Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN.indd
Image Description
Common Information
Type Value
UUID 822c588e-7543-481a-90b1-083231b822a9
Fingerprint ec895cb7873a42605e26721176becdaa707847e515736613ff07fa93cc0ecc50
Analysis status DONE
Considered CTI value 2
Text language
Published Aug. 25, 2022, 4:30 p.m.
Added to db March 11, 2024, 7:25 p.m.
Last updated Aug. 31, 2024, 3:50 a.m.
Headline Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN.indd
Title Macintosh HD:Users:Shared:dd:4work:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN:Bitdefender-PR-Whitepaper-BADHATCH-creat5237-en_EN.indd
Detected Hints/Tags/Attributes 123/2/116
Attributes
Details Type #Events CTI Value
Details CVE 67
cve-2021-40539
Details Domain 128
www.bitdefender.com
Details Domain 149
system.security
Details Domain 1
9eca39acdefe.s3.us-west-1.amazonaws.com
Details Domain 2
app.jetboatpilot.com
Details Domain 2
perkinelmer.com
Details Domain 2
node-sdk-sample-760723cc-b7e7-43ef-9f5b-9eca39acdefe.s3.us-west-1.amazonaws.com
Details Email 1
e=certificates@perkinelmer.com
Details File 96
rar.exe
Details File 28
plink.exe
Details File 11
test.jsp
Details File 2
ex.aspx
Details File 1
rr.aspx
Details File 3
request.bin
Details File 1
adselfwrapper.exe
Details File 1
part02.jpg
Details File 1
part05.jpg
Details File 1
part08.jpg
Details File 1
part03.jpg
Details File 1
part04.jpg
Details File 1
part01.jpg
Details File 2
c:\manageengine\adselfservice plus\bin\vm.exe
Details File 3
vm.exe
Details File 1
vm.log
Details File 7
s.bat
Details File 1
c:\windows\temp\vm.exe
Details File 1
c:\windows\temp\s.bat
Details File 1
h.log
Details File 2
git2.exe
Details File 478
lsass.exe
Details File 1018
rundll32.exe
Details File 69
comsvcs.dll
Details File 1
c:\bin\putty\lsass.dmp
Details File 1
c:\\bin\\putty\\w.exe
Details File 1
c:\\bin\\putty\\www.log
Details File 76
ping.exe
Details File 240
wmic.exe
Details File 1
c:\windows\system\s.bat
Details File 1
c:\\windows\\system\\schost.exe
Details File 351
recycle.bin
Details File 2
r.jpg
Details File 1
amsi.exe
Details File 1
c:\windows\system\plink.exe
Details File 1
cache.log
Details File 38
lsass.dmp
Details File 3
sqldumper.exe
Details File 3
c:\windows\system32\winrm.vbs
Details File 1
c:\\windows\\system\\conhost.exe
Details File 1
c:\\windows\\system\\evt.log
Details File 1
c:\\windows\\system32\\t.log
Details File 1
mfa.aspx
Details File 226
certutil.exe
Details File 2
ver.ico
Details File 21
m.exe
Details File 2
c:\windows\temp\nt.exe
Details File 1
adsspwebloader.aspx
Details File 2
c:\inetpub\wwwroot\aspnet_client\css\rr.aspx
Details File 2
c:\inetpub\wwwroot\aspnet_client\css\ex.aspx
Details File 2
y.jsp
Details File 2
nav_working.jsp
Details File 2
tot.jsp
Details File 3
ad.txt
Details File 2
t.jsp
Details File 2
ttt.jsp
Details md5 1
0100466950A604A9D970E81DD24D419F
Details md5 2
742a27fb2a87e2c660fea0bb8184b53e
Details md5 2
84b5e2ac1846d268f1cf9581b63bf953
Details md5 2
182d244ab4cd63e63997c0ec5d34f320
Details md5 2
28e0f31c506b346b8462f61b4903dcb3
Details md5 2
6572fc009a714fefc92dafcb2250f83d
Details md5 2
c8460622d893c5753b44a3ac08f55b4f
Details md5 2
ab6414b83b23807dd530d250829c8bc1
Details md5 2
fe54e8952f4a24d0747078ee8983ff4d
Details md5 2
57988b776d80b73ecc7640c72fc4f4a6
Details md5 2
f23436e941af00ae05ad709a7e1da8e1
Details md5 2
c9951e1646f68e418a186480c31eb00e
Details md5 2
c951158b74ec5b1869d0ff9ae7ae63f9
Details md5 2
eb4f89071009c72248ae26d46900d0f2
Details md5 2
2b65120a2d5703d2a042039a997b1284
Details sha1 1
7c496f5fe65803a45ad7bd8da5f59b8548e08e0a
Details sha1 1
5fa4a2cab917d571a10f9c5a51b04da1f5e39c9f
Details IPv4 2
113.25.2.136
Details IPv4 2
139.162.2.70
Details IPv4 2
193.34.167.229
Details IPv4 2
45.14.71.12
Details IPv4 2
172.86.75.152
Details IPv4 2
103.224.116.98
Details IPv4 2
113.25.10.69
Details IPv4 2
58.221.37.66
Details IPv4 2
125.79.201.69
Details IPv4 2
140.249.254.251
Details IPv4 2
222.67.12.181
Details IPv4 2
112.49.92.234
Details IPv4 2
182.138.144.147
Details IPv4 2
111.126.218.45
Details IPv4 2
171.8.217.156
Details IPv4 2
117.162.164.55
Details IPv4 2
113.2.174.149
Details IPv4 2
49.81.61.251
Details IPv4 2
39.128.220.139
Details IPv4 2
39.144.17.62
Details IPv4 2
39.144.4.66
Details IPv4 2
221.178.126.191
Details IPv4 4
59.163.248.170
Details IPv4 2
39.144.5.87
Details IPv4 2
59.163.248.162
Details IPv4 2
39.144.14.38
Details IPv4 2
221.178.124.233
Details IPv4 2
67.227.206.162
Details IPv4 2
221.178.127.152
Details IPv4 2
39.144.4.160
Details Url 1
https://app.jetboatpilot.com/utils/optimize
Details Url 2
https://app.jetboatpilot.com/utils/optimize/ver.ico
Details Url 2
http://node-sdk-sample-760723cc-b7e7-43ef-9f5b-9eca39acdefe.s3.us-west-1.amazonaws.com/git2.exe
Details Url 15
https://www.bitdefender.com
Details Windows Registry Key 37
HKLM\SYSTEM