PowerPoint Presentation
Image Description
Common Information
Type Value
UUID 49c53d09-9456-42e8-aaf0-3b65eaf7db61
Fingerprint 17c1bd30b540e4e843ddca0fc423fefa8405133a3dd93359c2347d523de922eb
Analysis status DONE
Considered CTI value 2
Text language
Published Nov. 4, 2022, 5:14 p.m.
Added to db Feb. 7, 2024, 6:59 p.m.
Last updated Aug. 31, 2024, 2:10 a.m.
Headline PowerPoint Presentation
Title PowerPoint Presentation
Detected Hints/Tags/Attributes 142/3/138
Attributes
Details Type #Events CTI Value
Details CVE 172
cve-2022-30190
Details CVE 23
cve-2021-42287
Details CVE 32
cve-2021-42278
Details CVE 91
cve-2021-34527
Details CVE 217
cve-2020-1472
Details Domain 1
courtlincolnglave.com
Details Domain 2
jardinoks.com
Details Domain 1
widisusez.com
Details Domain 1
purestealconstruction.com
Details Domain 1
groundworkseasy.com
Details Domain 4
assets.sentinelone.com
Details Domain 55
otx.alienvault.com
Details Domain 8
www.cynet.com
Details Domain 452
msrc.microsoft.com
Details Domain 1
www.property-tax.com
Details Domain 1
www.cadeploy.com
Details Domain 1
diamondmowers.com
Details Domain 1
edc3global.com
Details Domain 1
www.alrotransport.com
Details Domain 1
www.jmrodgers.com
Details Domain 1
www.bootz.be
Details Domain 435
www.hivepro.com
Details File 1
c:\windows\sysnative\nltest.exe
Details File 6
home.aspx
Details sha1 1
0b06b000f0dd8d89e7300fa333cba33f90aa8e62
Details sha1 1
31c0be28f46b86670c3d08d3c4f6ee8793cabbbe
Details sha1 2
48bf9b838ecb90b8389a0c50b301acc32b44b53e
Details sha1 1
5ebacb20f62fae0dd610d874583d13fac5024309
Details sha1 1
f48b84a91e90ad96f652e777c05e41157eb0c666
Details sha1 1
2b93cc96825ec27525b9caa918073387eea13538
Details sha1 1
fd6277f31d7a40d8ece67130f6b0dd69bb58db82
Details sha1 1
5ed592a6713d36c26139b7d386c97a251b9f2ccb
Details sha1 1
885e07e95661282000d843bfd87295718d08ee05
Details sha1 1
2c25eefd5a8c1df0346deefb705f80c3c4775e8f
Details sha1 1
84a594fc02731009fdf444a3e4134b1b7a928626
Details sha1 1
fbb59ffa0f882cc2971d72b8556bfe3b9cce060c
Details sha1 2
3b2a0d2cb8993764a042e8e6a89cbbf8a29d47d1
Details sha1 1
1860e9423d55720a44e7814e757b10d880e1d9af
Details sha1 1
93cf40f95ab91a0e33b405c0c49025dab7ceb496
Details sha1 1
a0c3ba7679a36976bbbbad6c08758054ba49af8b
Details sha1 1
0b879c224e3ae5be0b6d3fcca28e27bd26ed7114
Details sha1 1
20486b47aa29334b368fe80bd815181aa59d5db4
Details sha1 1
877da581a05917591cfa905d2a3981f03c1389fc
Details sha1 1
3112a39aad950045d6422fb2abe98bed05931e6c
Details sha1 1
d76188d82e1c09c7703e30ab9b64a0c42f68a67b
Details IPv4 2
185.217.1.23
Details IPv4 1
159.223.236.110
Details IPv4 1
193.29.13.159
Details IPv4 1
193.29.13.216
Details IPv4 1
193.29.13.170
Details IPv4 1
190.123.44.126
Details IPv4 1
190.123.44.130
Details IPv4 1
185.125.206.218
Details IPv4 1
95.179.161.101
Details IPv4 1
69.46.15.147
Details IPv4 1
87.247.152.249
Details IPv4 1
185.107.80.78
Details IPv4 1
177.54.145.139
Details IPv4 1
109.248.149.137
Details IPv4 1
109.170.6.150
Details IPv4 1
78.128.112.217
Details IPv4 4
45.153.241.167
Details IPv4 1
209.250.236.75
Details MITRE ATT&CK Techniques 695
T1059
Details MITRE ATT&CK Techniques 137
T1059.005
Details MITRE ATT&CK Techniques 93
T1059.007
Details MITRE ATT&CK Techniques 627
T1027
Details MITRE ATT&CK Techniques 42
T1027.005
Details MITRE ATT&CK Techniques 23
T1027.006
Details MITRE ATT&CK Techniques 160
T1027.002
Details MITRE ATT&CK Techniques 78
T1569
Details MITRE ATT&CK Techniques 247
T1070
Details MITRE ATT&CK Techniques 297
T1070.004
Details MITRE ATT&CK Techniques 124
T1482
Details MITRE ATT&CK Techniques 176
T1135
Details MITRE ATT&CK Techniques 65
T1069
Details MITRE ATT&CK Techniques 32
T1069.001
Details MITRE ATT&CK Techniques 245
T1016
Details MITRE ATT&CK Techniques 119
T1049
Details MITRE ATT&CK Techniques 230
T1033
Details MITRE ATT&CK Techniques 75
T1010
Details MITRE ATT&CK Techniques 1006
T1082
Details MITRE ATT&CK Techniques 534
T1005
Details MITRE ATT&CK Techniques 444
T1071
Details MITRE ATT&CK Techniques 422
T1041
Details MITRE ATT&CK Techniques 149
T1102
Details MITRE ATT&CK Techniques 152
T1090
Details MITRE ATT&CK Techniques 67
T1505
Details MITRE ATT&CK Techniques 409
T1566
Details MITRE ATT&CK Techniques 310
T1566.001
Details MITRE ATT&CK Techniques 183
T1566.002
Details MITRE ATT&CK Techniques 420
T1204
Details MITRE ATT&CK Techniques 106
T1204.001
Details MITRE ATT&CK Techniques 365
T1204.002
Details MITRE ATT&CK Techniques 207
T1547
Details MITRE ATT&CK Techniques 380
T1547.001
Details MITRE ATT&CK Techniques 480
T1053
Details MITRE ATT&CK Techniques 275
T1053.005
Details MITRE ATT&CK Techniques 122
T1543
Details MITRE ATT&CK Techniques 180
T1543.003
Details MITRE ATT&CK Techniques 164
T1574
Details MITRE ATT&CK Techniques 70
T1574.001
Details MITRE ATT&CK Techniques 276
T1490
Details MITRE ATT&CK Techniques 121
T1218
Details MITRE ATT&CK Techniques 44
T1218.010
Details MITRE ATT&CK Techniques 119
T1218.011
Details MITRE ATT&CK Techniques 550
T1112
Details MITRE ATT&CK Techniques 440
T1055
Details MITRE ATT&CK Techniques 86
T1055.012
Details MITRE ATT&CK Techniques 235
T1562
Details MITRE ATT&CK Techniques 28
T1562.009
Details MITRE ATT&CK Techniques 52
T1622
Details MITRE ATT&CK Techniques 172
T1555
Details MITRE ATT&CK Techniques 125
T1555.003
Details MITRE ATT&CK Techniques 289
T1003
Details MITRE ATT&CK Techniques 433
T1057
Details MITRE ATT&CK Techniques 243
T1018
Details MITRE ATT&CK Techniques 163
T1573
Details MITRE ATT&CK Techniques 472
T1486
Details Threat Actor Identifier - FIN 377
FIN7
Details Url 1
https://assets.sentinelone.com/sentinellabs22/sentinellabs-blackbasta
Details Url 1
https://otx.alienvault.com/pulse/6363be4e63994f523414639c
Details Url 1
https://www.cynet.com/blog/orion-threat-alert-qakbot-ttps-arsenal-and-the-black-basta-
Details Url 3
https://msrc.microsoft.com/update-guide/vulnerability/cve-2022-30190
Details Url 1
https://msrc.microsoft.com/update-guide/vulnerability/cve-2021-42287
Details Url 1
https://msrc.microsoft.com/update-guide/vulnerability/cve-2021-42278
Details Url 5
https://msrc.microsoft.com/update-guide/vulnerability/cve-2021-34527
Details Url 4
https://msrc.microsoft.com/update-guide/vulnerability/cve-2020-1472
Details Url 1
https://www.property-tax.com
Details Url 1
https://www.cadeploy.com
Details Url 1
https://diamondmowers.com
Details Url 1
https://edc3global.com
Details Url 1
http://www.alrotransport.com
Details Url 1
https://www.jmrodgers.com
Details Url 1
https://www.bootz.be/nl/home.aspx
Details Windows Registry Key 112
HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Details Windows Registry Key 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Sentin
Details Windows Registry Key 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Panda