Miner Uses WMI and EternalBlue To Spread Filelessly
Common Information
Type Value
UUID ff6760be-41f4-4f9f-a511-9adefbe049bc
Fingerprint 8425098d0d37ee8f
Analysis status DONE
Considered CTI value 0
Text language
Published Aug. 21, 2017, midnight
Added to db Jan. 18, 2023, 9:02 p.m.
Last updated Nov. 17, 2024, 6:54 p.m.
Headline Miner Uses WMI and EternalBlue To Spread Filelessly
Title Miner Uses WMI and EternalBlue To Spread Filelessly
Detected Hints/Tags/Attributes 51/2/8
Attributes
Details Type #Events CTI Value
Details Domain 1
wmi.mykings.top
Details Domain 1
32.zip
Details Domain 4
activescripteventconsumer.name
Details File 23
scrcons.exe
Details File 1
32.zip
Details IPv4 1
67.21.90.226
Details Url 1
http://wmi.mykings.top:8888/test.html
Details Url 1
http://67.21.90.226:8888/32.zip