JavaScript-based BlueCrab Ransomware Has Stopped? - ASEC BLOG
Tags
attack-pattern: | Dns - T1071.004 Dns - T1590.002 Domains - T1583.001 Domains - T1584.001 Javascript - T1059.007 Malware - T1587.001 Malware - T1588.001 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | 1cf12444-c0a7-4e76-9ea8-7f00af610fba |
Fingerprint | a78625fec5e5a6cb |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Aug. 25, 2021, 11:52 a.m. |
Added to db | Sept. 11, 2022, 4:59 p.m. |
Last updated | Sept. 4, 2024, 2:34 p.m. |
Headline | JavaScript-based BlueCrab Ransomware Has Stopped? |
Title | JavaScript-based BlueCrab Ransomware Has Stopped? - ASEC BLOG |
Detected Hints/Tags/Attributes | 30/1/7 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://asec.ahnlab.com/en/26293/ |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 5 | decoder.re |
|
Details | Domain | 1 | www.archivalladolid.org |
|
Details | Domain | 1 | www.mict.it |
|
Details | Domain | 5 | aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion |
|
Details | Url | 1 | http://www.archivalladolid.org/web/한글-워드-무료-다운로드 |
|
Details | Url | 1 | http://www.mict.it/?p=14023 |
|
Details | Url | 3 | http://aplebzu47wgazapdqks6vrcv6zcnjppkbxbr6wketf56nf6aq2nmyoyd.onion |