A review of the evolution of Andromeda over the years before we say goodbye!
Image Description
Common Information
Type Value
UUID 848304fb-48f9-4f71-b962-2c4bf73e5408
Fingerprint 3f418167b4e1e11ab67bee06038c4c629cbc6508e6447a0230b7a94ef10d404e
Analysis status DONE
Considered CTI value 2
Text language
Published Feb. 6, 2018, 4:01 p.m.
Added to db April 18, 2024, 10:12 a.m.
Last updated Aug. 31, 2024, 1:06 a.m.
Headline A review of the evolution of Andromeda over the years before we say goodbye!
Title A review of the evolution of Andromeda over the years before we say goodbye!
Detected Hints/Tags/Attributes 61/2/37
Attributes
Details Type #Events CTI Value
Details Domain 247
www.virusbulletin.com
Details Domain 33
blog.fortinet.com
Details Domain 1
ca.reuters.com
Details Domain 94
virusbulletin.com
Details Email 52
editor@virusbulletin.com
Details File 1122
svchost.exe
Details File 30
vmwareuser.exe
Details File 13
vmwareservice.exe
Details File 42
vboxservice.exe
Details File 44
vboxtray.exe
Details File 9
sandboxiedcomlaunch.exe
Details File 8
sandboxierpcss.exe
Details File 1
sandoxierpcss.exe
Details File 74
procmon.exe
Details File 71
wireshark.exe
Details File 22
regmon.exe
Details File 19
netmon.exe
Details File 2
lemon.exe
Details File 3
prl_tools_service.exe
Details File 11
prl_tools.exe
Details File 9
prl_cc.exe
Details File 3
sharedintapp.exe
Details File 74
vmtoolsd.exe
Details File 14
vmsrvc.exe
Details File 14
vmusrvc.exe
Details md5 1
73564f834fd0f61c8b5d67b1dae19209
Details md5 1
d7c00d17e7a36987a359d77db4568df0
Details md5 1
b4d37eff59a820d9be2db1ac23fe056e
Details md5 1
3f2762d18c1abc67e21a7f9ad4fa67fd
Details md5 1
fb0a6857c15a1f596494a28c3cf7379d
Details Url 1
https://blog.fortinet.com/2014/04/23
Details Url 109
https://www.virusbulletin.com
Details Url 1
https://ca.reuters.com/article
Details Url 1
https://blog.fortinet.com/2015/01/07/cracked-
Details Windows Registry Key 1
HKLM\system\currentcontrolset\services\disk\enum
Details Windows Registry Key 164
HKLM\SOFTWARE\Microsoft\Windows
Details Windows Registry Key 1
HKLM\software\policies