Trusted Design

Jaff Ransomware Gets Makeover - SANS Internet Storm Center

概要

Since 2017-05-11, a new ransomware named Jaff has been distributed through malicious spam (malspam) from the Necurs botnet. This malspam uses PDF attachments with embedded Word documents containing malicious macros. Victims must open the PDF attachment, agree to open the embedded Word document, then enable macros on the embedded Word document to infect their Windows computers. Prior to Jaff, weve seen waves of malspam using the same PDF attachment/embedded Word doc scheme to push Locky ransomware. Prior to that, this type of malspam was pushing Dridex. With all the recent news about WannaCry ransomware, people might forget Jaff is an ongoing threat. Worse yet, some people might not know about it at all since its debut about 2 weeks ago. Jaff has already gotten a makeover, so an infected host looks noticeably different now. With that in mind, todays diary reviews a wave of malspam pushing Jaff ransomware from Tuesday 2017-05-23.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 11.35
Matched TTPs:
  • T1036.007 - Double File Extension
  • T1608.001 - Upload Malware
  • T1036.004 - Masquerade Task or Service
  • T1055.012 - Process Hollowing
MITREへのリンク →

Mustang Panda

Score: 7.60
Matched TTPs:
  • T1036.007 - Double File Extension
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1583.008 - Malvertising
  • T1608.001 - Upload Malware
MITREへのリンク →

Sandworm Team

Score: 7.09
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1584.005 - Botnet
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

TA2541

Score: 5.12
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055.012 - Process Hollowing
MITREへのリンク →

LuminousMoth

Score: 4.57
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1560 - Archive Collected Data
MITREへのリンク →

OilRig

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Gamaredon Group

Score: 9.66
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1001 - Data Obfuscation
  • T1221 - Template Injection
MITREへのリンク →

Threat Group-3390

Score: 6.62
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1055.012 - Process Hollowing
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

BlackByte

Score: 11.34
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1567 - Exfiltration Over Web Service
  • T1560 - Archive Collected Data
  • T1055.012 - Process Hollowing
MITREへのリンク →

BITTER

Score: 5.56
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT32

Score: 12.00
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1560 - Archive Collected Data
  • T1550.003 - Pass the Ticket
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Saint Bear

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Moonstone Sleet

Score: 5.26
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1217 - Browser Information Discovery
MITREへのリンク →

Contagious Interview

Score: 5.59
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1567 - Exfiltration Over Web Service
MITREへのリンク →

FIN7

Score: 4.07
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Magic Hound

Score: 5.72
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

APT28

Score: 10.86
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1560 - Archive Collected Data
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Dragonfly

Score: 7.24
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Patchwork

Score: 7.24
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1055.012 - Process Hollowing
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Axiom

Score: 7.71
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1584.005 - Botnet
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Ember Bear

Score: 4.09
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Lazarus Group

Score: 6.18
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

FIN6

Score: 4.69
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

menuPass

Score: 5.74
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1055.012 - Process Hollowing
MITREへのリンク →

Leviathan

Score: 4.09
Matched TTPs:
  • T1560 - Archive Collected Data
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Fox Kitten

Score: 5.38
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

Volt Typhoon

Score: 6.91
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1584.005 - Botnet
MITREへのリンク →

APT38

Score: 3.29
Matched TTPs:
  • T1217 - Browser Information Discovery
MITREへのリンク →

Scattered Spider

Score: 7.13
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1621 - Multi-Factor Authentication Request Generation
MITREへのリンク →

Chimera

Score: 3.29
Matched TTPs:
  • T1217 - Browser Information Discovery
MITREへのリンク →

APT29

Score: 13.72
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1621 - Multi-Factor Authentication Request Generation
  • T1203 - Exploitation for Client Execution
  • T1090.004 - Domain Fronting
MITREへのリンク →

BRONZE BUTLER

Score: 5.34
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

PROMETHIUM

Score: 6.23
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
MITREへのリンク →

UNC3886

Score: 7.72
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Higaisa

Score: 3.59
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT41

Score: 3.59
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

HAFNIUM

Score: 3.62
Matched TTPs:
  • T1584.005 - Botnet
MITREへのリンク →

LAPSUS$

Score: 3.84
Matched TTPs:
  • T1621 - Multi-Factor Authentication Request Generation
MITREへのリンク →

Gorgon Group

Score: 3.15
Matched TTPs:
  • T1055.012 - Process Hollowing
MITREへのリンク →

Confucius

Score: 4.65
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Tropic Trooper

Score: 4.65
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Inception

Score: 4.65
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

DarkHydrus

Score: 3.15
Matched TTPs:
  • T1221 - Template Injection
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Medusa Group

Score: 4.54
Matched TTPs:
  • T1218.014 - MMC
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT29

Score: 0.81
Matched TTPs:
  • T1090.004 - Domain Fronting
  • T1621 - Multi-Factor Authentication Request Generation
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

BlackByte

Score: 0.72
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1055.012 - Process Hollowing
  • T1560 - Archive Collected Data
  • T1608.001 - Upload Malware
MITREへのリンク →

APT32

Score: 0.71
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1560 - Archive Collected Data
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1608.001 - Upload Malware
MITREへのリンク →

Kimsuky

Score: 0.68
Matched TTPs:
  • T1055.012 - Process Hollowing
  • T1036.004 - Masquerade Task or Service
  • T1608.001 - Upload Malware
  • T1036.007 - Double File Extension
MITREへのリンク →

APT28

Score: 0.67
Matched TTPs:
  • T1567 - Exfiltration Over Web Service
  • T1221 - Template Injection
  • T1560 - Archive Collected Data
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Gamaredon Group

Score: 0.59
Matched TTPs:
  • T1001 - Data Obfuscation
  • T1608.001 - Upload Malware
  • T1221 - Template Injection
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る