You’d be surprised to know what devices are still using Windows CE
Tags
country: | Argentina Iran Israel Kazakhstan Saudi Arabia |
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Exploits - T1587.004 Exploits - T1588.005 Hardware - T1592.001 Malware - T1587.001 Malware - T1588.001 Social Media - T1593.001 Software - T1592.002 Tool - T1588.002 Connection Proxy - T1090 |
Common Information
Type | Value |
---|---|
UUID | 30d14bf1-7f3a-433d-b7f9-4d792ca0c432 |
Fingerprint | 27903956de34f0f5 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Nov. 2, 2023, 2 p.m. |
Added to db | Nov. 18, 2023, 11:49 p.m. |
Last updated | Nov. 15, 2024, 10:46 a.m. |
Headline | Cisco Talos Intelligence Blog |
Title | You’d be surprised to know what devices are still using Windows CE |
Detected Hints/Tags/Attributes | 65/3/20 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://blog.talosintelligence.com/threat-source-newsletter-nov-2-2023/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 68 | ✔ | Cisco Talos Blog | https://blog.talosintelligence.com/rss/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 116 | cve-2023-4966 |
|
Details | Domain | 3 | 100.sbx.tg |
|
Details | Domain | 127 | pua.win |
|
Details | File | 13 | office.exe |
|
Details | File | 7 | dropper.py |
|
Details | File | 40 | wuauclt.exe |
|
Details | File | 17 | aact.exe |
|
Details | md5 | 1 | af8a072f20c8e647f53eb735528f070d |
|
Details | md5 | 1 | a5cc0738a563489458f6541c3d3dc722 |
|
Details | md5 | 2 | 0e4c49327e3be816022a233f844a5731 |
|
Details | md5 | 10 | a087b2e6ec57b08c0d0750c60f96a74c |
|
Details | md5 | 4 | 3b100bdcd61bb1da816cd7eaf9ef13ba |
|
Details | sha256 | 1 | 21d709b0593c19ad2798903ae02de7ecdbf8033b3e791b70d7595bca64b99721 |
|
Details | sha256 | 1 | 032f2e845d2b9832c7845bc6a7de650ee2148891c8ee442fe3f3a8478e588dbe |
|
Details | sha256 | 2 | 8664e2f59077c58ac12e747da09d2810fd5ca611f56c0c900578bf750cab56b7 |
|
Details | sha256 | 9 | e12b6641d7e7e4da97a0ff8e1a0d4840c882569d47b8fab8fb187ac2b475636c |
|
Details | sha256 | 4 | b9ddbd1a4cec61e6b022a275d66312b5b676f9a0a9537a7708de9aa8ce34de59 |
|
Details | IPv6 | 2 | a::100 |
|
Details | IPv6 | 11 | ::100 |
|
Details | IPv6 | 63 | ::1201 |