Threat Advisory
Image Description
Common Information
Type Value
UUID d32f8ca8-6e0f-40a0-aa79-6575069eacff
Fingerprint c92018050c2bf411b786b161e8ccb0b4466d0cdcf396438ad52d7312f7b069e3
Analysis status DONE
Considered CTI value 2
Text language
Published Nov. 7, 2023, 5:27 p.m.
Added to db Feb. 7, 2024, 7:31 p.m.
Last updated Aug. 31, 2024, 2:24 a.m.
Headline Threat Advisory
Title Threat Advisory
Detected Hints/Tags/Attributes 75/4/26
Attributes
Details Type #Events CTI Value
Details Domain 224
unit42.paloaltonetworks.com
Details Domain 435
www.hivepro.com
Details File 2
bfg.exe
Details File 3
systems.txt
Details IPv4 3
185.105.46.34
Details IPv4 3
185.105.46.19
Details IPv4 3
93.188.207.110
Details IPv4 3
109.237.107.212
Details IPv4 3
217.29.62.166
Details IPv4 3
81.177.22.182
Details MITRE ATT&CK Techniques 36
T1595
Details MITRE ATT&CK Techniques 542
T1190
Details MITRE ATT&CK Techniques 289
T1003
Details MITRE ATT&CK Techniques 157
T1560
Details MITRE ATT&CK Techniques 276
T1490
Details MITRE ATT&CK Techniques 164
T1574
Details MITRE ATT&CK Techniques 695
T1059
Details MITRE ATT&CK Techniques 125
T1110
Details MITRE ATT&CK Techniques 534
T1005
Details MITRE ATT&CK Techniques 422
T1041
Details MITRE ATT&CK Techniques 93
T1485
Details MITRE ATT&CK Techniques 14
T1561
Details Deprecated Microsoft Threat Actor Naming Taxonomy (Groups in development) 2
DEV-0227
Details Pdb 1
dropper.pdb
Details Url 3
https://unit42.paloaltonetworks.com/agonizing-serpens-targets-israeli-tech-higher-ed-sectors
Details Url 1
https://www.hivepro.com/threat-advisory/iran-based-agrius-deploys-fantasy-wiper-to-attack-it-