Volt Typhoon: Advisory Update
Tags
attack-pattern: | Data Credentials - T1589.001 Malware - T1587.001 Malware - T1588.001 Powershell - T1059.001 Software - T1592.002 Tool - T1588.002 Credential Dumping - T1003 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | 4cd9b141-a829-40db-aacf-5ba63bcf298d |
Fingerprint | a61869512ebfd541 |
Analysis status | DONE |
Considered CTI value | 1 |
Text language | |
Published | Aug. 12, 2024, midnight |
Added to db | Aug. 31, 2024, 1:20 a.m. |
Last updated | Nov. 17, 2024, 6:55 p.m. |
Headline | Volt Typhoon: Advisory Update |
Title | Volt Typhoon: Advisory Update |
Detected Hints/Tags/Attributes | 55/1/10 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://intel471.com/blog/volt-typhoon-advisory-update |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 138 | ✔ | Intel471 | https://intel471.com/blog/feed | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 15 | cve-2021-36934 |
|
Details | File | 2125 | cmd.exe |
|
Details | File | 1208 | powershell.exe |
|
Details | File | 69 | comsvcs.dll |
|
Details | File | 478 | lsass.exe |
|
Details | File | 59 | ntdsutil.exe |
|
Details | File | 2 | ifconfig.exe |
|
Details | File | 46 | netstat.exe |
|
Details | File | 76 | ping.exe |
|
Details | File | 240 | wmic.exe |