Web Shells and RSA NetWitness Part 3
Tags
attack-pattern: | Data Credentials - T1589.001 Server - T1583.004 Server - T1584.004 Web Shell - T1505.003 Tool - T1588.002 Web Shell - T1100 |
Common Information
Type | Value |
---|---|
UUID | 33565cd3-0b8c-40e1-a955-7c507e66a716 |
Fingerprint | 7e5dd07667a38c97 |
Analysis status | DONE |
Considered CTI value | 1 |
Text language | |
Published | Feb. 19, 2019, 4:27 p.m. |
Added to db | Jan. 18, 2023, 9:24 p.m. |
Last updated | Nov. 17, 2024, 5:57 p.m. |
Headline | NetWitness Community |
Title | Web Shells and RSA NetWitness Part 3 |
Detected Hints/Tags/Attributes | 40/1/8 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 19 | community.rsa.com |
|
Details | Domain | 15 | sensepost.com |
|
Details | File | 33 | sethc.exe |
|
Details | File | 8 | tunnel.jsp |
|
Details | Threat Actor Identifier - APT | 297 | APT27 |
|
Details | Url | 1 | https://community.rsa.com/community/products/netwitness/blog/2019/02/12/web-shells-and-netwitness |
|
Details | Url | 1 | https://community.rsa.com/community/products/netwitness/blog/2019/02/13/web-shells-and-netwitness-part-2 |
|
Details | Url | 1 | https://sensepost.com/discover/tools/regeorg |