Tales From the Incident Response Cliff Face – Case Study 2
Common Information
Type Value
UUID 80ef5ad7-9aa2-4888-b7d4-6293ade711f0
Fingerprint a54919972c322685
Analysis status DONE
Considered CTI value 2
Text language
Published Dec. 6, 2023, 12:02 p.m.
Added to db Aug. 31, 2024, 5:10 a.m.
Last updated Nov. 17, 2024, 7:44 p.m.
Headline Tales From the Incident Response Cliff Face – Case Study 2
Title Tales From the Incident Response Cliff Face – Case Study 2
Detected Hints/Tags/Attributes 80/1/25
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 205 Kudelski Security Research https://research.kudelskisecurity.com/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CVE 168
cve-2021-34473
Details CVE 142
cve-2021-34523
Details CVE 143
cve-2021-31207
Details CVE 184
cve-2021-26855
Details CVE 126
cve-2021-27065
Details CVE 105
cve-2022-41040
Details CVE 127
cve-2022-41082
Details Domain 5
www.scip.ch
Details Domain 4127
github.com
Details Domain 13
www.giac.org
Details Domain 1
mega.co
Details Domain 2
www.kelacyber.com
Details File 2
ntoskrnl.dll
Details File 125
ntoskrnl.exe
Details File 1
loot.dll
Details File 1
authbas.dll
Details File 45
mpr.dll
Details File 4
mpnotify.exe
Details Github username 4
gtworek
Details IPv4 1
103.112.232.44
Details Microsoft Patch Numbers 4
KB5009543
Details Url 1
https://www.scip.ch/en/?labs.20220217
Details Url 1
https://github.com/gtworek/psbits/tree/master/passwordstealing/nppspy
Details Url 1
https://www.giac.org/paper/gcih/117/microsoft-network-provider-exploit/101145
Details Url 1
https://www.kelacyber.com/the-secret-life-of-an-initial-access-broker