Twelve: от первичного взлома до шифровальщиков и вайперов
Tags
Common Information
Type | Value |
---|---|
UUID | f783a9cc-1cfc-4cc3-a231-ce8415ddd862 |
Fingerprint | 5e9c2ee343b53c0b |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Aug. 14, 2024, 11:30 a.m. |
Added to db | Aug. 31, 2024, 8:17 a.m. |
Last updated | Nov. 17, 2024, 7:44 p.m. |
Headline | Возвращение группировки -=TWELVE=- |
Title | Twelve: от первичного взлома до шифровальщиков и вайперов |
Detected Hints/Tags/Attributes | 0/0/27 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://securelist.ru/twelve-group-unified-kill-chain/110128/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 224 | ✔ | Securelist | https://securelist.ru/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 52 | cve-2021-21972 |
|
Details | CVE | 26 | cve-2021-22005 |
|
Details | Domain | 4127 | github.com |
|
Details | Domain | 6 | libs.so |
|
Details | Domain | 117 | ld.so |
|
Details | Domain | 55 | process.name |
|
Details | Domain | 2 | dropmefiles.net |
|
Details | Domain | 2 | autorun.in |
|
Details | File | 2 | f6d098f417.php |
|
Details | File | 2 | 3425b29f4e.php |
|
Details | File | 2 | ecb2979be7.php |
|
Details | File | 2 | 04116e895b.php |
|
Details | File | 2 | 7784ba76e2.php |
|
Details | File | 2 | a4daa72a70.php |
|
Details | File | 2 | 5146d22914.php |
|
Details | File | 2 | 001d7a.php |
|
Details | File | 2 | 8759c7.php |
|
Details | File | 2 | 48a08b.php |
|
Details | File | 2 | 6f99ac.php |
|
Details | File | 2 | 82f5f4.php |
|
Details | File | 2 | 0dd37d.php |
|
Details | File | 2 | 6bceb2.php |
|
Details | File | 2 | d0af43.php |
|
Details | File | 3 | wso2.php |
|
Details | File | 20 | shell.jsp |
|
Details | File | 256 | net.exe |
|
Details | File | 2 | c:\windows\system32\tasks\run c:\windows\system32\tasks\update microsoft c:\windows\system32\tasks\yandex c:\windows\system32\tasks\yandexupdate c:\windows\sysvol_dfsr\domain\scripts\intel.exe |