StopRansomware: RansomHub Ransomware
Essential information
- Published
- 30/08/2024 17:44
- Modified
- 30/08/2024 18:08
- Tags
- 2024-08-30 CVE-2017-0144 CVE-2020-0787 CVE-2020-1472 CVE-2023-22515 CVE-2023-27997 CVE-2023-3519 CVE-2023-46604 CVE-2023-46747 CVE-2023-48788 cobalt strike critical-infrastructure data exfiltration double-extortion encryption lateral movement metasploit mimikatz privilege-escalation ransomhub ransomware-as-a-service
- Related entities
- 9 vulnerabilities (cve), 14 observables, 1 intrusion sets (apt), 23 techniques (mitre), 4 malware, 11 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Vulnerabilities (CVE) (9)
Microsoft Windows BITS is vulnerable to to a privilege elevation vulnerability if it improperly handles symbolic links. An actor can exploit this …
- Published
- 28/01/2022
- Modified
- 21/12/2025
The SMBv1 server in multiple Microsoft Windows versions allows remote attackers to execute arbitrary code via crafted packets.
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 17/03/2017
- Modified
- 22/04/2026
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
- Attack vector
- Network
- Published
- 19/07/2023
- Modified
- 27/05/2026
Fortinet FortiOS and FortiProxy SSL-VPN contain a heap-based buffer overflow vulnerability which can allow an unauthenticated, remote attacker to execute code or …
- Attack vector
- Network
- Published
- 13/06/2023
- Modified
- 21/12/2025
Fortinet FortiClient EMS contains a SQL injection vulnerability that allows an unauthenticated attacker to execute commands as SYSTEM via specifically crafted requests.
- Attack vector
- Network
- Published
- 25/03/2024
- Modified
- 21/12/2025
Apache ActiveMQ contains a deserialization of untrusted data vulnerability that may allow a remote attacker with network access to a broker to …
- Attack vector
- Network
- Published
- 02/11/2023
- Modified
- 21/12/2025
F5 BIG-IP Configuration utility contains an authentication bypass using an alternate path or channel vulnerability due to undisclosed requests that may allow …
- Attack vector
- Network
- Published
- 31/10/2023
- Modified
- 21/12/2025
Atlassian Confluence Data Center and Server contains a broken access control vulnerability that allows an attacker to create unauthorized Confluence administrator accounts …
- Attack vector
- Network
- Published
- 05/10/2023
- Modified
- 21/12/2025
Microsoft's Netlogon Remote Protocol (MS-NRPC) contains a privilege escalation vulnerability when an attacker establishes a vulnerable Netlogon secure channel connection to a …
- Attack vector
- Local
- Published
- 03/11/2021
- Modified
- 27/05/2026
Observables (14)
89.23.96.2038.211.2.9745.95.67.41193.233.254.21193.124.125.78193.106.175.10745.135.232.2188.34.188.745.134.140.69i.ibb.com40031.co12301230.cosamuelelena.co[email protected]
Intrusion sets (APT) (1)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 04:35 · Modified 21/12/2025 04:35
Techniques (MITRE) (23)
-
T1110.003
-
Remote Desktop Protocol
-
Transfer Data to Cloud Account
-
Exfiltration Over Unencrypted Non-C2 Protocol
-
T1588.005
-
Inhibit System Recovery
-
Remote System Discovery
-
Create Account
-
PowerShell
-
Disable or Modify Tools
-
Data Encrypted for Impact
-
Indicator Removal
-
Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
-
Windows Management Instrumentation
-
Exploitation of Remote Services
-
Network Service Discovery
-
Remote Access Tools
-
Masquerading
-
Account Manipulation
-
Phishing
-
Exploit Public-Facing Application
-
Exploitation for Privilege Escalation
-
OS Credential Dumping
Malware (4)
-
FamilyPublished 03/02/2026 08:21 · Modified 03/02/2026 08:21
-
FamilyPublished 07/08/2025 18:57 · Modified 07/08/2025 18:57
-
FamilyPublished 11/05/2026 16:15 · Modified 11/05/2026 16:15
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
Others (11)
- Critical Manufacturing
- Commercial Facilities
- Food and Agriculture
- Emergency Services
- Water and Wastewater
- Communications
- Information Technology
- Financial Services
- Healthcare
- Transportation
- Government