UmbreCrypt
Tags
attack-pattern: Software - T1592.002
Common Information
Type Value
UUID a27435be-0150-4c93-8c25-0119c2330264
Fingerprint 2ec68a7fd747b15b
Analysis status DONE
Considered CTI value 0
Text language
Published Feb. 10, 2016, 9:58 p.m.
Added to db Sept. 26, 2022, 9:32 a.m.
Last updated Nov. 12, 2024, 7:42 p.m.
Headline Шифровальщики-вымогатели The Digest "Crypto-Ransomware"
Title UmbreCrypt
Detected Hints/Tags/Attributes 22/1/18
Attributes
Details Type #Events CTI Value
Details Domain 7
engineer.com
Details Domain 5
consultant.com
Details Email 2
umbredecrypt@engineer.com
Details Email 2
umbrehelp@consultant.com
Details File 1
default32643264.bmp
Details File 1
default432643264.jpg
Details File 4
chrysanthemum.jpg
Details File 131
tar.gz
Details File 1
%appdata%\chromesetings3264\default32643264.bmp
Details File 1
%appdata%\chromesetings3264\default432643264.jpg
Details File 1
path_to_installer.exe
Details File 1
%appdata%\chromesetings3264\wosybiny.exe
Details Windows Registry Key 2
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft
Details Windows Registry Key 1
HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ChromeSettingsStart3264
Details Windows Registry Key 1
HKCU\Software\Microsoft\Windows\ChromeRandomAdress3264
Details Windows Registry Key 1
HKCU\Software\Microsoft\Windows\ChromeSettiings3264
Details Windows Registry Key 1
HKCU\Software\Microsoft\Windows\ChromeStarts3264
Details Windows Registry Key 1
HKCU\Software\Microsoft\Windows\TRUECRT3264