IoCs/Ransomware-ProLock.csv at master · sophoslabs/IoCs
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Powershell - T1059.001 Software - T1592.002 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | dff562cb-c0e3-4c08-b51a-39e5b6474bdf |
Fingerprint | 3616fc3b7c76320b |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Jan. 1, 2022, midnight |
Added to db | Sept. 11, 2022, 12:35 p.m. |
Last updated | Nov. 17, 2024, 6:50 p.m. |
Headline | UNKNOWN |
Title | IoCs/Ransomware-ProLock.csv at master · sophoslabs/IoCs |
Detected Hints/Tags/Attributes | 21/2/24 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://github.com/sophoslabs/IoCs/blob/master/Ransomware-ProLock.csv |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | File | 1 | ransomware-prolock.csv |
|
Details | File | 3 | c:\programdata\winmgr.bmp |
|
Details | File | 1 | c:\programdaa\winmgr.xml |
|
Details | File | 4 | c:\programdata\run.bat |
|
Details | File | 3 | c:\programdata\clean.bat |
|
Details | File | 15 | clean.bat |
|
Details | File | 26 | run.bat |
|
Details | File | 4 | winmgr.xml |
|
Details | File | 5 | winmgr.bmp |
|
Details | sha1 | 1 | 9cae5fcefc8bc9b748b4b16549e789e27ae816df |
|
Details | sha1 | 1 | a037439ad7e79dbf4a20664cf10126c93429e350 |
|
Details | sha1 | 1 | 0ce3614560e7c1ddbc3b8f56f3e45278de47d3bb |
|
Details | sha1 | 1 | 4f125d890a8f98c9c7069b0bb2b5625c7754fad6 |
|
Details | sha1 | 1 | e2a961c9a78d4c8bf118a0387dc15c564efc8fe9 |
|
Details | sha1 | 1 | 81d5888bb8d43d88315c040be1f51db6bb5cf64c |
|
Details | sha256 | 1 | 18661f8c245d26be1ec4df48a9e186569a77237f424f322f00ef94652b9d5f35 |
|
Details | sha256 | 1 | b262b1b82e5db337d367ea1d4119cadb928963896f1aff940be763a00d45f305 |
|
Details | sha256 | 1 | 2f0e4b178311a260601e054b0b405999715084227e49ff18a19e1a59f7b2f309 |
|
Details | sha256 | 1 | a6ded68af5a6e5cc8c1adee029347ec72da3b10a439d98f79f4b15801abd7af0 |
|
Details | sha256 | 1 | dfbd62a3d1b239601e17a5533e5cef53036647901f3fb72be76d92063e279178 |
|
Details | IPv4 | 1 | 185.212.128.8 |
|
Details | Url | 1 | http://185.212.128.8/b |
|
Details | Windows Registry Key | 2 | HKU\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet |
|
Details | Windows Registry Key | 164 | HKLM\SOFTWARE\Microsoft\Windows |