Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks | CISA
Tags
Common Information
Type | Value |
---|---|
UUID | 33ff6ebc-a05b-4221-8a9f-c0e004b702e2 |
Fingerprint | b44508f08175a1cb |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Feb. 24, 2022, midnight |
Added to db | Sept. 11, 2022, 12:31 p.m. |
Last updated | Nov. 17, 2024, 10:40 p.m. |
Headline | Alert (AA22-055A ) |
Title | Iranian Government-Sponsored Actors Conduct Cyber Operations Against Global Government and Commercial Networks | CISA |
Detected Hints/Tags/Attributes | 273/4/123 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://www.cisa.gov/uscert/ncas/alerts/aa22-055a |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 217 | cve-2020-1472 |
|
Details | CVE | 71 | cve-2020-0688 |
|
Details | CVE | 269 | cve-2017-0199 |
|
Details | Domain | 41 | stopransomware.gov |
|
Details | Domain | 1 | gram.app |
|
Details | Domain | 128 | www.fbi.gov |
|
Details | Domain | 56 | fbi.gov |
|
Details | Domain | 55 | cisa.dhs.gov |
|
Details | Domain | 29 | nsa.gov |
|
Details | Domain | 53 | ncsc.gov.uk |
|
Details | 29 | cywatch@fbi.gov |
||
Details | 22 | cisaservicedesk@cisa.dhs.gov |
||
Details | 14 | cybersecurity_requests@nsa.gov |
||
Details | File | 28 | goopdate.dll |
|
Details | File | 105 | googleupdate.exe |
|
Details | File | 3 | goopdate.dat |
|
Details | File | 35 | config.txt |
|
Details | File | 4 | gram_app.exe |
|
Details | File | 6 | index.exe |
|
Details | File | 3 | terms.xls |
|
Details | File | 3 | fml.dll |
|
Details | File | 459 | regsvr32.exe |
|
Details | File | 66 | normal.dot |
|
Details | File | 2 | temp.jpg |
|
Details | File | 59 | csc.exe |
|
Details | File | 47 | cmstp.exe |
|
Details | File | 456 | mshta.exe |
|
Details | File | 1018 | rundll32.exe |
|
Details | File | 26 | procdump64.exe |
|
Details | File | 2126 | cmd.exe |
|
Details | File | 18 | makecab.exe |
|
Details | File | 26 | app.exe |
|
Details | File | 3 | %localappdata%\microsoftwindowsoutlookdataplus.txt |
|
Details | File | 3 | microsoftwindowsoutlookdataplus.txt |
|
Details | File | 3 | %appdata%\outlookmicrosift\index.exe |
|
Details | md5 | 5 | 15fa3b32539d7453a9a85958b77d4c95 |
|
Details | md5 | 5 | 5763530f25ed0ec08fb26a30c04009f1 |
|
Details | sha1 | 4 | 11d594f3b3cf8525682f6214acb7b7782056d282 |
|
Details | sha1 | 4 | 2a6ddf89a8366a262b56a251b00aafaed5321992 |
|
Details | sha256 | 4 | b75208393fa17c0bcbc1a07857686b8c0d7e0471d00a167a07fd0d52e1fc9054 |
|
Details | sha256 | 4 | bf090cf7078414c9e157da7002ca727f06053b39fa4e377f9a0050f2af37d3a2 |
|
Details | IPv4 | 5 | 88.119.170.124 |
|
Details | IPv4 | 6 | 5.199.133.149 |
|
Details | IPv4 | 2 | 45.142.213.17 |
|
Details | IPv4 | 2 | 45.142.212.61 |
|
Details | IPv4 | 2 | 45.153.231.104 |
|
Details | IPv4 | 1 | 46.166.129.159 |
|
Details | IPv4 | 1 | 80.85.158.49 |
|
Details | IPv4 | 3 | 87.236.212.22 |
|
Details | IPv4 | 1 | 88.119.171.213 |
|
Details | IPv4 | 1 | 89.163.252.232 |
|
Details | IPv4 | 1 | 95.181.161.49 |
|
Details | IPv4 | 2 | 95.181.161.50 |
|
Details | IPv4 | 4 | 164.132.237.65 |
|
Details | IPv4 | 1 | 185.25.51.108 |
|
Details | IPv4 | 1 | 185.45.192.228 |
|
Details | IPv4 | 4 | 185.117.75.34 |
|
Details | IPv4 | 2 | 185.118.164.21 |
|
Details | IPv4 | 1 | 185.141.27.143 |
|
Details | IPv4 | 1 | 185.141.27.248 |
|
Details | IPv4 | 4 | 185.183.96.7 |
|
Details | IPv4 | 2 | 185.183.96.44 |
|
Details | IPv4 | 2 | 192.210.191.188 |
|
Details | IPv4 | 1 | 192.210.226.128 |
|
Details | IPv4 | 3 | 10.17.32.18 |
|
Details | Mandiant Temporary Group Assumption | 29 | TEMP.ZAGROS |
|
Details | Mandiant Temporary Group Assumption | 2 | TEMP.JPG |
|
Details | MITRE ATT&CK Techniques | 310 | T1566.001 |
|
Details | MITRE ATT&CK Techniques | 365 | T1204.002 |
|
Details | MITRE ATT&CK Techniques | 227 | T1574.002 |
|
Details | MITRE ATT&CK Techniques | 460 | T1059.001 |
|
Details | MITRE ATT&CK Techniques | 627 | T1027 |
|
Details | MITRE ATT&CK Techniques | 59 | T1059.006 |
|
Details | MITRE ATT&CK Techniques | 380 | T1547.001 |
|
Details | MITRE ATT&CK Techniques | 183 | T1036.005 |
|
Details | MITRE ATT&CK Techniques | 442 | T1071.001 |
|
Details | MITRE ATT&CK Techniques | 40 | T1132.002 |
|
Details | MITRE ATT&CK Techniques | 534 | T1005 |
|
Details | MITRE ATT&CK Techniques | 422 | T1041 |
|
Details | MITRE ATT&CK Techniques | 95 | T1572 |
|
Details | MITRE ATT&CK Techniques | 8 | T1001.001 |
|
Details | MITRE ATT&CK Techniques | 22 | T1589.002 |
|
Details | MITRE ATT&CK Techniques | 21 | T1583.006 |
|
Details | MITRE ATT&CK Techniques | 59 | T1588.002 |
|
Details | MITRE ATT&CK Techniques | 183 | T1566.002 |
|
Details | MITRE ATT&CK Techniques | 310 | T1047 |
|
Details | MITRE ATT&CK Techniques | 137 | T1059.005 |
|
Details | MITRE ATT&CK Techniques | 93 | T1059.007 |
|
Details | MITRE ATT&CK Techniques | 245 | T1203 |
|
Details | MITRE ATT&CK Techniques | 106 | T1204.001 |
|
Details | MITRE ATT&CK Techniques | 31 | T1559.001 |
|
Details | MITRE ATT&CK Techniques | 10 | T1559.002 |
|
Details | MITRE ATT&CK Techniques | 275 | T1053.005 |
|
Details | MITRE ATT&CK Techniques | 10 | T1137.001 |
|
Details | MITRE ATT&CK Techniques | 86 | T1548.002 |
|
Details | MITRE ATT&CK Techniques | 172 | T1555 |
|
Details | MITRE ATT&CK Techniques | 26 | T1027.003 |
|
Details | MITRE ATT&CK Techniques | 19 | T1027.004 |
|
Details | MITRE ATT&CK Techniques | 59 | T1218.005 |
|
Details | MITRE ATT&CK Techniques | 119 | T1218.011 |
|
Details | MITRE ATT&CK Techniques | 48 | T1480 |
|
Details | MITRE ATT&CK Techniques | 298 | T1562.001 |
|
Details | MITRE ATT&CK Techniques | 173 | T1003.001 |
|
Details | MITRE ATT&CK Techniques | 14 | T1003.005 |
|
Details | MITRE ATT&CK Techniques | 245 | T1016 |
|
Details | MITRE ATT&CK Techniques | 230 | T1033 |
|
Details | MITRE ATT&CK Techniques | 119 | T1049 |
|
Details | MITRE ATT&CK Techniques | 433 | T1057 |
|
Details | MITRE ATT&CK Techniques | 585 | T1083 |
|
Details | MITRE ATT&CK Techniques | 99 | T1087.002 |
|
Details | MITRE ATT&CK Techniques | 185 | T1518 |
|
Details | MITRE ATT&CK Techniques | 141 | T1518.001 |
|
Details | MITRE ATT&CK Techniques | 219 | T1113 |
|
Details | MITRE ATT&CK Techniques | 116 | T1560.001 |
|
Details | MITRE ATT&CK Techniques | 36 | T1090.002 |
|
Details | MITRE ATT&CK Techniques | 33 | T1102.002 |
|
Details | MITRE ATT&CK Techniques | 25 | T1104 |
|
Details | MITRE ATT&CK Techniques | 492 | T1105 |
|
Details | MITRE ATT&CK Techniques | 99 | T1132.001 |
|
Details | MITRE ATT&CK Techniques | 141 | T1219 |
|
Details | Windows Registry Key | 1 | HKLM\Software\NFC\IPA |
|
Details | Windows Registry Key | 1 | HKLM\Software\NFC |
|
Details | Windows Registry Key | 3 | HKCU\Software\Microsoft\Windows\CurrentVersion\Run\OutlookMicrosift |