REDCURL
Image Description
Common Information
Type Value
UUID 185a6e81-2c4f-4b5b-a747-60450c9ba7e7
Fingerprint f60bba163f6a06c2df99ac8479e923e000611ddbf7ee627285b2da845ada9291
Analysis status DONE
Considered CTI value 2
Text language
Published Aug. 11, 2020, 5:33 p.m.
Added to db April 14, 2024, 1:28 a.m.
Last updated Aug. 31, 2024, 6:23 a.m.
Headline REDCURL
Title REDCURL
Detected Hints/Tags/Attributes 224/3/297
Attributes
Details Type #Events CTI Value
Details CVE 375
cve-2017-11882
Details CVE 117
cve-2018-0802
Details CVE 27
cve-2009-3129
Details CVE 79
cve-2010-3333
Details CVE 176
cve-2012-0158
Details CVE 51
cve-2014-1761
Details Domain 35
group-ib.com
Details Domain 7
cloudme.com
Details Domain 3
koofr.net
Details Domain 5
pcloud.com
Details Domain 3
idata.uz
Details Domain 3
drivehq.com
Details Domain 3
driveonweb.de
Details Domain 4
opendrive.com
Details Domain 3
powerfolder.com
Details Domain 5
docs.live.net
Details Domain 3
syncwerk.cloud
Details Domain 3
cloud.woelkli.com
Details Domain 3
framagenda.org
Details Domain 3
multcloud.com
Details Domain 3
mailsecure.tech
Details Domain 3
byethost22.com
Details Domain 3
byethost7.com
Details Domain 3
logs99.atwebpages.com
Details Domain 3
mtpon34.myartsonline.com
Details Domain 3
app.koofr.net
Details Domain 3
thetempmail.com
Details Domain 149
system.security
Details Domain 3
storage.driveonweb.de
Details Domain 372
wscript.shell
Details Domain 12
securelist.ru
Details Domain 403
securelist.com
Details Domain 101
www.group-ib.com
Details Domain 1373
twitter.com
Details Domain 335
www.facebook.com
Details Email 3
foyub@thetempmail.com
Details Email 22
info@group-ib.com
Details File 2
%bd%d0%b8%d0%ba%d0%be%d0%b2.7z
Details File 24
report.php
Details File 1208
powershell.exe
Details File 1018
rundll32.exe
Details File 3
sdm5.dll
Details File 376
wscript.exe
Details File 3
enablelicenseacquisitionf.vbs
Details File 9
check.exe
Details File 14
check.bat
Details File 4
redcurl.ini
Details File 2126
cmd.exe
Details File 256
net.exe
Details File 409
c:\windows\system32\cmd.exe
Details File 3
wsswapassessmenttasks.vbs
Details File 4
syspack.exe
Details File 5
7za.dll
Details File 93
curl.exe
Details File 14
cmd.txt
Details File 3
_%hh%%mm%.tmp
Details File 459
regsvr32.exe
Details md5 3
571cba0332280827b067612f04f43f2b
Details md5 3
cc9460fa24872509eae5bd6496858202
Details md5 3
b15c556a02ae0779781d1e1a8bf60ff2
Details md5 3
8292f62c1583a79021ad5e7654b33fd3
Details md5 3
6a5eef605d8cfccf00f636ca7021e590
Details md5 3
40ee1d475ff236b83d61c563ad5d261d
Details md5 3
5f6d12a1f6a58f0abab1e214c5fcc872
Details md5 3
6272b59b5090f45639a5a26ad8f98365
Details md5 3
9691daebab79c6ab48adac73bda0a84a
Details md5 3
aff86bd355a746208fcf31de9707ae0b
Details md5 3
2375e40fb45efecc4e162449ea1fb479
Details md5 3
2abdcca9bdfa79e22f49af21082422f1
Details md5 3
aa57b416608949c5dcf9f496832f317e
Details md5 3
5294c19eea035302410711b718cd623e
Details md5 3
e18e269de42033065baeaf3e1bba0cf7
Details md5 3
aa625ac2df396bb478eee6a875083dc6
Details md5 3
fd3f1940afc2b429bc56c0b55f356944
Details md5 3
8048a791b5946dd68a1fc8ca5358ec75
Details md5 3
40ef07b3221d9846d892c42d10b7220e
Details md5 3
f215b71695e8f5f4ddf50466e853cc42
Details md5 3
313ede2578a6d8ab5a1b558a78759085
Details md5 3
3becc75bfd9c8d3fd19b8486ba980ce4
Details md5 3
b096449ed0ca654ae166bc141bd22335
Details md5 3
da62ada98b1b0c6ecb5d47eab1e9519e
Details md5 3
b1479513a24a37e4e3b0c38d6535cf21
Details md5 3
b2e91b4b714adbe826dbb5692db78453
Details md5 3
98e9ab41cc8756fb15edaf879200d414
Details md5 3
484bb302a2ca940f562be418e1b67eee
Details md5 3
948ccaba625e5073730cef8c0d21f894
Details md5 3
edab30e2d72f62f9056398e85d31195d
Details md5 3
dcf33e6f22ed5a24fb8e2c507770f278
Details md5 3
3E36E2AF206B6C41847161C58C777554
Details md5 3
f2fe7442b9017dcfe146ebea85a631e7
Details md5 3
8734bfe951847a5b577f01088c5cc803
Details md5 3
2c100f7835627ab7acb5cb58dfd04b8d
Details md5 3
4adf6dff493427be125d6708a93151aa
Details md5 3
973579883D19696C3B4286E74D8FA062
Details md5 3
ecff12e894d75e21f86562cd76a9a102
Details md5 3
b661d7367b778ba69941424d4bffbf09
Details md5 3
8b16f157d0f07819ada6896fed86d5d3
Details md5 3
dcc0098c95e58a6bf95f0cfe70a4f476
Details md5 3
78965056e42a035de01a7fc420d9bb97
Details md5 3
5e29db24d44311463fdeea35aa6cd61c
Details md5 3
b2ac2fad617b22f11b19bd24c50c4e8c
Details md5 3
e2d981da14863ab47345eb8534c8e3a1
Details md5 3
e315ea0ad5aa2556e4b0f68afe989acc
Details md5 3
04055917ce47645427b4f4ca84fe1e51
Details md5 3
dc8544751117ef6c0d320fbcd9e4a2db
Details md5 3
e7d27d0d682d8bb56b29b34e3eda03d7
Details md5 3
f2e33472eb55f22a5c1eb1dd2dfdca8c
Details md5 3
acb1882549b7556259bf7f25c7fbf077
Details md5 3
7c0ec47f4b6acb597954b8f6befe33f1
Details md5 3
0bd8e164a95532bb2817bf2e056cc0f1
Details md5 3
553ee9ce533f0a103e644c6881eff81c
Details md5 3
774e762e8546c569328a1d550cd9479e
Details md5 3
313a8aad53478e141011934a3ead2ed6
Details md5 3
5050484c1f18d65059ff7e01dc162bf6
Details md5 3
e3ac036fe4ac10813914b1cca52d1de5
Details md5 3
36fb611a076da404f61ef667a12cac55
Details md5 3
868d9d2bd0d11843e5a381b1873508cb
Details md5 3
fe8dceacfbf2dc4d874359ef6fca2de1
Details md5 3
25f4359b5201295ac56dcf234800a3d9
Details md5 3
e31512cb72b081f51e214f7d2496c0e1
Details md5 3
7086d00950105c9530bff7375b8464c3
Details md5 3
5f49e06a5a03f67eb476b66ab461f116
Details md5 3
e2ce59cd2a36a5dfa2bc3ab8a8d9eca8
Details md5 3
73340f09829b923c5a8c3468e166e49d
Details md5 3
c45df36255f57e31aeabd723e03bbd08
Details md5 3
5e694e86bf0bc3e55f5a65d6684e1631
Details md5 3
2a5365dc4344c258196dfdba5d783db0
Details md5 3
2d484bd4ea9e4d3853f0e91e062d980b
Details md5 3
a1fa93c9650044ed71bbda18bdfe5f61
Details md5 3
c47104f9c669454e7b48d2c717d949da
Details md5 3
808f2e36caaa5c2e88c29cf0e634e2bb
Details md5 3
1c3a60db0b174963dd01953c55804411
Details md5 3
04a1c0704b549581e3029634ea2ecf07
Details md5 3
47db515e537b88184f450bd352cb7e6e
Details md5 3
65693ff4d81af47db2974ade7db857e0
Details md5 3
24b5427d7e147de61d6b2b535aa1028f
Details md5 3
a3d0c95a34ebf46b313c26ea7ca79288
Details md5 3
95a5fba13ae88e43f460c9fba7328670
Details md5 3
4fff5bd6c746139406279f764504cd9c
Details md5 3
d3de39a4482cfa3f051f418a10e1994e
Details md5 3
082f4383801b79279e82b718c672a452
Details md5 3
a75871000b944b87fa0aee37cb20facf
Details md5 3
e000ab9fa0bf5e01ba353bba14fac8f1
Details md5 3
12ec7e6876dc86f158f448ebfba9e0eb
Details md5 3
65167ef2ac035b8205e657a31b3c8ee5
Details md5 3
cda007d68777e193827ab87cb00c4726
Details md5 3
1a0b622c4f2805b601655f7ffe0dabf6
Details md5 3
4071bf66e07cd4a7feadd316f91cfd56
Details md5 3
db602ed8ba5890f162dc3546847646b1
Details md5 3
f04cf464ddd719dce94640cc4b6e866d
Details md5 3
979eaebd1510996ab834e3471fdaab5b
Details md5 3
040cb066f2cdfc579c9be86128ceb8ff
Details md5 3
b5d0f72dc1bda1727d88c51cf16ee8c1
Details md5 3
662493e155284d654d61e2923efeeec4
Details sha1 3
c2614da1b29293505fd71589641adfc5161a1146
Details sha1 3
21e08a4ebff766c25b1df255a1efc3f39dd1180c
Details sha1 3
6d488096fae4916dab8a17c43eb2ce8cee340616
Details sha1 3
d13feeac312e7a43340ef3ef6df28b4f53209016
Details sha1 3
b5922c93e70840125617ba36a3651413c641e558
Details sha1 3
dd4392b4c06a24b615d7672a90d4c0bf43425efe
Details sha1 3
126fb5c821e4d9e3cd22fb4076c718e6c7048537
Details sha1 3
fc6d0882cafc128ea44dfb82a8612c28246457ba
Details sha1 3
4d068039476fe2e5a883d08d3b16827ab2442a1f
Details sha1 3
d80dea264dc6621223b3f91564c71699f4d20d6b
Details sha1 3
a7a170ea16b4fb567da7656f9690977129bf022b
Details sha1 3
9921aaba1bc6ac7c2002db7b395d2d6fce232b05
Details sha1 3
6e4a0fc3b901a1eb2d7dad87e08bbe8176df27ca
Details sha1 3
a32edf29e9dd334d938e7d43bf5f23e5e2e1379b
Details sha1 3
2bc166ae7482ab1fc164a82333d52f562e3ebcf2
Details sha1 3
1e799d277564f5e2dc02765d67baa2b001eb3c14
Details sha1 3
9544021eca90f2b61c00b1f3d964eada46c4069f
Details sha1 3
0536f010e53e68844875d635b9af896b98b7b7f9
Details sha1 3
e8c2b3f99fccd983fb8245d9523687e6f3d9e7c0
Details sha1 3
37bd8f99b48d3c4ba2d961a2845500d49f6d0b67
Details sha1 3
eab481f339cd5f64bc91c7718ccdc7997bb717d6
Details sha1 3
5ded57ebeb26d53926338f350e5ff3c5b97c355b
Details sha1 3
c9f2ed153f54faab782fde4d7b99b8a76165b43b
Details sha1 3
3e8594a9ae1b779502dad2783a32be3708121ee6
Details sha1 3
6a3132c2d2663c70cbf91c3b6e412de6a9b2000f
Details sha1 3
8a7dc93cb358dfa3ede7ebe6215200541a5d2350
Details sha1 3
18f5abb55e372c59d35665b125a3facd39406d0a
Details sha1 3
1d4b869153121c47b97901dfe9b0a595d3a41b65
Details sha1 3
a31c0046f06c9274adc322363045b7a6e01ccc9e
Details sha1 3
af8e1aa9e57b2dae655b6b2a0c3b3ec15878a57d
Details sha1 3
19a1b5c4153bbe082b43688f57b4a02ffbc3f06c
Details sha1 3
679a71094cd62d342cfd189f178e7d8cddc5d0c1
Details sha1 3
a608509665e6f07e407c636fdafc9a364df9ba89
Details sha1 3
6ed0375d527cc8855f435777f68d4924cf24957b
Details sha1 3
f16bc12267399b61e779a380962372ba403bcff9
Details sha1 3
08d429f8ba3218b9442f6c00d33988fe8d924cab
Details sha1 3
3580dd6b213c6efb86f6dfcd9a39ef850c47e503
Details sha1 3
b3dea7c6d31b4e1acf07befe2b937e545faa1172
Details sha1 3
276b97c5805d932e19b5156e93d3054ca2403c58
Details sha1 3
e10da81bf3b5d4864d6e339dff2aaf84b416f29e
Details sha1 3
5e950dc125984ce19136d99dd87baaf943c3a8b7
Details sha1 3
e66f165ddb1c6bbf2e5c524e3ba6715dce0d0290
Details sha1 3
b359138e5a02a4ccdbb3526aa5351e44ee175352
Details sha1 3
3e684d2e3043c57b960343319c094ef7318bea5f
Details sha1 3
5bea907808d30369f60e7902a1b4906ded699897
Details sha1 3
3606849f0d6ec485579a8c6c136707e6c85ec473
Details sha1 3
21f23c97bb3d008baf5b276a847ede51efef8cc3
Details sha1 3
f2e3d9700b0303cc1f57a7802b36420e79b25ce6
Details sha1 3
ef8b6293111eb3fd2244307d95e8278b31778a78
Details sha1 3
1e82f8862e2d0884d20fbcd96d9d751c5924403e
Details sha1 3
aad0f1ce8cae3b0dd12f5a70f1ef495fd7269a1a
Details sha1 3
1644b15cdda74505f5a06ccbe1c5615db11f2558
Details sha1 3
403f8b0f9bb5e8a80651743ab274c63fa930c3bf
Details sha1 3
1eb09787262722d8684db5c008066c9b69b15b94
Details sha1 3
0e8fe9dcfd88c89632f813227ecd9299455bec86
Details sha1 3
f47a3e557813139b0202bb7e1bef7d1e5564f3d6
Details sha1 3
3c34b35c9bf5e73cb702d6c2f7cbd96d2ee2f5cd
Details sha1 3
8711b71fda59b5b75176b436d2498d57c59d1389
Details sha1 3
36de37b3117e1f8e9df4749b2de886aef968511f
Details sha1 3
b0eb8d3d80e503708a19a891b5ba11a9b55e54f6
Details sha1 3
82ffae3656dfc3422462797bb3b21a0752f3dcbd
Details sha1 3
11c62b38f40faa6961be9ec2df8af1344c672233
Details sha1 3
3a4ba61af6cbc627dd450ed74e58cdec3aee076d
Details sha1 3
46e50da34773d0960dbedfb4598762b233725bbd
Details sha1 3
0d0938ce0b6a2150ba3e02d231b9dafd5aeea69f
Details sha1 3
25ec727de33683062e1e4afa11269fcaf61ea2b9
Details sha1 3
2991873bd471a288379b2ddc3d03fa9a415e0eac
Details sha1 3
4cb87f3d29b83620c96b67e4531120063438af01
Details sha1 3
c47522b3923173881f52dddacd48acd88359f23a
Details sha1 3
0782da50a5ddf8551adc5957896a0406abc8ad16
Details sha1 3
a31317e167c445fc09a2fb04a8eff66f038f921f
Details sha1 3
19fd1b5c9d7f3f2ff9bad94381a2a4c19247dfd3
Details sha1 3
edfc60a54fda49fa43a6e0d8ed5a14e181278617
Details sha1 3
84051063cf4e11cef9ec8c3ce81d4a2a4b36348f
Details sha1 3
ccc8176dd2cc0d7831d153f9d9399b4712e6da5b
Details sha1 3
6343000188465aa07d92639f812f7fccf0ed56cf
Details sha1 3
d9d6001515073a6fda28958f5990091733662e17
Details sha1 3
2dd90d341d80edef4fbee339c856caec3001056f
Details sha1 3
ff054cc435c8007f3238bee5ab40b95675ee8208
Details sha1 3
7bef4606d73bd77b8d1d5b6b7a08f8869190d49d
Details sha1 3
47dc335be7c9c114c6061fd72b8b76cf87e63e72
Details sha1 3
2f7581666f5a7ccc6afa3a1ac7cc1994f78a7ae2
Details sha1 3
91210c365e4ceaaef5aeb595f30c53d573a27943
Details sha1 3
ce178c77370e9654c810c5a67fa55d2e0bd0a7f4
Details sha1 3
c25194f9c547a85a9ce7a7dd752427b33a16c0e7
Details sha1 3
51d60a7da40c11e37b31462e6b78f909e84d85f4
Details sha1 3
464a8c086279357ad41e15180ae0d4881cf48717
Details sha1 3
aa21dc970461c653bd24e75a1440f6893bbaf747
Details sha1 3
25a3d8aacc4bb40fd3a42ab7fa80c180324ac90b
Details sha1 3
8fc49c58aeb70943da579e6985b64d78a56f6958
Details sha1 3
b9c762e7e65b4cdcac054fa424b2219f8ecf3b78
Details sha1 3
7fee558c6d6668e67e75dd94a2d7609c287ec756
Details sha1 3
19d0afc92e3e98e3ed5e1db9aed21da791245e8d
Details sha1 3
23e813e43dc67b50a7d00f76223c1fc56fe1abbe
Details sha1 3
b1a79cce4a75e46830f52fedc67b2a3209eb78bb
Details sha1 3
729c83d7986eca76536e3b318233945a7febaff8
Details sha1 3
09bd864389edcc7585a42950e32619c31b1ac34a
Details MITRE ATT&CK Techniques 183
T1566.002
Details MITRE ATT&CK Techniques 365
T1204.002
Details MITRE ATT&CK Techniques 333
T1059.003
Details MITRE ATT&CK Techniques 460
T1059.001
Details MITRE ATT&CK Techniques 137
T1059.005
Details MITRE ATT&CK Techniques 275
T1053.005
Details MITRE ATT&CK Techniques 380
T1547.001
Details MITRE ATT&CK Techniques 627
T1027
Details MITRE ATT&CK Techniques 183
T1036.005
Details MITRE ATT&CK Techniques 297
T1070.004
Details MITRE ATT&CK Techniques 94
T1564.001
Details MITRE ATT&CK Techniques 119
T1218.011
Details MITRE ATT&CK Techniques 173
T1003.001
Details MITRE ATT&CK Techniques 125
T1555.003
Details MITRE ATT&CK Techniques 89
T1552.001
Details MITRE ATT&CK Techniques 23
T1552.002
Details MITRE ATT&CK Techniques 11
T1056.002
Details MITRE ATT&CK Techniques 1006
T1082
Details MITRE ATT&CK Techniques 39
T1035
Details MITRE ATT&CK Techniques 585
T1083
Details MITRE ATT&CK Techniques 72
T1087.001
Details MITRE ATT&CK Techniques 99
T1087.002
Details MITRE ATT&CK Techniques 22
T1087.003
Details MITRE ATT&CK Techniques 33
T1080
Details MITRE ATT&CK Techniques 111
T1119
Details MITRE ATT&CK Techniques 534
T1005
Details MITRE ATT&CK Techniques 67
T1039
Details MITRE ATT&CK Techniques 34
T1114.001
Details MITRE ATT&CK Techniques 149
T1102
Details MITRE ATT&CK Techniques 442
T1071.001
Details MITRE ATT&CK Techniques 102
T1020
Details MITRE ATT&CK Techniques 33
T1537
Details MITRE ATT&CK Techniques 310
T1566.001
Details MITRE ATT&CK Techniques 245
T1203
Details MITRE ATT&CK Techniques 44
T1218.010
Details MITRE ATT&CK Techniques 59
T1218.005
Details MITRE ATT&CK Techniques 40
T1221
Details MITRE ATT&CK Techniques 185
T1518
Details MITRE ATT&CK Techniques 130
T1573.001
Details MITRE ATT&CK Techniques 48
T1090.003
Details Url 2
http://logs99.atwebpages.com
Details Url 2
http://mtpon34.myartsonline.com/report/2890000027835616636545613
Details Url 2
https://app.koofr.net/dav
Details Url 2
https://storage.driveonweb.de/probdav
Details Windows Registry Key 26
HKCU\Software\Microsoft
Details Windows Registry Key 36
HKCU\Software