d.uijn.nl - Shortcuts another neat phishing trick
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Phishing - T1660 Phishing - T1566 Powershell - T1059.001 Tool - T1588.002 Connection Proxy - T1090 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | d0b44b71-2f5b-47c8-a425-5f58a78ebafb |
Fingerprint | acc18d6a21af7fe0 |
Analysis status | DONE |
Considered CTI value | 1 |
Text language | |
Published | Dec. 28, 2016, midnight |
Added to db | Feb. 17, 2023, 9:22 p.m. |
Last updated | Nov. 18, 2024, 1:38 a.m. |
Headline | |
Title | d.uijn.nl - Shortcuts another neat phishing trick |
Detected Hints/Tags/Attributes | 28/2/11 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://d.uijn.nl/2016/12/28/shortcuts-another-neat-phishing-trick/ |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 339 | system.net |
|
Details | Domain | 61 | system.windows |
|
Details | Domain | 7 | unicorn.py |
|
Details | File | 2127 | cmd.exe |
|
Details | File | 1209 | powershell.exe |
|
Details | File | 748 | kernel32.dll |
|
Details | File | 80 | msvcrt.dll |
|
Details | File | 7 | unicorn.py |
|
Details | IPv4 | 1 | 192.168.255.170 |
|
Details | Threat Actor Identifier - APT | 258 | APT34 |
|
Details | Url | 1 | http://192.168.255.170/script |