Blinded by Silence
Tags
Common Information
Type | Value |
---|---|
UUID | a46601e5-1cd2-4e64-b5d0-900c302fa3fc |
Fingerprint | 9f144917d1e48c95 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Nov. 14, 2024, 1:02 p.m. |
Added to db | Nov. 14, 2024, 9:58 p.m. |
Last updated | Nov. 17, 2024, 6:56 p.m. |
Headline | Blinded by Silence |
Title | Blinded by Silence |
Detected Hints/Tags/Attributes | 68/1/39 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://securityboulevard.com/2024/11/blinded-by-silence/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 226 | ✔ | Security Boulevard | https://securityboulevard.com/feed | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | here.channel |
|
Details | Domain | 1 | blog.snapattack.com |
|
Details | File | 198 | msmpeng.exe |
|
Details | File | 6 | edrsilencer.exe |
|
Details | File | 1 | userslocaluserdesktopedrsilencer.exe |
|
Details | File | 7 | windowssystem32cmd.exe |
|
Details | File | 1 | windowssystem32ntdll.dll |
|
Details | File | 1 | windowssystem32kernelbase.dll |
|
Details | File | 1 | userslocaluseredrsandblast.exe |
|
Details | File | 2 | windowssystem32kernel32.dll |
|
Details | File | 1 | edrsandblast.exe |
|
Details | File | 1 | 11-0msmpeng.exe |
|
Details | File | 7 | windowssystem32svchost.exe |
|
Details | File | 478 | lsass.exe |
|
Details | File | 1 | c:\users\localuser\desktop\edrsilencer.exe |
|
Details | File | 409 | c:\windows\system32\cmd.exe |
|
Details | File | 36 | c:\windows\system32\ntdll.dll |
|
Details | File | 20 | c:\windows\system32\kernelbase.dll |
|
Details | File | 1 | c:\users\localuser\edrsandblast.exe |
|
Details | File | 23 | c:\windows\system32\kernel32.dll |
|
Details | File | 1 | c:\users\localuser\ sourceimage: c:\users\localuser\edrsandblast.exe |
|
Details | File | 92 | c:\windows\system32\svchost.exe |
|
Details | File | 1 | c:\users\localuser\gdrv.sys |
|
Details | File | 1 | blackout.sys |
|
Details | File | 1 | c:\users\public\blackout.sys |
|
Details | File | 23 | c:\windows\system32\services.exe |
|
Details | File | 306 | services.exe |
|
Details | File | 10 | procexp.sys |
|
Details | File | 7 | procexp152.sys |
|
Details | File | 1 | c:\windows\system32\ausophos.exe |
|
Details | MITRE ATT&CK Techniques | 298 | T1562.001 |
|
Details | MITRE ATT&CK Techniques | 70 | T1562.004 |
|
Details | MITRE ATT&CK Techniques | 78 | T1569 |
|
Details | MITRE ATT&CK Techniques | 550 | T1112 |
|
Details | Url | 1 | https://blog.snapattack.com/blinded-by-silence-61fea220fe64?source=rss |
|
Details | Windows Registry Key | 1 | HKLMSystemCurrentControlSetServicesSharedAccessParametersFirewallPolicyFirewallRules |
|
Details | Windows Registry Key | 2 | HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules |
|
Details | Windows Registry Key | 1 | HKLM\System\CurrentControlSet\Services\NimBlackout\ImagePath |
|
Details | Windows Registry Key | 1 | HKLM\System\CurrentControlSet\Services\wuauserv\Start |