Industroyer2
Image Description
Common Information
Type Value
UUID fcea76fc-e540-4c8b-bc7d-e746b8895a56
Fingerprint 8b09bbb268ba781c5f945860eba154ad0e31695f8b4de9edf2fb52e6381c6b52
Analysis status DONE
Considered CTI value 2
Text language
Published Aug. 3, 2022, 6:11 p.m.
Added to db March 11, 2024, 7:04 p.m.
Last updated Aug. 31, 2024, 1:46 a.m.
Headline Industroyer2
Title Industroyer2
Detected Hints/Tags/Attributes 73/2/29
Attributes
Details Type #Events CTI Value
Details Domain 4128
github.com
Details File 1
aorta.php
Details File 1
setattr.php
Details File 1
paramctrl.php
Details File 1
statinfo.php
Details File 16
check.php
Details File 1
vercontrol.php
Details File 2127
cmd.exe
Details File 142
wmiprvse.exe
Details Github username 26
eset
Details ICS-CERT ADVISORY 4
ICSA-15-202-01
Details IPv4 3
95.143.193.182
Details IPv4 3
5.61.38.31
Details IPv4 3
144.76.119.48
Details IPv4 3
78.46.40.239
Details IPv4 3
95.143.193.131
Details IPv4 4
46.165.222.6
Details IPv4 1
4.76.119.48
Details IPv4 1441
127.0.0.1
Details MITRE ATT&CK Techniques 29
T1484.001
Details Threat Actor Identifier - APT 783
APT28
Details Threat Actor Identifier - APT 665
APT29
Details Url 1
https://95.143.193.182/franceaviatelecom8/statmach/aorta.php
Details Url 1
https://5.61.38.31/epsiloneridani0/setattr.php
Details Url 1
https://144.76.119.48/arrakis02/loadvers/paramctrl.php
Details Url 1
https://78.46.40.239/salusasecundus2/segments/statinfo.php
Details Url 1
https://95.143.193.131/houseatreides94/dirconf/check.php
Details Url 1
https://46.165.222.6/basharofthesardaukars/tempreports/vercontrol.php
Details Url 1
https://github.com/eset/malware-research/tree/master/industroyer2