Silence 2.0 Going Global
Image Description
Common Information
Type Value
UUID 56be64df-f05f-4e28-a7a6-ce434e528a4e
Fingerprint 46147b81ccd5985b14177370956aba3f1aa37647292c88f9c5b69311e6c73a7f
Analysis status DONE
Considered CTI value 2
Text language
Published Aug. 14, 2019, 3:48 p.m.
Added to db Oct. 15, 2024, 4:35 p.m.
Last updated Oct. 15, 2024, 4:41 p.m.
Headline Silence 2.0 Going Global
Title Silence 2.0 Going Global
Detected Hints/Tags/Attributes 86/3/362
Attributes
Details Type #Events CTI Value
Details CVE 375
cve-2017-11882
Details CVE 117
cve-2018-0802
Details Domain 35
group-ib.com
Details Domain 4127
github.com
Details Domain 4
silence.proxybot.net
Details Domain 2
bankuco.com
Details Domain 2
cardisprom.ru
Details Domain 2
en.prothomalo.com
Details Domain 1
mail1.bankuco.com
Details Domain 2
priglashenie.zip
Details Domain 2
bankica.top
Details Domain 2
bankusr.ru
Details Domain 1
ccrbank.ru
Details Domain 4
fpbank.ru
Details Domain 4
proxybot.net
Details Domain 2
apt.silence.ivoke.ps
Details Domain 3
clodflarechk.com
Details Domain 3
thespecsupportservice.com
Details Domain 2
date2.date
Details Domain 2
date1.date
Details Domain 2
msboxoffice.com
Details Domain 2
dorlon-sa.com
Details Domain 2
mobilecommerzbank.com
Details Domain 2
itablex.com
Details Domain 2
sbbank.ru
Details Domain 2
pharmk.group
Details Domain 2
bankrebres.ru
Details Domain 2
basch.eu
Details Domain 2
counterstat.pw
Details Domain 2
counterstat.club
Details Domain 2
zaometallniva.ru
Details Domain 2
www.thedailystar.net
Details Domain 768
www.youtube.com
Details Domain 2
www.prothomalo.com
Details Domain 2
www.dhakatribune.com
Details Domain 9
www.kommersant.ru
Details Domain 16
www.group-ib.ru
Details Domain 6
blog.group-ib.ru
Details Domain 15
group-ib.ru
Details Domain 1373
twitter.com
Details Domain 330
facebook.com
Details Email 3
intelligence@group-ib.com
Details Email 2
info@bankuco.com
Details Email 8
info@group-ib.ru
Details File 6
xfs-disp.exe
Details File 2
dnscat2.ps1
Details File 4
договор.doc
Details File 2
карты.doc
Details File 2
карты.zip
Details File 2
priglashenie.zip
Details File 2
13012019.chm
Details File 2126
cmd.exe
Details File 4
с:\windows\system32\cmd.exe
Details File 2
dmw.exe
Details File 2
%appdata%\dmw.exe
Details File 2
4%.php
Details File 2
rogr.php
Details File 2
nc-bank.crt
Details File 10
2.tmp
Details File 2
c:\programdata\win7z\wsus.exe
Details File 2
xfs-test.exe
Details File 2
%appdata%\temps.dat
Details File 2
logpc.php
Details File 119
avp.exe
Details File 2
%programdata%\svconhost.exe
Details File 4
dns.php
Details File 3
guid.dat
Details File 2
novikov.7z
Details File 2
statement_180619.docx
Details File 456
mshta.exe
Details File 1
powersherll.exe
Details File 2
txt.ps1
Details File 2
ivoke.ps
Details File 4
book.php
Details File 32
showthread.php
Details File 2
c:\some_file.exe
Details File 11
f.exe
Details File 156
1.exe
Details File 2
gxftcp.dat
Details File 1205
index.php
Details File 2
lisk.ps1
Details File 2
eda.ps1
Details File 13
msxfs.dll
Details File 2
c:\xfsasdf.txt
Details File 14
d.dat
Details File 5
qhactivedefense.exe
Details File 6
qhsafetray.exe
Details File 3
qhwatchdog.exe
Details File 23
cmdagent.exe
Details File 11
cis.exe
Details File 5
v3lite.exe
Details File 4
v3main.exe
Details File 3
v3sp.exe
Details File 36
egui.exe
Details File 53
ekrn.exe
Details File 23
dwengine.exe
Details File 11
dwarkdaemon.exe
Details File 4
bullguardtray.exe
Details File 42
bdagent.exe
Details File 10
bullguard.exe
Details File 4
bdss.exe
Details File 7
wsus.exe
Details File 2
wmihost.exe
Details File 2
settings3.bin
Details File 2
wmites.exe
Details File 256
net.exe
Details File 2
ammyy_service.log
Details File 4
service.log
Details File 85
log.txt
Details File 1
%temp%\default.bin
Details File 2
cloud.png
Details File 6
load.png
Details File 2
ban3.dat
Details File 2
kernel.dat
Details File 2
date2.dat
Details File 2
ba.dat
Details File 3
date1.dat
Details File 2
181.dat
Details File 14
s.dat
Details File 7
p.dat
Details File 2
dns.dat
Details File 2
dns3.dat
Details File 2
c:\windows\st.exe
Details File 2
c:\hp\dotnet.exe
Details File 2
c:\hp\1.txt
Details File 2
c:\hp\sockstest.exe
Details File 2
net35.dll
Details File 2
c:\intel\sockstest.exe
Details Github username 3
lukebaggett
Details Github username 18
empireproject
Details md5 2
2fe01a04d6beef14555b2cf9a717615c
Details md5 2
fd133e977471a76de8a22ccb0d9815b2
Details md5 2
14732e82a6cbd108c40540314b029ee3
Details md5 2
edf59a111cce8ea1d09a2b4e8febdfdf
Details md5 1
3bb13571fb8f07df69beee8b077ac938
Details md5 2
7af426e0952b13ef158a4220e25df1ae
Details md5 2
94531c20462f69c6135c4d0a06925471
Details md5 2
914F6BA6A3A043ECC961296FA94A6BAD
Details md5 2
76F1492A32C82CB1A003C2B0AAEC20E0
Details sha1 2
2ee8ee6d8ca6e815d654bb96952861f3704e82e9
Details sha1 2
e22d5170981b8150dd08eda9b7eca7f5317247af
Details sha1 2
4d0d5ecaea133dbcc603119a5271796bfe371036
Details sha1 2
f858c23c03a598d270eba506f851fb14685809fd
Details sha1 2
c59cb38bcada36d8c7a671642146ff39f1f49693
Details sha1 2
1477b18e917c295df9b3c5624e91057999a3f2b6
Details sha1 2
f88d4e44d85ef3acc24c8b459c68915c76e792ed
Details sha1 2
81673f941092618231599e910300249e13903c32
Details sha1 2
7c5f06b9c929f0effcb052e87ddfb07b814a41d5
Details sha1 2
06bd5fc2eb2b00cabfe279b1321e6671f0c768be
Details sha1 2
1cc39211d98e3e11dc9afd499f97b93043c470fb
Details sha1 2
93223c0dbc7df43e4d813c9809cde1263aaf4ec3
Details sha1 2
2a54b8216b96897f9f5c31992ea0d6b43b96f32b
Details sha1 2
957538ca1a87ce6cbf4f840777c032811d82bf55
Details sha1 2
2cd620cea310b0edb68e4bb27301b2563191287b
Details sha1 2
f3a639f2659709c76b70a0c2dd7dc3ef1d12103b
Details sha1 2
3e796c9580de47fe994cbbfcc8c383375ab4618b
Details sha1 2
2250174b8998a787332c198fc94db4615504d771
Details sha1 2
1b8c71131891dc1c728349405409a687caeefdbc
Details sha1 2
d1dd819dc64c26913d2d9ec8dd4ad9c4e26512a9
Details sha1 2
d0dcfbeeb9f81af8bad758d5e255a412ad5a7004
Details sha1 2
cc3875b9a8062b3bc97564c922ef8440fa95923c
Details sha1 2
3a8e362f8183bc9d33320f03285ceea07fd19250
Details sha1 2
272fcd5c45c1f8a42b15b95df7d293cc8fe22375
Details sha1 2
7fe56ac2b3eedc4e51021ed3c0c83b8722f2bf07
Details sha1 2
7e4cb7e39b314f92252791597a45d685a5a38a7d
Details sha1 2
8d37648a1ad242f8eab2016aaee7a5b314757764
Details sha1 2
c58642a02f848d437c30027c6455d07587477423
Details sha1 2
e4b7dbdad70443c565673dc46d8eea05dd5c2b69
Details sha1 2
fe1f5f9774e2b58af0b51453c933931648f7aa47
Details sha1 2
d044bc7fb58792a6bf612116662df892a306a931
Details sha1 2
290af346e9e235501e4004f997266f7256755669
Details sha1 2
256bb2d559885b3116e64797ac57c0102a905296
Details sha1 3
c572ba3fcd991fd29919d171b8445dbb5277a51d
Details sha1 2
4896d0d045bbfb796731d9f851126e59c87fc580
Details sha1 2
20688dbbfd8b96e23663e059cd7a7ddb5a997dcd
Details sha1 2
640560fa36cf9d3b9b134bd9b951e8d5c9a3e3e6
Details sha1 2
ebe222153f3663239522812dc349a9a1fd95f717
Details sha1 2
2beacf1ca098550b829b4b0d9b4f723ad8d1978e
Details sha1 2
5fcb0495cf70946cf606b95b51ead132e4dded3e
Details sha1 2
818c0ade5cc1000a7ac7088b431d44a681e06d7b
Details sha1 2
974f24e8f87e6a9cce7c6873954ecab50ffa6f92
Details sha1 2
7a2aad56c8306a062279645686c59cbf2b2647c4
Details sha1 2
7067326bf1efd4898afa4318b1b1ceba0da86bb3
Details sha1 2
edaf75c6b649c48ec1ca78156bb49503b6183c38
Details sha1 2
62a4ce1c4f81643eda4288f28c158b5f92bf6983
Details sha1 2
08c985a9187d3823d89c16f479a56181559681ae
Details sha1 2
0f5cf45240401aad6ea2118f99eb3fceca9d23e4
Details sha1 2
e2955b716250ec0f25510e5bc2ca05fa037ffdad
Details sha1 2
0b5f0c94ca5251a16bf142f8fdbae117d2996f66
Details sha1 2
15e8fac9c9d5e541940a3c2782df6196ec1e9326
Details sha1 2
c667cba2b4c2d0426aacfcb7b6cb9c8282dddcdb
Details sha1 2
21f557e714f240cd0fff365a454c57849a87170c
Details sha1 2
cd4e470e7448e8d9e559fd2029a069829c6190cb
Details sha256 2
600e1adba4983692e9b74e631e155eab65279dd2ab73bb35fbd6e0e84d0e68a5
Details sha256 2
18462ae676c539b2a3626a7b465123b20c88bd68342777a090f40b7dcb7ace0d
Details sha256 2
7f61258418b89942aa8e7bf2563ce11a05402d3ccf405a18e3d0a4d7a7f9ee41
Details sha256 3
ba8ed406005064fdffc3e00a233ae1e1fb315ffdc70996f6f983127a7f484e99
Details sha256 2
bce75d6ec2b8d7419044ba8302c96bbdeec0354b0dc764e19ec4e7aa44e8ef13
Details sha256 2
7bf942db8cc97f6274754e1f4d16dcf14e9d21c09038746895e27b64fcfcdfe4
Details sha256 2
18732545bc6fe6035f92d3b3aa0bfc06f031be2f26f556ad76f06e9573d384d9
Details sha256 2
42ded82ef563db3b35aa797b7befd1a19ec925952f78f076db809aa8558b2e57
Details sha256 2
73e149adb7cc2a09a7af59aecd441fd4469fc0342b687097cadfbce10896c629
Details sha256 2
557db9e6398fd38b7f215bbbc18d433c5c49a86adfba0cb9dbc9ea272366d727
Details sha256 2
56f1ab4b108cafcbada89f5ca52ed7cdaf51c6da0368a08830ca8e590d793498
Details sha256 2
c2080983598643a2498d1f6ef3f1cc9dc58a784a69e3f313f18dc1b8e0afbc17
Details sha256 2
89590e12f45b01e70563205a67db70645f8bb534ab6fdf54fba1f7d36f614d67
Details sha256 2
773f08e332a9bf8648c1cad76186e1120025dae9aac402c0ca1ba7b71d8af9c9
Details sha256 2
efeadabb39db0f7087ecec71b31f198727443beef8fa030ee2dfe5266d78603b
Details sha256 2
8cbf24dbbe16fa051ba13b3bc84b1b2c359206488f8fd35e1bc89339813ae180
Details sha256 2
7d0eef74bc6cdc0d6af977fcdcd94af9859fbac84671e869409b2e141cc131d0
Details sha256 2
b966e1a71719361338e861800c3c989b22336e4a4497c28f75398c4804a250c6
Details sha256 2
8947f9468f16ab3eebb56d546034061d7073e29b5010444e385aa3937b10a81e
Details sha256 2
ebce43d96b77e0e6a395a7cbde462b90abbc91894dbd80c2a413286aa24e3435
Details sha256 2
35613fdfb5940ead5d2f2c124ccf6d022d308b6efbffecead20e57202292f423
Details sha256 2
bb6d7888b7538c8df9c7b3fb4baedd2e8309c39df527c0d48bfb46bc87918de4
Details sha256 2
ed5d29a19f3aed2c870051d639b974f16682a2463fd20bd230594102c39958dd
Details sha256 2
50c94e998a1c387ba7af19f870716c0299f5e9ffd8fa3bd721f120ede8f1b440
Details sha256 2
e525e1b3367eb427002fd84a5b5d7ac18df93fce4412d0f18aaa6b1141cc56c2
Details sha256 2
f143a594fa59150afc7503a8e18a0986bbe7985e8c4480b11f49344194317bd4
Details sha256 2
8f21ac40c116f25276c5c52a64ef883bd80d28a5d09f589cbc7180ac4b009abb
Details sha256 2
f318b1fe2d131e67ac1a1800e59dc1373464c69992008db4dac436bed90225e8
Details sha256 2
c8156fef756fdc195b0acfad767ce26c304c8dccd1ba8f3fb7efb7f1e08cd1e6
Details sha256 2
56b57fc829774aa4423b7a29ff5a081b75167d2466898acbc7d89e717bfb4869
Details sha256 2
7ecfd68341fe276c17246dc51c5d70ee2c1bbc6801c85201c8a62956c23d872d
Details sha256 3
af1d155a0b36c14626b2bf9394c1b460d198c9dd96eb57fac06d38e36b805460
Details sha256 2
8562d866b475e221a5394e6ddeec67ccdb49faa752dd25b76281842bec8c2907
Details sha256 2
bccddce212adc252328a56af862c1310d084fcfd3838ffe6c36fb4e0ff64ca78
Details sha256 2
6e53d7e07e04b718825f6ab209a74ecbcfc6285097f0c0f9d332e8c0f54e1097
Details sha256 2
4425fec38db7503a3cb1a1be48d14881a18a00ccef7a975a0d64fba1191d8b09
Details sha256 2
03318d195541590cce94df7ec95ba899e5cd0dbac813a4042ac7efaa9a01f9ed
Details sha256 2
1b5a01df930dbaaf8a61a948b2d7205eed023022c5d76c03144daeae0442e5ca
Details sha256 2
dd11953288c33ca020301ec639efa1a42f87059fb1adafde58343db7002d4b4b
Details sha256 2
127178ad32549676de47111180a356bfc1184bb0de8e3ce46a61da6a170489de
Details sha256 2
64edb1c153edd7ed92b2847f9ba703b1254924f046f8873459e74ecb9bb4d6d7
Details IPv4 3
185.20.187.89
Details IPv4 2
46.30.41.232
Details IPv4 2
185.70.186.146
Details IPv4 2
185.70.187.188
Details IPv4 2
185.70.186.149
Details IPv4 2
193.109.69.5
Details IPv4 2
185.29.10.26
Details IPv4 2
84.38.134.103
Details IPv4 2
31.207.45.85
Details IPv4 2
185.176.221.29
Details IPv4 3
147.135.170.169
Details IPv4 2
185.17.121.223
Details IPv4 2
185.180.196.43
Details IPv4 3
79.137.127.216
Details IPv4 2
185.17.123.201
Details IPv4 2
185.17.120.235
Details IPv4 2
213.183.63.242
Details IPv4 2
195.123.209.169
Details IPv4 2
91.200.41.236
Details IPv4 2
185.162.131.87
Details IPv4 2
185.231.155.59
Details IPv4 2
185.128.213.12
Details IPv4 2
31.41.47.190
Details IPv4 2
167.179.86.255
Details IPv4 2
202.168.153.228
Details IPv4 2
185.222.202.139
Details IPv4 2
103.208.86.140
Details IPv4 2
169.239.129.125
Details IPv4 2
103.208.86.39
Details IPv4 2
103.208.86.252
Details IPv4 3
185.99.132.119
Details IPv4 2
103.208.86.226
Details IPv4 2
185.99.132.128
Details IPv4 2
169.239.128.150
Details IPv4 2
169.239.129.3
Details IPv4 2
169.239.129.27
Details IPv4 2
185.99.132.12
Details IPv4 2
185.255.79.44
Details IPv4 3
185.99.133.83
Details IPv4 2
185.255.79.67
Details IPv4 3
169.239.129.31
Details IPv4 2
185.99.133.2
Details IPv4 2
169.239.128.15
Details IPv4 2
91.201.65.181
Details IPv4 2
146.0.77.62
Details IPv4 2
5.39.221.46
Details IPv4 3
5.39.218.205
Details IPv4 4
5.8.88.254
Details IPv4 4
91.243.80.200
Details IPv4 2
84.38.133.22
Details IPv4 3
146.0.77.18
Details IPv4 3
5.39.221.60
Details IPv4 2
91.243.80.84
Details IPv4 2
74.220.215.239
Details IPv4 2
146.0.72.139
Details IPv4 2
146.0.72.188
Details IPv4 2
185.236.76.175
Details IPv4 2
5.39.218.162
Details IPv4 2
146.0.77.104
Details IPv4 2
146.0.77.112
Details IPv4 2
213.183.63.227
Details IPv4 3
185.244.131.68
Details IPv4 2
217.160.233.141
Details IPv4 2
185.36.191.42
Details IPv4 2
185.175.58.136
Details IPv4 2
185.29.8.45
Details IPv4 2
5.39.218.210
Details IPv4 2
5.188.231.47
Details IPv4 2
185.70.184.32
Details IPv4 2
185.29.9.41
Details IPv4 2
185.161.208.9
Details IPv4 2
185.70.186.151
Details IPv4 2
151.248.115.41
Details IPv4 2
185.154.52.83
Details IPv4 2
185.154.52.142
Details IPv4 2
185.236.76.216
Details Pdb 1
c:\_bkittest\dispenser\release_notoken\dispenserxfs.pdb
Details Pdb 2
dispenserxfs.pdb
Details Url 60
https://github.com
Details Url 1
https://github.com/lukebaggett/dnscat2-powershell/blob
Details Url 2
https://en.prothomalo.com/bangladesh/news/196691/six-foreign-citizens-detained-in-never-seen-before
Details Url 2
http://185.70.186.146/rogr.php
Details Url 2
http://185.70.186.146/nc-bank.crt
Details Url 1
http://193.109.69.5/gggm/upl/txt.
Details Url 2
http://193.109.69.5/gggm/book.php
Details Url 2
http://cnc/showthread.php?yz=2&alphayz=
Details Url 2
http://185.29.10.26/showthread.php?yz=1
Details Url 2
http://185.29.10.26/showthread.
Details Url 1
http://185.29.10.26/showthread.php?yz=2&alphayz=1234567
Details Url 2
http://84.38.134.103/f.exe
Details Url 7
https://github.com/empireproject/empire
Details Url 2
http://31.207.45.85/d.dat
Details Url 2
http://clodflarechk.com/cloud.png
Details Url 2
http://thespecsupportservice.com
Details Url 2
http://185.176.221.29/ban3.dat
Details Url 2
http://147.135.170.169/kernel.dat
Details Url 2
http://185.17.121.223/date2.date
Details Url 2
http://185.180.196.43/date2.dat
Details Url 2
http://79.137.127.216/ba.dat
Details Url 2
http://185.180.196.43/date1.dat
Details Url 2
http://185.17.121.223/date1.date
Details Url 2
http://msboxoffice.com/date1.dat
Details Url 2
http://185.17.123.201/dat1.omg
Details Url 2
http://185.17.123.201/dat2.omg
Details Url 2
http://185.17.123.201/dat3.omg
Details Url 2
http://185.17.120.235/dat3.omg
Details Url 2
http://185.17.120.235/dat1.omg
Details Url 2
http://185.17.120.235/dat4.omg
Details Url 2
http://213.183.63.242/fact1.omg
Details Url 2
http://195.123.209.169/dat1.omg
Details Url 2
http://dorlon-sa.com
Details Url 2
http://91.200.41.236/s.dat
Details Url 2
http://185.162.131.87/p.dat
Details Url 2
http://185.231.155.59/s.dat
Details Url 2
http://185.128.213.12/s.dat
Details Url 2
http://31.41.47.190/s.dat
Details Url 2
http://167.179.86.255/dns.dat
Details Url 2
http://202.168.153.228/dns3.dat
Details Url 2
https://www.thedailystar.net/frontpage/news/three-banks-hit-cyberattacks-1760629
Details Url 2
https://www.youtube.com/watch?v=un1h
Details Url 2
https://www.prothomalo.com/economy/article/1597491/%25e0%25a6%25a6%25e0%25a7
Details Url 2
https://www.dhakatribune.com/bangladesh/crime/2019/06/02/police-bank-authorities-in-
Details Url 2
https://www.youtube.com/watch?v%3dun1h
Details Url 2
https://www.kommersant.ru/doc/3881484
Details Windows Registry Key 188
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
Details Windows Registry Key 582
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Details Windows Registry Key 2
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services
Details Windows Registry Key 9
HKCU\Software\Microsoft\Windows\CurrentVersion