Blinded by Silence
Common Information
Type Value
UUID a46601e5-1cd2-4e64-b5d0-900c302fa3fc
Fingerprint 9f144917d1e48c95
Analysis status DONE
Considered CTI value 2
Text language
Published Nov. 14, 2024, 1:02 p.m.
Added to db Nov. 14, 2024, 9:58 p.m.
Last updated Nov. 17, 2024, 6:56 p.m.
Headline Blinded by Silence
Title Blinded by Silence
Detected Hints/Tags/Attributes 68/1/39
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 226 Security Boulevard https://securityboulevard.com/feed 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details Domain 1
here.channel
Details Domain 1
blog.snapattack.com
Details File 198
msmpeng.exe
Details File 6
edrsilencer.exe
Details File 1
userslocaluserdesktopedrsilencer.exe
Details File 7
windowssystem32cmd.exe
Details File 1
windowssystem32ntdll.dll
Details File 1
windowssystem32kernelbase.dll
Details File 1
userslocaluseredrsandblast.exe
Details File 2
windowssystem32kernel32.dll
Details File 1
edrsandblast.exe
Details File 1
11-0msmpeng.exe
Details File 7
windowssystem32svchost.exe
Details File 478
lsass.exe
Details File 1
c:\users\localuser\desktop\edrsilencer.exe
Details File 409
c:\windows\system32\cmd.exe
Details File 36
c:\windows\system32\ntdll.dll
Details File 20
c:\windows\system32\kernelbase.dll
Details File 1
c:\users\localuser\edrsandblast.exe
Details File 23
c:\windows\system32\kernel32.dll
Details File 1
c:\users\localuser\ sourceimage: c:\users\localuser\edrsandblast.exe
Details File 92
c:\windows\system32\svchost.exe
Details File 1
c:\users\localuser\gdrv.sys
Details File 1
blackout.sys
Details File 1
c:\users\public\blackout.sys
Details File 23
c:\windows\system32\services.exe
Details File 306
services.exe
Details File 10
procexp.sys
Details File 7
procexp152.sys
Details File 1
c:\windows\system32\ausophos.exe
Details MITRE ATT&CK Techniques 298
T1562.001
Details MITRE ATT&CK Techniques 70
T1562.004
Details MITRE ATT&CK Techniques 78
T1569
Details MITRE ATT&CK Techniques 550
T1112
Details Url 1
https://blog.snapattack.com/blinded-by-silence-61fea220fe64?source=rss
Details Windows Registry Key 1
HKLMSystemCurrentControlSetServicesSharedAccessParametersFirewallPolicyFirewallRules
Details Windows Registry Key 2
HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules
Details Windows Registry Key 1
HKLM\System\CurrentControlSet\Services\NimBlackout\ImagePath
Details Windows Registry Key 1
HKLM\System\CurrentControlSet\Services\wuauserv\Start