b789-408e-8cba-7275e81c0ada",
            "x_mitre_version": "1.0",
            "x_mitre_modified_by_ref": "identity--c78cb6e5-0c4b-4611-8297-d1b8b55e40b5"
        }
    ]
}