BlackCat — In a Shifting Threat Landscape, It Helps to Land on Your Feet: Tech Dive
Common Information
Type Value
UUID 5c5e2c34-e61c-42ad-a266-074194bcfe04
Fingerprint a7319099b4f2b65e
Analysis status DONE
Considered CTI value 2
Text language
Published June 7, 2022, 4:54 p.m.
Added to db Sept. 26, 2022, 9:34 a.m.
Last updated Nov. 17, 2024, 6:56 p.m.
Headline BlackCat — In a Shifting Threat Landscape, It Helps to Land on Your Feet: Tech Dive
Title BlackCat — In a Shifting Threat Landscape, It Helps to Land on Your Feet: Tech Dive
Detected Hints/Tags/Attributes 111/2/37
Attributes
Details Type #Events CTI Value
Details Domain 1
app.rs
Details Domain 1
samba.rs
Details Domain 1
shutdown.rs
Details Domain 1
service.rs
Details Domain 1
config.rs
Details Domain 1
console.rs
Details Domain 1
psexec.rs
Details Domain 1
cluster.rs
Details Domain 1
discoverer.rs
Details Domain 1
safeboot.rs
Details Domain 1
user.rs
Details Domain 1
netbios.rs
Details Domain 1
process.rs
Details Domain 1
stack.rs
Details Domain 1
renderer.rs
Details Domain 1
env.rs
Details Domain 5
advintel.tech
Details Email 4
support@advintel.tech
Details File 21
locker.exe
Details File 1260
explorer.exe
Details File 533
ntdll.dll
Details File 1
rswmic.exe
Details File 1
desktop_note.rss
Details File 1
file_worker_pool.rss
Details File 1
ccmd.exe
Details File 23
'wevtutil.exe
Details File 95
wevtutil.exe
Details File 18
iisreset.exe
Details File 2
drag-and-drop-target.bat
Details MITRE ATT&CK Techniques 247
T1070
Details MITRE ATT&CK Techniques 92
T1070.001
Details MITRE ATT&CK Techniques 43
T1078.003
Details MITRE ATT&CK Techniques 298
T1562.001
Details MITRE ATT&CK Techniques 92
T1048
Details MITRE ATT&CK Techniques 19
T1048.002
Details MITRE ATT&CK Techniques 472
T1486
Details Windows Registry Key 17
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters