StopRansomware: RansomHub Ransomware
Essential information
- Published
- 30/08/2024 17:44
- Modified
- 30/08/2024 18:08
- Tags
- 2024-08-30 CVE-2017-0144 CVE-2020-0787 CVE-2020-1472 CVE-2023-22515 CVE-2023-27997 CVE-2023-3519 CVE-2023-46604 CVE-2023-46747 CVE-2023-48788 cobalt strike critical-infrastructure data exfiltration double-extortion encryption lateral movement metasploit mimikatz privilege-escalation ransomhub ransomware-as-a-service
- Related entities
- 9 vulnerabilities (cve), 14 observables, 1 intrusion sets (apt), 23 techniques (mitre), 4 malware, 11 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (9)
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this …
- Published
- 28/01/2022
- Modified
- 21/12/2025
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 17/03/2017
- Modified
- 22/04/2026
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
- Attack vector
- Network
- Published
- 19/07/2023
- Modified
- 27/05/2026
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or …
- Attack vector
- Network
- Published
- 13/06/2023
- Modified
- 21/12/2025
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
- Attack vector
- Network
- Published
- 25/03/2024
- Modified
- 21/12/2025
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to …
- Attack vector
- Network
- Published
- 02/11/2023
- Modified
- 21/12/2025
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow …
- Attack vector
- Network
- Published
- 31/10/2023
- Modified
- 21/12/2025
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts …
- Attack vector
- Network
- Published
- 05/10/2023
- Modified
- 21/12/2025
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a …
- Attack vector
- Local
- Published
- 03/11/2021
- Modified
- 27/05/2026
Observables (14)
-
89.23.96.203 -
8.211.2.97 -
45.95.67.41 -
193.233.254.21 -
193.124.125.78 -
193.106.175.107 -
45.135.232.2 -
188.34.188.7 -
45.134.140.69 -
i.ibb.com -
40031.co -
12301230.co
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Techniques (MITRE) (23)
-
T1110.003 MITRE
-
Remote Desktop Protocol MITRE
-
Transfer Data to Cloud Account MITRE
-
Exfiltration Over Unencrypted Non-C2 Protocol MITRE
-
T1588.005 MITRE
-
Inhibit System Recovery MITRE
-
Remote System Discovery MITRE
-
Create Account MITRE
-
PowerShell MITRE
-
Disable or Modify Tools MITRE
-
Data Encrypted for Impact MITRE
-
Indicator Removal MITRE
Malware (4)
-
Family
-
Family
-
Family
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Others (11)
-
Critical Manufacturing
-
Commercial Facilities
-
Food and Agriculture
-
Emergency Services
-
Water and Wastewater
-
Communications
-
Information Technology
-
Financial Services
-
Healthcare
-
Transportation
-
Government