MOVEit Transfer CVE-2023-34362 Deep Dive and Indicators of Compromise
Tags
attack-pattern: | Data Credentials - T1589.001 Email Addresses - T1589.002 Python - T1059.006 Server - T1583.004 Server - T1584.004 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | 9d51556a-35eb-4fa6-8502-5bd26ae602a8 |
Fingerprint | ac092cc16e6d332d |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | June 9, 2023, 1:48 p.m. |
Added to db | June 12, 2023, 1:32 p.m. |
Last updated | Nov. 18, 2024, 1:24 p.m. |
Headline | MOVEit Transfer CVE-2023-34362 Deep Dive and Indicators of Compromise |
Title | MOVEit Transfer CVE-2023-34362 Deep Dive and Indicators of Compromise |
Detected Hints/Tags/Attributes | 42/1/14 |
Source URLs
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 316 | ✔ | Horizon3.ai | https://www.horizon3.ai/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 244 | cve-2023-34362 |
|
Details | Domain | 32 | ysoserial.net |
|
Details | File | 17 | guestaccess.aspx |
|
Details | File | 5 | machine2.aspx |
|
Details | File | 13 | moveitisapi.dll |
|
Details | File | 1 | msgengine.msg |
|
Details | File | 13 | ysoserial.exe |
|
Details | File | 2130 | cmd.exe |
|
Details | File | 3 | c:\windows\temp\message.txt |
|
Details | File | 1 | c:\moveitdmz_install.ini |
|
Details | File | 1 | moveitdmz_install.ini |
|
Details | File | 1 | dmz_webapi.log |
|
Details | File | 1 | dmz_web.log |
|
Details | File | 1 | dmz_isapi.log |