Rewterz Threat Alert – REvil Ransomware Supply Chain Attack – Active IOCs - Rewterz
Tags
attack-pattern: | Data Server - T1583.004 Server - T1584.004 Software - T1592.002 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | 37ff7a17-562f-490e-9d5e-a5fc61babb28 |
Fingerprint | 853bc1ec241fae5a |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | July 8, 2021, 4:03 p.m. |
Added to db | Dec. 19, 2024, 8:41 a.m. |
Last updated | Dec. 19, 2024, 5:02 p.m. |
Headline | Rewterz Threat Alert – REvil Ransomware Supply Chain Attack – Active IOCs |
Title | Rewterz Threat Alert – REvil Ransomware Supply Chain Attack – Active IOCs - Rewterz |
Detected Hints/Tags/Attributes | 20/1/9 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 4 | cve-2021-1359 |
|
Details | md5 | 1 | 5de6ec9265f79a31a9845c8a504d28f0 |
|
Details | sha1 | 1 | 7b6621202ac7795e89891b7bd65e769ba6c267c5 |
|
Details | sha256 | 1 | 32fc03caa22bc3bbf778b04da675e528dd7125a61da6f9fc5e532230745bcd8c |
|
Details | IPv4 | 1 | 31.42.177.52 |
|
Details | IPv4 | 2 | 45.153.241.113 |
|
Details | Url | 1 | http://31.42.177.52/dpixel |
|
Details | Url | 1 | http://31.42.177.52/submit.php |
|
Details | Url | 1 | http://45.153.241.113/download/pload.exe |