Weekly Intelligence Report - 22 Nov 2024 | #ransomware | #cybercrime | National Cyber Security Consulting
Tags
cmtmf-attack-pattern: Application Layer Protocol Command And Scripting Interpreter Masquerading Obfuscated Files Or Information Scheduled Task/Job
country: United Arab Emirates Belgium Malaysia Canada Kuwait North Korea Denmark India Indonesia Iran Japan South Korea Sweden Singapore Romania Russia Vietnam United States Of America U.S. Virgin Islands
maec-delivery-vectors: Watering Hole
attack-pattern: Data Direct Model Applescript - T1059.002 Software Discovery - T1418 Application Layer Protocol - T1437 Clipboard Data - T1414 Code Signing - T1553.002 Command And Scripting Interpreter - T1623 Credentials - T1589.001 Data Destruction - T1662 Data Destruction - T1485 Data Encrypted For Impact - T1471 Data Encrypted For Impact - T1486 Dll Side-Loading - T1574.002 Domains - T1583.001 Domains - T1584.001 Email Addresses - T1589.002 Exploits - T1587.004 Exploits - T1588.005 File And Directory Discovery - T1420 File And Directory Permissions Modification - T1222 File Deletion - T1070.004 File Deletion - T1630.002 Hidden Files And Directories - T1564.001 Hidden Window - T1564.003 Hide Artifacts - T1628 Hide Artifacts - T1564 Hijack Execution Flow - T1625 Hijack Execution Flow - T1574 Indicator Removal From Tools - T1027.005 Ingress Tool Transfer - T1544 Ip Addresses - T1590.005 Javascript - T1059.007 Malicious File - T1204.002 Malware - T1587.001 Malware - T1588.001 Masquerading - T1655 Obfuscated Files Or Information - T1406 Process Discovery - T1424 System Information Discovery - T1426 Multi-Factor Authentication - T1556.006 Phishing - T1660 Phishing - T1566 Powershell - T1059.001 Python - T1059.006 Scheduled Task/Job - T1603 Security Software Discovery - T1418.001 Security Software Discovery - T1518.001 Social Media - T1593.001 Social Media Accounts - T1585.001 Social Media Accounts - T1586.001 Software - T1592.002 Software Discovery - T1518 Software Packing - T1027.002 Software Packing - T1406.002 System Location Discovery - T1614 Windows Command Shell - T1059.003 Unix Shell - T1059.004 Virtualization/Sandbox Evasion - T1497 Tool - T1588.002 Vulnerabilities - T1588.006 Unix Shell - T1623.001 Virtualization/Sandbox Evasion - T1633 Applescript - T1155 Standard Application Layer Protocol - T1071 Clipboard Data - T1115 Code Signing - T1116 Command-Line Interface - T1059 Dll Side-Loading - T1073 Execution Through Module Load - T1129 File And Directory Discovery - T1083 File Deletion - T1107 Hidden Files And Directories - T1158 Hidden Window - T1143 Indicator Removal On Host - T1070 Indicator Removal From Tools - T1066 Indirect Command Execution - T1202 Remote File Copy - T1105 Masquerading - T1036 Network Share Discovery - T1135 Obfuscated Files Or Information - T1027 Powershell - T1086 Process Discovery - T1057 Query Registry - T1012 Scheduled Task - T1053 Security Software Discovery - T1063 Software Packing - T1045 System Information Discovery - T1082 Windows Management Instrumentation - T1047 Data Destruction Masquerading
Common Information
Type Value
UUID 4a815380-2fba-4c0c-be72-3a5e471e9ebb
Fingerprint 943409d3afb39fd9
Analysis status DONE
Considered CTI value 2
Text language
Published Nov. 22, 2024, 1 a.m.
Added to db Nov. 22, 2024, 2:56 a.m.
Last updated Dec. 21, 2024, 4:56 a.m.
Headline Weekly Intelligence Report – 22 Nov 2024 | #ransomware | #cybercrime
Title Weekly Intelligence Report - 22 Nov 2024 | #ransomware | #cybercrime | National Cyber Security Consulting
Detected Hints/Tags/Attributes 294/4/53
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 6 National Cyber Security Consulting http://nationalcybersecurity.com/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CVE 3
cve-2024-2550
Details Domain 1
ransomware.target
Details Domain 4
synaptics.zip
Details Domain 5
tvdseo.com
Details Domain 4
aehack.com
Details Domain 1
www.dragoncapital.com.vn
Details Domain 1
www.princepipes.com
Details Domain 49
security.paloaltonetworks.com
Details Domain 1
www.paaf.gov.kw
Details Domain 1
kfcku.com
Details File 1
ransomware.tar
Details File 3
+readme-warning+.txt
Details File 4
synaptics.zip
Details File 6
synaptics.exe
Details File 3
windowssecurity.bat
Details File 42
key4.db
Details File 33
profiles.ini
Details File 3
important_logins.txt
Details File 3
all_passwords.txt
Details File 3
facebook_cookies.txt
Details File 4
webappsstore.sql
Details File 3
db_maxcare.sql
Details File 11
preload.js
Details MITRE ATT&CK Techniques 501
T1053
Details MITRE ATT&CK Techniques 368
T1059.003
Details MITRE ATT&CK Techniques 131
T1129
Details MITRE ATT&CK Techniques 246
T1574.002
Details MITRE ATT&CK Techniques 166
T1027.002
Details MITRE ATT&CK Techniques 49
T1027.005
Details MITRE ATT&CK Techniques 371
T1036
Details MITRE ATT&CK Techniques 323
T1070.004
Details MITRE ATT&CK Techniques 63
T1202
Details MITRE ATT&CK Techniques 270
T1222
Details MITRE ATT&CK Techniques 100
T1564.001
Details MITRE ATT&CK Techniques 75
T1564.003
Details MITRE ATT&CK Techniques 520
T1012
Details MITRE ATT&CK Techniques 472
T1057
Details MITRE ATT&CK Techniques 1062
T1082
Details MITRE ATT&CK Techniques 629
T1083
Details MITRE ATT&CK Techniques 191
T1135
Details MITRE ATT&CK Techniques 257
T1497
Details MITRE ATT&CK Techniques 152
T1518.001
Details MITRE ATT&CK Techniques 54
T1614
Details MITRE ATT&CK Techniques 89
T1115
Details MITRE ATT&CK Techniques 479
T1071
Details MITRE ATT&CK Techniques 101
T1485
Details MITRE ATT&CK Techniques 521
T1486
Details MITRE ATT&CK Techniques 15
T1059.002
Details MITRE ATT&CK Techniques 93
T1059.004
Details MITRE ATT&CK Techniques 116
T1564
Details MITRE ATT&CK Techniques 523
T1105
Details Url 2
https://security.paloaltonetworks.com/cve-2024-2550
Details Url 1
https://kfcku.com