BugWare
Tags
attack-pattern: Data Software - T1592.002
Common Information
Type Value
UUID a71aa6ab-7396-44de-af60-92601b0689f7
Fingerprint b2b5387f427c436a
Analysis status DONE
Considered CTI value 0
Text language
Published Oct. 10, 2017, 6:10 a.m.
Added to db Jan. 18, 2023, 7:53 p.m.
Last updated Nov. 17, 2024, 5:57 p.m.
Headline Шифровальщики-вымогатели The Digest "Crypto-Ransomware"
Title BugWare
Detected Hints/Tags/Attributes 15/1/29
Attributes
Details Type #Events CTI Value
Details Domain 12
secmail.pro
Details Domain 3
foxbit.com.br
Details Domain 10
poloniex.com
Details Domain 768
www.youtube.com
Details Domain 1
dedamento-vendas.xyz
Details Domain 1
getrichordietryin.xyz
Details Domain 1373
twitter.com
Details Email 1
slavic@secmail.pro
Details Email 1
maxvision@secmail.pro
Details File 1
doc_2017100200000-15.pdf
Details File 95
pdf.exe
Details File 1
bugware.exe
Details File 1
bugware.bmp
Details File 1
wpp.bmp
Details File 1
lista.log
Details File 1
%appdata%\lista.log
Details File 1
boleto-atualizado-7853.docx
Details File 1
boleto-atualizado-7852.exe
Details Url 1
https://foxbit.com.br
Details Url 2
https://poloniex.com
Details Url 1
https://www.youtube.com/watch?v=znwl63g66ei
Details Url 1
https://www.youtube.com/watch?v=puuxe68d_ek
Details Url 1
https://twitter.com/malwrhunterteam/status/918403062993182720
Details Windows Registry Key 1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BUGWARE
Details Windows Registry Key 1
HKCU\SOFTWARE\BUGWARE\Arquivos
Details Windows Registry Key 1
HKCU\SOFTWARE\BUGWARE\Chavepriv8
Details Windows Registry Key 1
HKCU\SOFTWARE\BUGWARE\Enviado
Details Windows Registry Key 1
HKCU\SOFTWARE\BUGWARE\ID
Details Windows Registry Key 1
HKCU\SOFTWARE\BUGWARE\prazo