Tracking the Operators of the Newly Emerged BlueSky Ransomware | Threat Intelligence | CloudSEK
Common Information
Type Value
UUID 6ed472bf-45bd-4faf-813a-c768c5a3193b
Fingerprint 9772e0df0e7096c1
Analysis status DONE
Considered CTI value 2
Text language
Published July 14, 2022, midnight
Added to db Aug. 31, 2024, 2:14 a.m.
Last updated Nov. 17, 2024, 5:55 p.m.
Headline Tracking the Operators of the Newly Emerged BlueSky Ransomware
Title Tracking the Operators of the Newly Emerged BlueSky Ransomware | Threat Intelligence | CloudSEK
Detected Hints/Tags/Attributes 48/3/19
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 89 CloudSEK Threat Intelligence https://cloudsek.com/threatintelligence/rss.xml 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CVE 19
cve-2022-21882
Details CVE 63
cve-2020-0796
Details Domain 4
kmsauto.us
Details Domain 59
torproject.org
Details Domain 2
ccpyeuptrlatb2piua4ukhnhi7lrxgerrcrj4p2b5uhbzqm2xgdjaqid.onion
Details File 44
javaw.exe
Details File 9
2.ps1
Details File 19
l.exe
Details md5 2
d8a44d2ed34b5fee7c8e24d998f805d9
Details sha1 2
d8369cb0d8ccec95b2a49ba34aa7749b60998661
Details sha256 2
3e035f2d7d30869ce53171ef5a0f761bfb9c14d94d9fe6da385e20b8d96dc2fb
Details Url 1
https://kmsauto.us/someone.
Details Url 3
https://kmsauto.us/v-mire
Details Url 2
https://kmsauto.us/kriminal
Details Url 2
https://kmsauto.us/religiya
Details Url 3
https://kmsauto.us/ekonomika
Details Url 2
https://kmsauto.us/someone/l.exe
Details Url 27
https://torproject.org
Details Url 1
http://ccpyeuptrlatb2piua4ukhnhi7lrxgerrcrj4p2b5uhbzqm2xgdjaqid.onion