June-2014.indd
Image Description
Common Information
Type Value
UUID e900968b-ec3e-4e9c-ada4-207d27b1b133
Fingerprint 1b39a33822d7e88bf89f68f5f5d59e35ec003a3c7321192333277fa405020923
Analysis status DONE
Considered CTI value 2
Text language
Published June 2, 2014, 4:09 p.m.
Added to db April 18, 2024, 9:37 a.m.
Last updated Aug. 31, 2024, 12:59 a.m.
Headline June-2014.indd
Title June-2014.indd
Detected Hints/Tags/Attributes 251/3/123
Attributes
Details Type #Events CTI Value
Details CVE 29
cve-2013-3906
Details CVE 3
cve-2014-0315
Details CVE 2
cve-2013-1324
Details CVE 2
cve-2013-1296
Details Domain 404
www.virusbtn.com
Details Domain 202
krebsonsecurity.com
Details Domain 6
blog.spiderlabs.com
Details Domain 175
www.zdnet.com
Details Domain 216
www.symantec.com
Details Domain 262
www.welivesecurity.com
Details Domain 70
nakedsecurity.sophos.com
Details Domain 3
www.trusteer.com
Details Domain 1
secureandroidupdate.org
Details Domain 1
www.fuzzing.org
Details Domain 6
www.chromium.org
Details Domain 337
virusbtn.com
Details Domain 19
www.smi-online.co.uk
Details Domain 56
www.maawg.org
Details Domain 113
www.usenix.org
Details Domain 169
www.first.org
Details Domain 8
www.hackinparis.com
Details Domain 222
www.blackhat.com
Details Domain 39
www.defcon.org
Details Domain 2
44con.com
Details Domain 15
www.intelligence-sec.com
Details Domain 5
congress.isc2.org
Details Domain 10
www.isse.eu.com
Details Domain 5
secsi.polymtl.ca
Details Domain 3
www.avar2014.com
Details Domain 17
www.botconf.eu
Details Email 330
editorial@virusbtn.com
Details Email 55
conference@virusbtn.com
Details File 10
blog.spi
Details File 1
esta-with-ploutus.html
Details File 1
rcgcyg.exe
Details File 748
kernel32.dll
Details File 1
%temp%\ rcgcyg.exe
Details File 1
%temp%\1c123a16.exe
Details File 1
k1.rar
Details File 1
1c123a16.exe
Details File 1
k2.rar
Details File 1
k3.rar
Details File 1
k4.rar
Details File 1
k5.rar
Details File 1
twzvxx.exe
Details File 96
rar.exe
Details File 1
8x.exe
Details File 1
%temp%\317a552f.exe
Details File 1
317a552f.exe
Details File 1
8x.bat
Details File 1
%temp%\6507656e.bat
Details File 125
ntoskrnl.exe
Details File 1122
svchost.exe
Details File 478
lsass.exe
Details File 3
201404.pdf
Details File 1
201405.pdf
Details File 459
regsvr32.exe
Details File 1260
explorer.exe
Details File 20
sysprep.exe
Details File 263
iexplore.exe
Details File 12
refox.exe
Details File 271
chrome.exe
Details File 533
ntdll.dll
Details File 291
user32.dll
Details File 76
gdi32.dll
Details File 146
wininet.dll
Details File 130
ws2_32.dll
Details File 86
ole32.dll
Details File 50
urlmon.dll
Details File 47
oleaut32.dll
Details File 30
comctl32.dll
Details File 11
comdlg32.dll
Details File 19
wintrust.dll
Details File 2
iecl.dll
Details File 6
mlang.dll
Details File 2
crclreg.dll
Details File 2
crcl.dll
Details File 17
content.js
Details File 2
ffcl.dll
Details File 2
gbsniffer.dll
Details File 229
advapi32.dll
Details File 52
bcrypt.dll
Details File 25
nspr4.dll
Details File 31
writeup.jsp
Details File 2
ogl.dll
Details File 33
gdiplus.dll
Details IPv4 1441
127.0.0.1
Details Url 1
http://krebsonsecurity.com/2014/05/thieves-planted-malware-to-hack-
Details Url 1
http://blog.spiderlabs.com/2013/10/having-a-fi
Details Url 1
http://www.zdnet.com/few-european-atms-upgraded-to-windows-7-
Details Url 1
http://ddos.[removed].net:799/cj//k1.rar
Details Url 290
http://www.virusbtn.com
Details Url 4
http://www.symantec.com/security_response
Details Url 1
http://www.welivesecurity.com/2013/03/13/how-
Details Url 4
http://nakedsecurity.sophos.com/exploring-the-
Details Url 1
https://www.trusteer.com/products/trusteer-rapport.
Details Url 18
http://www.virusbtn.com/virusbulletin
Details Url 1
http://secureandroidupdate.org/.
Details Url 1
http://www.pwn2own
Details Url 1
http://www.fuzzing.org/.
Details Url 2
http://www.chromium.org/home/chromium-
Details Url 138
http://www.virusbtn.com/virusbulletin/subscriptions
Details Url 4
http://www.smi-online.co.uk/energy/europe
Details Url 2
http://www.maawg.org/events
Details Url 1
https://www.usenix.org/atc14/vb/.
Details Url 7
http://www.first.org/conference/2014.
Details Url 4
http://www.hackinparis.com/.
Details Url 134
http://www.blackhat.com/.
Details Url 7
https://www.defcon.org/.
Details Url 2
http://44con.com/.
Details Url 8
http://www.intelligence-sec.com
Details Url 9
http://www.virusbtn.com/conference/vb2014/.
Details Url 5
https://congress.isc2.org/.
Details Url 10
http://www.isse.eu.com/.
Details Url 7
http://www.maawg.org
Details Url 1
http://secsi.polymtl.ca/water2014/.
Details Url 3
http://www.avar2014.com/.
Details Url 7
https://www.botconf.eu/.
Details Url 3
http://www.virusbtn.com/conference/vb2015
Details Windows Registry Key 14
HKLM\SOFTWARE
Details Windows Registry Key 3
HKCU\Software\Microsoft\Notepad
Details Windows Registry Key 3
HKCU\Software\AppDataLow
Details Windows Registry Key 26
HKCU\Software\Microsoft