Trusted Design

Romanian Shellshock Backdoor

概要

This backdoor was discovered while digging through apache logs for shellshock exploitation attempts and inspecting the malicious payloads associated with them. This attack initially exploits CVE-2014-6271 (shellshock) to download a tar file on the system after which the contents of the tar file are extracted to the file system in the /tmp directory. After extracting the files to the file system xcron.sh is run, which looks for /lib/libpcprofile.so on the system and attempts to further exploit CVE-2013-2094 in order to elevate privileges to root. Upon successful exploitation of CVE-2013-2094 the software will install a root account on the system in addition to SSH keys which allows the attacker to remotely log in to the system as root. The attack originated out of an IP in Germany, however strings contained within the backdoor scripts suggest the software is of Romanian origin.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Gamaredon Group

Score: 6.77
Matched TTPs:
  • T1021.005 - VNC
  • T1027.015 - Compression
MITREへのリンク →

FIN7

Score: 10.68
Matched TTPs:
  • T1021.005 - VNC
  • T1210 - Exploitation of Remote Services
  • T1021.001 - Remote Desktop Protocol
  • T1078.003 - Local Accounts
MITREへのリンク →

GCMAN

Score: 3.62
Matched TTPs:
  • T1021.005 - VNC
MITREへのリンク →

Fox Kitten

Score: 12.12
Matched TTPs:
  • T1021.005 - VNC
  • T1505.003 - Web Shell
  • T1210 - Exploitation of Remote Services
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

APT41

Score: 11.60
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1059.004 - Unix Shell
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

Scattered Spider

Score: 14.24
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1059.004 - Unix Shell
  • T1578.002 - Create Cloud Instance
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

TA505

Score: 3.29
Matched TTPs:
  • T1069 - Permission Groups Discovery
MITREへのリンク →

Volt Typhoon

Score: 16.00
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1505.003 - Web Shell
  • T1059.004 - Unix Shell
  • T1614 - System Location Discovery
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

APT3

Score: 10.05
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1203 - Exploitation for Client Execution
  • T1036.010 - Masquerade Account Name
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

FIN13

Score: 9.04
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1505.003 - Web Shell
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

CURIUM

Score: 5.61
Matched TTPs:
  • T1505.003 - Web Shell
  • T1048.002 - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
MITREへのリンク →

Dragonfly

Score: 13.62
Matched TTPs:
  • T1505.003 - Web Shell
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
  • T1036.010 - Masquerade Account Name
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

APT28

Score: 16.32
Matched TTPs:
  • T1505.003 - Web Shell
  • T1048.002 - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

OilRig

Score: 4.91
Matched TTPs:
  • T1505.003 - Web Shell
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Agrius

Score: 3.41
Matched TTPs:
  • T1505.003 - Web Shell
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT39

Score: 3.41
Matched TTPs:
  • T1505.003 - Web Shell
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Mustang Panda

Score: 5.60
Matched TTPs:
  • T1505.003 - Web Shell
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
MITREへのリンク →

GALLIUM

Score: 5.05
Matched TTPs:
  • T1505.003 - Web Shell
  • T1036.003 - Rename Legitimate Utilities
MITREへのリンク →

Threat Group-3390

Score: 9.16
Matched TTPs:
  • T1505.003 - Web Shell
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
  • T1027.015 - Compression
MITREへのリンク →

Tropic Trooper

Score: 5.92
Matched TTPs:
  • T1505.003 - Web Shell
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Ember Bear

Score: 10.14
Matched TTPs:
  • T1505.003 - Web Shell
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
  • T1588.005 - Exploits
MITREへのリンク →

HAFNIUM

Score: 6.77
Matched TTPs:
  • T1505.003 - Web Shell
  • T1003.003 - NTDS
  • T1078.003 - Local Accounts
MITREへのリンク →

Sandworm Team

Score: 5.60
Matched TTPs:
  • T1505.003 - Web Shell
  • T1203 - Exploitation for Client Execution
  • T1003.003 - NTDS
MITREへのリンク →

Tonto Team

Score: 6.01
Matched TTPs:
  • T1505.003 - Web Shell
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT38

Score: 13.21
Matched TTPs:
  • T1505.003 - Web Shell
  • T1036.003 - Rename Legitimate Utilities
  • T1036.006 - Space after Filename
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT29

Score: 5.92
Matched TTPs:
  • T1505.003 - Web Shell
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Magic Hound

Score: 7.03
Matched TTPs:
  • T1505.003 - Web Shell
  • T1036.010 - Masquerade Account Name
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

BlackByte

Score: 3.41
Matched TTPs:
  • T1505.003 - Web Shell
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT5

Score: 3.41
Matched TTPs:
  • T1505.003 - Web Shell
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT32

Score: 9.21
Matched TTPs:
  • T1505.003 - Web Shell
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Medusa Group

Score: 13.91
Matched TTPs:
  • T1505.003 - Web Shell
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
  • T1529 - System Shutdown/Reboot
  • T1218.014 - MMC
MITREへのリンク →

Leviathan

Score: 8.06
Matched TTPs:
  • T1505.003 - Web Shell
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
  • T1027.015 - Compression
MITREへのリンク →

Sea Turtle

Score: 8.76
Matched TTPs:
  • T1505.003 - Web Shell
  • T1059.004 - Unix Shell
  • T1203 - Exploitation for Client Execution
  • T1078.003 - Local Accounts
MITREへのリンク →

Kimsuky

Score: 10.21
Matched TTPs:
  • T1505.003 - Web Shell
  • T1021.001 - Remote Desktop Protocol
  • T1588.005 - Exploits
  • T1078.003 - Local Accounts
MITREへのリンク →

Storm-1811

Score: 7.47
Matched TTPs:
  • T1048.002 - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
  • T1036.010 - Masquerade Account Name
MITREへのリンク →

Wizard Spider

Score: 6.73
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

menuPass

Score: 10.02
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1036.003 - Rename Legitimate Utilities
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

MuddyWater

Score: 4.24
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Aquatic Panda

Score: 4.48
Matched TTPs:
  • T1059.004 - Unix Shell
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Velvet Ant

Score: 9.63
Matched TTPs:
  • T1059.004 - Unix Shell
  • T1078.003 - Local Accounts
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

UNC3886

Score: 4.33
Matched TTPs:
  • T1059.004 - Unix Shell
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

Lazarus Group

Score: 10.05
Matched TTPs:
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Daggerfly

Score: 3.29
Matched TTPs:
  • T1036.003 - Rename Legitimate Utilities
MITREへのリンク →

Patchwork

Score: 3.14
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Axiom

Score: 3.14
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Higaisa

Score: 4.65
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1027.015 - Compression
MITREへのリンク →

Cobalt Group

Score: 3.14
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT37

Score: 5.12
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

SideCopy

Score: 4.13
Matched TTPs:
  • T1614 - System Location Discovery
MITREへのリンク →

LAPSUS$

Score: 6.47
Matched TTPs:
  • T1578.002 - Create Cloud Instance
  • T1003.003 - NTDS
MITREへのリンク →

FIN6

Score: 3.99
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

FIN10

Score: 4.31
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1078.003 - Local Accounts
MITREへのリンク →

Chimera

Score: 3.99
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1003.003 - NTDS
MITREへのリンク →

Molerats

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

TA2541

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.81
Matched TTPs:
  • T1211 - Exploitation for Defense Evasion
  • T1048.002 - Exfiltration Over Asymmetric Encrypted Non-C2 Protocol
  • T1210 - Exploitation of Remote Services
  • T1003.003 - NTDS
  • T1203 - Exploitation for Client Execution
  • T1505.003 - Web Shell
MITREへのリンク →

Volt Typhoon

Score: 0.77
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1069 - Permission Groups Discovery
  • T1614 - System Location Discovery
  • T1059.004 - Unix Shell
  • T1003.003 - NTDS
  • T1505.003 - Web Shell
MITREへのリンク →

Medusa Group

Score: 0.69
Matched TTPs:
  • T1529 - System Shutdown/Reboot
  • T1021.001 - Remote Desktop Protocol
  • T1218.014 - MMC
  • T1003.003 - NTDS
  • T1505.003 - Web Shell
MITREへのリンク →

Scattered Spider

Score: 0.68
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1069 - Permission Groups Discovery
  • T1578.002 - Create Cloud Instance
  • T1003.003 - NTDS
  • T1059.004 - Unix Shell
MITREへのリンク →

Dragonfly

Score: 0.67
Matched TTPs:
  • T1036.010 - Masquerade Account Name
  • T1021.001 - Remote Desktop Protocol
  • T1210 - Exploitation of Remote Services
  • T1003.003 - NTDS
  • T1203 - Exploitation for Client Execution
  • T1505.003 - Web Shell
MITREへのリンク →

APT38

Score: 0.66
Matched TTPs:
  • T1529 - System Shutdown/Reboot
  • T1036.006 - Space after Filename
  • T1036.003 - Rename Legitimate Utilities
  • T1505.003 - Web Shell
MITREへのリンク →

Fox Kitten

Score: 0.62
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1021.005 - VNC
  • T1210 - Exploitation of Remote Services
  • T1003.003 - NTDS
  • T1505.003 - Web Shell
MITREへのリンク →

APT41

Score: 0.60
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1069 - Permission Groups Discovery
  • T1003.003 - NTDS
  • T1059.004 - Unix Shell
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

FIN7

Score: 0.57
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1210 - Exploitation of Remote Services
  • T1021.005 - VNC
  • T1078.003 - Local Accounts
MITREへのリンク →

Related CVEs

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る