Twelve: от первичного взлома до шифровальщиков и вайперов
Tags
Common Information
Type Value
UUID f783a9cc-1cfc-4cc3-a231-ce8415ddd862
Fingerprint 5e9c2ee343b53c0b
Analysis status DONE
Considered CTI value 0
Text language
Published Aug. 14, 2024, 11:30 a.m.
Added to db Aug. 31, 2024, 8:17 a.m.
Last updated Nov. 17, 2024, 7:44 p.m.
Headline Возвращение группировки -=TWELVE=-
Title Twelve: от первичного взлома до шифровальщиков и вайперов
Detected Hints/Tags/Attributes 0/0/27
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 224 Securelist https://securelist.ru/feed/ 2024-08-30 22:08
Attributes
Details Type #Events CTI Value
Details CVE 52
cve-2021-21972
Details CVE 26
cve-2021-22005
Details Domain 4127
github.com
Details Domain 6
libs.so
Details Domain 117
ld.so
Details Domain 55
process.name
Details Domain 2
dropmefiles.net
Details Domain 2
autorun.in
Details File 2
f6d098f417.php
Details File 2
3425b29f4e.php
Details File 2
ecb2979be7.php
Details File 2
04116e895b.php
Details File 2
7784ba76e2.php
Details File 2
a4daa72a70.php
Details File 2
5146d22914.php
Details File 2
001d7a.php
Details File 2
8759c7.php
Details File 2
48a08b.php
Details File 2
6f99ac.php
Details File 2
82f5f4.php
Details File 2
0dd37d.php
Details File 2
6bceb2.php
Details File 2
d0af43.php
Details File 3
wso2.php
Details File 20
shell.jsp
Details File 256
net.exe
Details File 2
c:\windows\system32\tasks\run c:\windows\system32\tasks\update microsoft c:\windows\system32\tasks\yandex c:\windows\system32\tasks\yandexupdate c:\windows\sysvol_dfsr\domain\scripts\intel.exe