-
Notifications
You must be signed in to change notification settings - Fork 114
Files
/
Copy pathRansomware-REvil-Kaseya.csv
51 lines (51 loc) · 1.71 KB
/
Ransomware-REvil-Kaseya.csv
1 | Indicator_type | Data | Note |
---|---|---|---|
2 | file_path_name | C:\windows\cert.exe | Copied CERTUTIL |
3 | file_path_name | C:\windows\msmpeng.exe | Outdated Defender executable vulnerable to DLL sideload |
4 | sha256 | 33bc14d231a4afaa18f06513766d5f69d8b88f1e697cd127d24fb4b72ad44c7a | Outdated Defender executable vulnerable to DLL sideload |
5 | file_path_name | C:\kworking\agent.crt | Revil dropper used in Kaseya exploit |
6 | sha256 | d55f983c994caa160ec63a59f6b4250fe67fb3e8c43a388aec60a4a6978e9f1 | Revil dropper used in Kaseya exploit |
7 | file_path_name | C:\windows\mpsvc.dll | Revil ransomware DLL |
8 | sha256 | 8dd620d9aeb35960bb766458c8890ede987c33d239cf730f93fe49d90ae759dd | Revil ransomware DLL |
9 | domain | ncuccr.org | |
10 | domain | 1team.es | |
11 | domain | 4net.guru | |
12 | domain | 35-40konkatsu.net | |
13 | domain | 123vrachi.ru | |
14 | domain | 4youbeautysalon.com | |
15 | domain | 12starhd.online | |
16 | domain | 101gowrie.com | |
17 | domain | 8449nohate.org | |
18 | domain | 1kbk.com.ua | |
19 | domain | 365questions.org | |
20 | domain | 321play.com.hk | |
21 | domain | candyhouseusa.com | |
22 | domain | andersongilmour.co.uk | |
23 | domain | facettenreich27.de | |
24 | domain | blgr.be | |
25 | domain | fannmedias.com | |
26 | domain | southeasternacademyofprosthodontics.org | |
27 | domain | filmstreamingvfcomplet.be | |
28 | domain | smartypractice.com | |
29 | domain | tanzschule-kieber.de | |
30 | domain | iqbalscientific.com | |
31 | domain | pasvenska.se | |
32 | domain | cursosgratuitosnainternet.com | |
33 | domain | bierensgebakkramen.nl | |
34 | domain | c2e-poitiers.com | |
35 | domain | gonzalezfornes.es | |
36 | domain | tonelektro.nl | |
37 | domain | milestoneshows.com | |
38 | domain | blossombeyond50.com | |
39 | domain | thomasvicino.com | |
40 | domain | kaotikkustomz.com | |
41 | domain | mindpackstudios.com | |
42 | domain | faroairporttransfers.net | |
43 | domain | daklesa.de | |
44 | domain | bxdf.info | |
45 | domain | simoneblum.de | |
46 | domain | gmto.fr | |
47 | domain | cerebralforce.net | |
48 | domain | myhostcloud.com | |
49 | domain | fotoscondron.com | |
50 | domain | sw1m.ru | |
51 | domain | homng.net |