Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
Image Description
Common Information
Type Value
UUID 8cf9b302-6d8a-495a-bbf8-85fceffd2b16
Fingerprint ab369a936af58135c12790eacd38a97b2b8fcf19a18f0be5c55cc9fe5ed4483f
Analysis status DONE
Considered CTI value 2
Text language
Published Sept. 5, 2024, 1:32 p.m.
Added to db Oct. 31, 2024, 11:37 a.m.
Last updated Oct. 31, 2024, 11:41 a.m.
Headline Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
Title Russian Military Cyber Actors Target U.S. and Global Critical Infrastructure
Detected Hints/Tags/Attributes 267/4/397
Attributes
Details Type #Events CTI Value
Details CERT Ukraine 49
UAC-0056
Details CVE 217
cve-2020-1472
Details CVE 80
cve-2021-26084
Details CVE 21
cve-2021-3156
Details CVE 60
cve-2021-4034
Details CVE 5
cve-2022-27666
Details CVE 9
cve-2021-33044
Details CVE 9
cve-2021-33045
Details CVE 122
cve-2022-26134
Details CVE 20
cve-2022-26138
Details CVE 27
cve-2022-3236
Details Domain 469
www.cisa.gov
Details Domain 831
example.com
Details Domain 6
bxss.me
Details Domain 3
hitccruvbrumn76c1b.bxss.me
Details Domain 77
mega.nz
Details Domain 88
secretsdump.py
Details Domain 37
psexec.py
Details Domain 23
ntlmrelayx.py
Details Domain 4
krbrelayx.py
Details Domain 27
responder.py
Details Domain 2
dns.test658324901domain.me
Details Domain 55
cisa.dhs.gov
Details Domain 23
kali.org
Details Domain 152
cisa.gov
Details Domain 29
nsa.gov
Details Domain 112
cdn.discordapp.com
Details Domain 1
lashevychdirekcy.atom.gov.ua.zip
Details Domain 4
3237.site
Details Domain 5
smm2021.net
Details Domain 372
wscript.shell
Details Domain 6
djvu.sh
Details Domain 3
interlinks.top
Details Domain 4
3proxy.ru
Details Domain 16
ngrok.com
Details Domain 4
nssm.cc
Details Email 2
index.php?log=to@example.com
Details Email 1
377.3183.1bf6c.19446.2@bxss.me
Details Email 5
vulnerability@cisa.dhs.gov
Details Email 37
report@cisa.gov
Details Email 14
cybersecurity_requests@nsa.gov
Details File 1204
index.php
Details File 3
log.htm
Details File 10
login.htm
Details File 14
i.php
Details File 8
tunnel.jsp
Details File 85
secretsdump.py
Details File 34
psexec.py
Details File 22
ntlmrelayx.py
Details File 4
krbrelayx.py
Details File 25
responder.py
Details File 1
9oomla.php
Details File 17
contact.php
Details File 3
1.pst
Details File 383
security.txt
Details File 16
stage1.exe
Details File 20
stage2.exe
Details File 12
tbopbh.jpg
Details File 3
saint.exe
Details File 2
puttyjejfrwu.exe
Details File 4
ua.zip
Details File 3
test01.exe
Details File 2
load2022.exe
Details File 69
client.exe
Details File 5
asd.exe
Details File 1208
powershell.exe
Details File 9
nmddfrqqrbyjeygggda.vbs
Details File 11
advancedrun.exe
Details File 23
c:\windows\system32\sc.exe
Details File 83
installutil.exe
Details File 6
frkmlkdkdubkznbkmcf.dll
Details File 2125
cmd.exe
Details File 2
avbbwys.dll
Details File 2
azkebvoyswvjnrpmn.dll
Details File 2
budoejokuqbge.dll
Details File 2
bwqdffttejlkeqe.dll
Details File 4
e.dll
Details File 2
cpdvzvzyghy.dll
Details File 2
ctiktdfyauejxfak.dll
Details File 2
czxhayyankwsp.dll
Details File 2
djpajq.dll
Details File 2
dmdtflkcgebf.dll
Details File 1
kgd.dll
Details File 2
encuutwvdqbxlxh.dll
Details File 2
fdgofjdvmmllgsxunb.dll
Details File 2
fkhzvcuucaprsibp.dll
Details File 2
fkthhyexkr.dll
Details File 2
fqattuyxknkhv.dll
Details File 2
fqyubbzbubsge.dll
Details File 2
gsiook.dll
Details File 2
gutjuhi.dll
Details File 1
zx.dll
Details File 2
hsoahb.dll
Details File 2
jdfzavlqr.dll
Details File 2
jrdggfjvve.dll
Details File 2
jteieurqgvpgnhw.dll
Details File 1
ho.dll
Details File 2
kdmvyizz.dll
Details File 2
kfxghcmg.dll
Details File 1
pd.dll
Details File 2
lsurhpmpyewhv.dll
Details File 1
ip.dll
Details File 2
mhnovdgzzidqx.dll
Details File 1
wqd.dll
Details File 2
mppveiyannobrcdlkd.dll
Details File 2
nbbudwt.dll
Details File 2
nhqcfzagulwaw.dll
Details File 2
nlzhpvuzzoycqnnpl.dll
Details File 2
nvxwbzciqarteyuz.dll
Details File 1
vgq.dll
Details File 2
ofgdwttnmqibnmpqx.dll
Details File 2
olkscszculdbzvco.dll
Details File 2
onkwzkpfuqazvali.dll
Details File 2
opaqwrazeyyilbbjlkf.dll
Details File 1
atuu.dll
Details File 2
sutragevr.dll
Details File 3
l.dll
Details File 2
tosyxesxgrzyb.dll
Details File 2
tpmnkauftdydomyz.dll
Details File 2
tptjtwfhpsjfksqoajt.dll
Details File 2
tsgblplhdwwj.dll
Details File 1
n.dll
Details File 1
hv.dll
Details File 2
waordspinycera.dll
Details File 2
wcfsobntsczz.dll
Details File 2
wpqyhvfnunlabx.dll
Details File 1
eud.dll
Details File 1
cuh.dll
Details File 2
xgcpgrxhchgwz.dll
Details File 2
xgkepoc.dll
Details File 2
xlfthpiq.dll
Details File 2
xlocky.dll
Details File 9
d.dll
Details File 2
xykqrksoqqgyuckfc.dll
Details File 2
yawyjonk.dll
Details File 2
yrknbt.dll
Details File 2
yvbmuigfihprdxgiirp.dll
Details File 2
ywrovtjimixpmizuln.dll
Details File 2
zfgdccnwnee.dll
Details File 2
zkuxhxwbvifejn.dll
Details File 2
zsdflpivel.dll
Details md5 3
896e0f54fc67d72d94b40d7885f10c51
Details md5 8
5d5c99a08a7d927346ca2dafa7973fc1
Details md5 3
eac0ae655d344c25ff467a929790885c
Details md5 3
764f691b2168e8b3b6f9fb6582e2f819
Details md5 8
14c8482f302b5e81e3fa1b18a509289d
Details md5 7
b3370eb3c5ef6c536195b3bea0120929
Details md5 9
e61518ae9454a563b8f842286bbdb87b
Details md5 3
7c8cb5598e724d34384cce7402b11f0e
Details md5 5
78c855a088924e92a7f60d661c3d1845
Details md5 3
6eed4ee0cc57126e9a096ab9905f471c
Details md5 3
5a537673c34933fc854fbfb65477a686
Details md5 3
de85ca91e1e8100a619de1c25112f1a5
Details md5 3
9b1191f1ceddf312b0d609cd929c6631
Details md5 3
29d83f29c0b0a0b7499e71e7d5cb713f
Details md5 3
17fc12902f4769af3a9271eb4e2dacce
Details md5 4
3907c7fbd4148395284d8e6e3c1dba5d
Details md5 3
d034fe4c71b16b6d331886c24fef2751
Details md5 4
4074798a621232dc448b65db7b1fdd66
Details md5 3
422437f326b8dbe30cc5f103bde31f26
Details md5 4
7f84263fd24f783ff72d5ae91011b558
Details md5 3
562c337b8caca330da2ea6ae07ee5db6
Details md5 4
f73d203bdf924658fd6edf3444c93a50
Details md5 3
58e879213d81333b628434ba4aeb2751
Details md5 4
08dfebc04eb61c9a6d87b6524c1c0f2e
Details md5 3
1c85c0d044ac837e8939564afac1eb32
Details md5 4
8633bd2bbbb5da22c3f8751150186c42
Details md5 3
7234da8ceafbe6586469f18c03cc1832
Details md5 4
5f4df6dd8e644d59eaf182e500b5e7bf
Details md5 3
618d62dd95fd9aeb855fe2ef1403dce5
Details md5 4
955e4c198ee58e40fe92cb74ceefdf00
Details md5 3
d40195a444526eafb0db56d95bf8655d
Details md5 4
a905d620717f75751aa94ceb88995dbc
Details md5 3
d06761b2cff86035a4838110ed6ab622
Details md5 4
2ca6bcf16ee4293a771a1cf7b7b9ee49
Details md5 3
59da31da4db1aa5f9a5c7c0c151422c8
Details md5 4
de1bf141976776becd376a0dac400df6
Details md5 3
de1f9d1f0336ddcff832ad3900acd2f1
Details md5 4
974e7c0b3660fbf18f29eac059f85ac0
Details md5 3
394e056cb6cb732dfd5e0d45d3dae938
Details md5 4
4d8343c40be53d6521244fe74393d937
Details md5 3
b7c1a8d39f46eaf52be90e24565dd6b0
Details md5 4
7a70d5fbbafe3454b76e3ad2f009618f
Details md5 3
2b39eab325906b0a3ab7e584c3d67349
Details md5 4
df4f856f783d23fb01af1e0e64bc0e20
Details md5 3
80f0ee332a452172533ad8863bb3bc63
Details md5 4
f4f4e55a00d2f3a433c9e5624285ac1c
Details md5 3
9345425cf07b4c39a80cd8540e08bfde
Details md5 4
eef2363744345741e09fe5380eeb4df3
Details md5 3
aecb57e20d2c0b0d9fece2cbcbcc3459
Details md5 4
4bce4831b1dd71f19c55b3e3b5e99856
Details md5 3
58dc7c9577ff90a046359ca255c0c9f4
Details md5 4
19cb20c4e7dbfe15c1aa284752d0fecb
Details md5 3
5c9e2195d10375b746b6717fdb47b5b9
Details md5 4
2b5f159f022109a8de1bc5dd9e3138a0
Details md5 3
afbb9459d4a0f60d7ffb3b3532d11bc2
Details md5 4
8d3d4d702ba6b4be2766a41bfe5ff76e
Details md5 3
a1b509254a0a1daa7e00d279ec974461
Details md5 4
0e03103e8110785156105946e48ea9e0
Details md5 3
791a81f31a8e7090a7d5417451e09efa
Details md5 4
fba76f4eb2e7a2eb17193bebe290a198
Details md5 3
e1a15bc13157134f542cd9c55c742460
Details md5 4
c9d1677f4f89b95b41591b23a1dc1a63
Details md5 3
cd62d4a178705b2b90a8babd8613df93
Details md5 4
032f5642d4fb2fdd74e6f20a13c57746
Details md5 3
f34f60375bebad861a35b7c4bb0fa1c8
Details md5 4
a66b3b22a3619f739b197d0d443b700c
Details md5 3
7fe7f33d9b5dbdf3d032d2a10e39f283
Details md5 4
8cfef66b390f08bdbfd940922cf51650
Details md5 3
b32e14a9b7de6c92cd16758fa6e23346
Details md5 4
1220b580cef1bf22351e271773945d20
Details md5 3
b85538f665fdb6c8d9a74f2df7369832
Details md5 4
ffa68749aa3fc6495e2c49b01d964339
Details md5 3
869742fb9db71fdb66f00528fe2966ec
Details md5 4
5b884f15dc9b072d7bbad9ec2b249f38
Details md5 3
2128361d8aaae1225d50c9add32006a1
Details md5 4
9152c9de57b5647ee4ab3dff551dc8dd
Details md5 3
56e0446a6d7175a0d09110bc483ddbed
Details md5 4
fc418fdda06ce5982153766dcefb71d9
Details md5 3
6a4fca88ee36fecc5113e188cc39d25c
Details md5 4
5c3b0040e2dece6e17093ae607b79044
Details md5 3
143594597130e301499e5940a5fb798a
Details md5 4
911c7e82f32f78577dcd725a7adb114d
Details md5 3
993f01861aff306df44e6475f7886f37
Details md5 4
e4634ef9bfe7b598b857ad997445b239
Details md5 3
64b9feeccf6c183b9f7138f8fc53acbb
Details md5 4
7e0c42d33921a89724424f17c97037bd
Details md5 3
ddec2d79f460a881849037336ba8968f
Details md5 4
d973210977957209f255b58eb1715b12
Details md5 3
9606b4720a0e73ef1f00505a11aab2f7
Details md5 4
0adc2530cf348c0a3d53a680291a3d67
Details md5 3
f772f5c65d65412f61ef5f2660e33ceb
Details md5 4
f8ffd1eab6223e31b15d0fd6c3c0472e
Details md5 3
875f9200b49db08c33962b0a6bd05ab9
Details md5 4
2e035360971a817b854d7d5a2b008717
Details md5 3
fa97dbe84ce7717b754795fa89f13dce
Details md5 4
601c12596dfea84c2113ae5ee59a52ec
Details md5 3
d8c04ecd646a1f8537a59f63518ef3c6
Details md5 4
47f4534da421daf8089cf34d53f6bb6e
Details md5 3
3bcff990faacbebb8fb470dfe03e2543
Details md5 4
683546b9171a1ea284a96d1b45d1d823
Details md5 3
c265188fdadddb648629e8060601dca7
Details md5 4
af85885a74cfe099676af542dcdc5741
Details md5 3
8a2ba7f9cb6f65edf65dbe579907551e
Details md5 4
673586594242d99ab02118595e457297
Details md5 3
9657c2ef6ed5229740b125df9ca6c915
Details md5 4
0dc5ac12f7690db15c99eaabc11b129c
Details md5 3
a5494ffd9efb7c3df59c527076a05e62
Details md5 4
e2cc52273d56ed66c800a726760c1ed0
Details md5 3
85afdef18d65b0518d709a5a324ea57a
Details md5 4
77675a24040f10c85112d9a219d5f1c7
Details md5 3
da4d81f9ef3b25ea09f34481d923dd9d
Details md5 4
cc4a9db6f250114e26d8d9ba6ab46bc9
Details md5 3
0e6374042b33d78329149a6189a7cb46
Details md5 4
1934e2ebc64d41e37ef53ea0c075e974
Details md5 3
d33f608f561096be24cba91797e0da2f
Details md5 4
332b7f6662e28e3577bd1b269904b940
Details md5 3
32db8abce1618e60441f5c7cf4be0d22
Details md5 4
2b2509c6ee46d6327f2f1c9a75122d15
Details md5 3
dd2431b1f858b4ca14a4ea05fb8c4a06
Details md5 4
9b2924c727aa3a061906321a66c9050c
Details md5 3
7d3b529db1bd896d9fd877b85cafdc64
Details md5 4
de276cf07ccffa18d7ffc35281bca910
Details md5 3
6e1394938c2fecad2d4f5b3bcf357ec0
Details md5 4
d6b41747cb035c4c2b08790cd57f0626
Details md5 3
99305ce01cc2d0f58cd226efb2de893f
Details md5 4
6859fe5a3eead00a563cd93efcc6ea96
Details md5 3
6c152774f6894407075e6f0a2859bbae
Details md5 4
981160dee6cd25fb181e54eca7ff7c22
Details md5 3
343b140977b3f9b227e7e5f82b0fadb5
Details md5 4
95cf2a5a24b0d33d621bb8995d5826bc
Details md5 3
54a9fa9eb337a3b5ca7b0fa4553e439d
Details md5 4
cee5acbfef7e76f52f40b8ae95199c50
Details md5 3
4c19aeecbfca13b8a199703d8b8284b9
Details md5 4
ad0ca738aa6c987e4ee1a87ff2b8acd5
Details md5 3
dc795cb9290b1bc0b7fb1ce9d6ae7c93
Details md5 4
552d9b79cc544fc6c3e8aa204dd00811
Details md5 3
9935a86108e3ae3f72cd15817601dcc6
Details md5 4
5d063eecd894d3d523875bc82ef6f319
Details md5 3
77aa3f342a0d69fda67c853bcc004d48
Details md5 4
d0b00a6c83ce810ec2763af17e8ab1c4
Details md5 3
03af632aa6f87bf9dd4364ee3b612cbb
Details md5 4
9f11e915be5c0d02a3130329cf032a28
Details md5 3
41871fef433d7b4b89fd226fe3a1a2c0
Details md5 4
e21fe98cc8866c0eeecf3549ebcec751
Details md5 3
246d9f9831b125ea7e6ef21bc4c8a0ca
Details md5 4
dea3ae8225913dd98148fc86cfc3bcbe
Details md5 3
9c695be3703194fdb71c212a0832bcf3
Details md5 4
8744cec7547b1e73705c10a264e28e08
Details md5 3
69e58c5ee69f5e5e8a58f4afdd59adfe
Details md5 4
d43446b4a22a597b93b559821ee5ac9b
Details md5 3
540ee8e39150c539fea582b0e77be7b0
Details md5 4
3fe96ff4a5ef0f5346ce645a2a893597
Details md5 3
0a2affa6d895baab087b84e93145da35
Details md5 4
246f31c86bbbe7f65c0126cf4a1a947a
Details md5 3
569c1d31f4c7ec7701d8e4e51b59fe85
Details md5 4
5eaa7e812733a5c8cda734fab2f752d5
Details md5 3
09a2d85e809d36bff82bd5ab773980a3
Details md5 4
96964aed18f65a7acae632f358a093f6
Details md5 3
3ccf799ff208981349cee4fb1a1cf88c
Details md5 4
4e9c55c6fe25d61ca4394de794546fab
Details md5 3
6154760e602bd71192d93f72fbdb486e
Details md5 4
94bf96b76c2a092de8962496ce35deaf
Details md5 3
b0d0a23766fa64ece9315f37b28bb4c0
Details md5 4
1e22d64f263e8ea4b2d37dcd9b7c3012
Details md5 3
ca43a241042b5fcc305393765ae18e69
Details md5 4
28d571ddb5c04d065dfe1be9604663ba
Details md5 3
251f3a4757d9e4de0499cc30c0bc00a9
Details md5 4
755dac7edd17fbf5b5c449dd06c02e14
Details md5 3
9d7ab8b0aa669125d9a5adc4f46c56f3
Details md5 4
af277ae0fbf6cc20f887696ea4756d46
Details md5 3
a9c9c0be8eca3b575c24da0fcf1af1a9
Details md5 4
1cac5c0cb8801e8730447023270d8d56
Details sha256 20
a196c6b8ffcb97ffb276d04f354696e2391311db3841ae16c8c9f56f36a38e92
Details sha256 1
8bedc411012a33ba34f49130d0f186993c6a32dad8976f6a5d82c1ed23054c05
Details sha256 3
b9e64b58d7746cb1d3bed20405ef34d097af08c809d8dad10b9296b0bebb2b0b
Details sha256 3
aa79afbf82b06cda268664b7c83900d8f7a33e0f0071facba0b3d8f7a68ce56a
Details sha256 21
dcbbae5a1c61dbbbb7dcd6dc5dd1eb1169f5329958d38b58c3fd9384081c9b78
Details sha256 12
923eb77b3c9e11d6c56052318c119c1a22d11ab71675e6b95d05eeb73d1accd6
Details sha256 12
9ef7dbd3da51332a78eff19146d21c82957821e464e8133e9594a07d716d892d
Details sha256 5
db5a204a34969f60fe4a653f51d64eee024dbf018edea334e8b3df780eda846f
Details sha256 4
35feefe6bd2b982cb1a5d4c1d094e8665c51752d0a6f7e3cae546d770c280f3a
Details sha256 3
489ab4819830d231c3fc3572c5386cad9d18773a8121373ea8174de981cc9166
Details sha256 3
0dd61a16c625c49ffefaf4ce24cabf9a074028a06640d9bbb804f735ff56dfa3
Details sha256 3
fd4a5398e55beacb2315687a75af5aa15b776b5d36b9800a1792ede3955616c2
Details sha256 4
29ae7b30ed8394c509c561f6117ea671ec412da50d435099756bbb257fafb10b
Details sha256 9
34ca75a8c190f20b8a7596afeb255f2228cb2467bd210b2637965b61ac7ea907
Details IPv4 4
179.43.175.38
Details IPv4 1
81.17.24.130
Details IPv4 1441
127.0.0.1
Details IPv4 619
0.0.0.0
Details IPv4 9
111.111.111.111
Details IPv4 3
5.226.139.66
Details IPv4 3
45.141.87.11
Details IPv4 3
46.101.242.222
Details IPv4 3
62.173.140.223
Details IPv4 3
79.124.8.66
Details IPv4 3
90.131.156.107
Details IPv4 3
112.51.253.153
Details IPv4 3
112.132.218.45
Details IPv4 3
154.21.20.82
Details IPv4 3
179.43.133.202
Details IPv4 3
179.43.142.42
Details IPv4 3
179.43.162.55
Details IPv4 3
179.43.175.108
Details IPv4 2
179.43.176.60
Details IPv4 3
179.43.187.47
Details IPv4 3
179.43.189.218
Details IPv4 3
185.245.84.227
Details IPv4 3
185.245.85.251
Details IPv4 3
194.26.29.84
Details IPv4 3
194.26.29.95
Details IPv4 3
194.26.29.98
Details IPv4 3
194.26.29.251
Details Mandiant Uncategorized Groups 37
UNC2589
Details MITRE ATT&CK Techniques 93
T1485
Details MITRE ATT&CK Techniques 14
T1595.001
Details MITRE ATT&CK Techniques 36
T1595
Details MITRE ATT&CK Techniques 56
T1595.002
Details MITRE ATT&CK Techniques 8
T1590.002
Details MITRE ATT&CK Techniques 168
T1046
Details MITRE ATT&CK Techniques 6
T1596.005
Details MITRE ATT&CK Techniques 95
T1572
Details MITRE ATT&CK Techniques 60
T1588.005
Details MITRE ATT&CK Techniques 542
T1190
Details MITRE ATT&CK Techniques 42
T1588.001
Details MITRE ATT&CK Techniques 41
T1078.001
Details MITRE ATT&CK Techniques 32
T1125
Details MITRE ATT&CK Techniques 89
T1552.001
Details MITRE ATT&CK Techniques 289
T1003
Details MITRE ATT&CK Techniques 442
T1071.001
Details MITRE ATT&CK Techniques 100
T1567.002
Details MITRE ATT&CK Techniques 38
T1550.002
Details MITRE ATT&CK Techniques 49
T1110.003
Details MITRE ATT&CK Techniques 62
T1583.003
Details MITRE ATT&CK Techniques 492
T1105
Details MITRE ATT&CK Techniques 159
T1095
Details MITRE ATT&CK Techniques 104
T1505.003
Details MITRE ATT&CK Techniques 52
T1071.004
Details MITRE ATT&CK Techniques 48
T1090.003
Details MITRE ATT&CK Techniques 157
T1560
Details MITRE ATT&CK Techniques 173
T1003.001
Details MITRE ATT&CK Techniques 43
T1003.002
Details MITRE ATT&CK Techniques 4
T1654
Details MITRE ATT&CK Techniques 89
T1114
Details MITRE ATT&CK Techniques 460
T1059.001
Details MITRE ATT&CK Techniques 5
T1213.001
Details Deprecated Microsoft Threat Actor Naming Taxonomy (Groups in development) 51
DEV-0586
Details Url 43
http://www.cisa.gov/tlp.
Details Url 1
https://cdn.discordapp.com/attachments/928503440139771947/9301086376811847
Details Url 1
https://cdn.discordapp.com/attachments/888408190625128461/8956339522477998
Details Url 1
https://cdn.discordapp.com/attachments/945968593030496269/9459704461495091
Details Url 1
http://cdn.discordapp.com/attachments
Details Url 1
https://cdn.discordapp.com/attachments/928503440139771947/930108637681184768
Details Url 3
https://3proxy.ru
Details Url 4
https://ngrok.com
Details Url 4
https://nssm.cc