Threat Advisory
Image Description
Common Information
Type Value
UUID e4e345a6-0dac-45ec-b3c0-9aac0d3f355d
Fingerprint d1c6f6f00e68a33734477406c7b052dbd7ad35ce17f3b1228c4a977acdd8ea4b
Analysis status DONE
Considered CTI value 2
Text language
Published Jan. 16, 2024, 2:51 p.m.
Added to db Feb. 7, 2024, 7:47 p.m.
Last updated Aug. 31, 2024, 2:49 a.m.
Headline Threat Advisory
Title Threat Advisory
Detected Hints/Tags/Attributes 0/0/41
Attributes
Details Type #Events CTI Value
Details CVE 42
cve-2023-46805
Details CVE 55
cve-2024-21887
Details Domain 2
gpoaccess.com
Details Domain 2
webb-institute.com
Details Domain 2
symantke.com
Details Domain 2
sessionserver.sh
Details Domain 3
visits.py
Details Domain 2
sessionserver.pl
Details Domain 1
libsecure.so
Details Domain 469
www.cisa.gov
Details Domain 56
forums.ivanti.com
Details Domain 36
www.volexity.com
Details Domain 182
www.mandiant.com
Details Domain 435
www.hivepro.com
Details File 5
1.xml
Details md5 1
3d97f55a03ceb4f71671aa2ecf5b24e9
Details md5 1
677c1aa6e2503b56fe13e1568a814754
Details md5 1
6de651357a15efd01db4e658249d4981
Details md5 1
d0c7a334a4d9dcd3c6335ae13bee59ea
Details IPv4 2
206.189.208.156
Details IPv4 2
75.145.243.85
Details IPv4 2
47.207.9.89
Details IPv4 3
98.160.48.170
Details IPv4 3
173.220.106.166
Details IPv4 2
73.128.178.221
Details IPv4 2
50.243.177.161
Details IPv4 2
50.213.208.89
Details IPv4 2
64.24.179.210
Details IPv4 2
75.145.224.109
Details IPv4 2
50.215.39.49
Details IPv4 2
71.127.149.194
Details IPv4 2
173.53.43.7
Details Mandiant Uncategorized Groups 11
UNC5221
Details MITRE ATT&CK Techniques 152
T1056
Details MITRE ATT&CK Techniques 118
T1056.001
Details MITRE ATT&CK Techniques 93
T1059.007
Details MITRE ATT&CK Techniques 695
T1059
Details MITRE ATT&CK Techniques 542
T1190
Details MITRE ATT&CK Techniques 245
T1203
Details MITRE ATT&CK Techniques 110
T1588.006
Details MITRE ATT&CK Techniques 17
T1659