“Rogue RDP” Attack Detection: UAC-0215 Leverages RDP Configuration Files to Gain Remote Access to Ukrainian Public Sector Computers - SOC Prime
Common Information
Type Value
UUID 628d5295-e4f3-4e96-aad5-5535882e33ff
Fingerprint f41009db0ea5bfe7
Analysis status DONE
Considered CTI value 2
Text language
Published Oct. 24, 2024, 10:04 a.m.
Added to db Oct. 24, 2024, 1:01 p.m.
Last updated Nov. 17, 2024, 6:54 p.m.
Headline “Rogue RDP” Attack Detection: UAC-0215 Leverages RDP Configuration Files to Gain Remote Access to Ukrainian Public Sector Computers
Title “Rogue RDP” Attack Detection: UAC-0215 Leverages RDP Configuration Files to Gain Remote Access to Ukrainian Public Sector Computers - SOC Prime
Detected Hints/Tags/Attributes 41/3/4
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 237 SOC Prime https://socprime.com/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CERT Ukraine 13
UAC-0215
Details CERT Ukraine 40
UAC-0050
Details CERT Ukraine 29
UAC-0006
Details File 74
mstsc.exe