Beware of the Shadowbunny - Using virtual machines to persist and evade detections · Embrace The Red
Common Information
Type Value
UUID e2d5aaf9-caf1-4cfd-8c82-336c41b29abb
Fingerprint 3427991859a340a1
Analysis status DONE
Considered CTI value 0
Text language
Published Sept. 23, 2020, 8 p.m.
Added to db Sept. 26, 2022, 9:31 a.m.
Last updated Nov. 16, 2024, 6:06 p.m.
Headline Embrace The Red
Title Beware of the Shadowbunny - Using virtual machines to persist and evade detections · Embrace The Red
Detected Hints/Tags/Attributes 92/2/21
Attributes
Details Type #Events CTI Value
Details Domain 3
download.virtualbox.org
Details Domain 3
vboxlinuxadditions.run
Details Domain 28
docs.oracle.com
Details Domain 24
www.virtualbox.org
Details Domain 1
www.asciiart.eu
Details File 1
8.iso
Details File 1
8-137981-win.exe
Details File 1
14-133895-win.exe
Details File 1
installation_windows.html
Details File 2
vboxmanage.exe
Details File 1
ch08.html
Details File 1
c:\users\wuzzi\virtualbox vms\it recovery\it recovery.vb
Details File 1
%userprofile%\virtualbox vms\it recovery\it recovery.vb
Details File 1
config.bat
Details File 2
c:\program files\oracle\virtualbox\vboxmanage.exe
Details IPv4 38
10.10.10.10
Details Url 1
https://download.virtualbox.org/virtualbox/6.1.8/vboxguestadditions_6.1.8.iso
Details Url 1
https://download.virtualbox.org/virtualbox/6.1.8/virtualbox-6.1.8-137981-win.exe
Details Url 1
https://docs.oracle.com/en/virtualization/virtualbox/6.0/user/installation_windows.html
Details Url 1
https://www.virtualbox.org/manual/ch08.html
Details Url 1
https://www.asciiart.eu/animals/rabbits