Trusted Design

Digging for groundhogs: holes in your linux server

概要

In July 2015, Check Point’s Incident Response team was contacted by a customer after they noticed strange file system activities in one of their Linux-based DNS BIND servers. This strange behavior consisted of a large amount of peculiar files being written into sensitive system directories. A thorough analysis of the infected system by our Incident Response and Malware Research teams quickly revealed that the server was indeed compromised. The source of this compromise was traced to an SSH brute force attack that took place earlier the same month. The attacking IP addresses originated from very distinctive network ranges mostly associated with Chinese Internet service providers. Using this SSH brute-forcing network, it took the attackers only a few days to gain root access and full control of the targeted server. Once they obtained access to the server, the attackers infected the system with two malicious payloads.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Magic Hound

Score: 11.29
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1114 - Email Collection
  • T1102.002 - Bidirectional Communication
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

HEXANE

Score: 9.64
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1608.001 - Upload Malware
  • T1110 - Brute Force
  • T1102.002 - Bidirectional Communication
MITREへのリンク →

APT29

Score: 13.65
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1550.003 - Pass the Ticket
  • T1562.008 - Disable or Modify Cloud Logs
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Gamaredon Group

Score: 17.15
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1608.001 - Upload Malware
  • T1480 - Execution Guardrails
  • T1039 - Data from Network Shared Drive
  • T1102.002 - Bidirectional Communication
  • T1027.015 - Compression
MITREへのリンク →

TA2541

Score: 7.87
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1608.001 - Upload Malware
  • T1027.015 - Compression
MITREへのリンク →

FIN13

Score: 6.59
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1087 - Account Discovery
MITREへのリンク →

Turla

Score: 10.50
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1110 - Brute Force
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
MITREへのリンク →

Volt Typhoon

Score: 5.58
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1584.004 - Server
MITREへのリンク →

Ember Bear

Score: 6.14
Matched TTPs:
  • T1114 - Email Collection
  • T1110 - Brute Force
MITREへのリンク →

Silent Librarian

Score: 3.62
Matched TTPs:
  • T1114 - Email Collection
MITREへのリンク →

Scattered Spider

Score: 12.00
Matched TTPs:
  • T1114 - Email Collection
  • T1087 - Account Discovery
  • T1538 - Cloud Service Dashboard
MITREへのリンク →

Sandworm Team

Score: 11.74
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1499 - Endpoint Denial of Service
  • T1584.004 - Server
MITREへのリンク →

Earth Lusca

Score: 4.81
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1584.004 - Server
MITREへのリンク →

Mustang Panda

Score: 10.64
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1678 - Delay Execution
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Kimsuky

Score: 7.66
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Mustard Tempest

Score: 6.51
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1608.006 - SEO Poisoning
MITREへのリンク →

OilRig

Score: 7.02
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1110 - Brute Force
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Threat Group-3390

Score: 5.12
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1027.015 - Compression
MITREへのリンク →

BlackByte

Score: 8.22
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1480 - Execution Guardrails
  • T1569.002 - Service Execution
MITREへのリンク →

APT32

Score: 8.22
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1550.003 - Pass the Ticket
  • T1569.002 - Service Execution
MITREへのリンク →

Moonstone Sleet

Score: 6.89
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 8.34
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1480 - Execution Guardrails
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

FIN7

Score: 6.77
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1102.002 - Bidirectional Communication
  • T1569.002 - Service Execution
MITREへのリンク →

EXOTIC LILY

Score: 4.50
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Aquatic Panda

Score: 3.84
Matched TTPs:
  • T1087 - Account Discovery
MITREへのリンク →

BRONZE BUTLER

Score: 10.16
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1039 - Data from Network Shared Drive
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Fox Kitten

Score: 5.56
Matched TTPs:
  • T1110 - Brute Force
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

APT41

Score: 8.21
Matched TTPs:
  • T1110 - Brute Force
  • T1569.002 - Service Execution
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

APT38

Score: 8.54
Matched TTPs:
  • T1110 - Brute Force
  • T1569.002 - Service Execution
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT39

Score: 7.32
Matched TTPs:
  • T1110 - Brute Force
  • T1102.002 - Bidirectional Communication
  • T1569.002 - Service Execution
MITREへのリンク →

Dragonfly

Score: 5.36
Matched TTPs:
  • T1110 - Brute Force
  • T1584.004 - Server
MITREへのリンク →

Storm-0501

Score: 6.37
Matched TTPs:
  • T1110 - Brute Force
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

APT28

Score: 17.03
Matched TTPs:
  • T1110 - Brute Force
  • T1039 - Data from Network Shared Drive
  • T1102.002 - Bidirectional Communication
  • T1498 - Network Denial of Service
  • T1669 - Wi-Fi Networks
MITREへのリンク →

RedCurl

Score: 6.88
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1537 - Transfer Data to Cloud Account
MITREへのリンク →

Sowbug

Score: 3.03
Matched TTPs:
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Chimera

Score: 5.43
Matched TTPs:
  • T1039 - Data from Network Shared Drive
  • T1569.002 - Service Execution
MITREへのリンク →

menuPass

Score: 3.03
Matched TTPs:
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

APT37

Score: 6.02
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Lazarus Group

Score: 15.51
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1584.004 - Server
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

INC Ransom

Score: 6.24
Matched TTPs:
  • T1537 - Transfer Data to Cloud Account
  • T1569.002 - Service Execution
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Leviathan

Score: 5.98
Matched TTPs:
  • T1584.004 - Server
  • T1027.015 - Compression
MITREへのリンク →

Medusa Group

Score: 10.56
Matched TTPs:
  • T1569.002 - Service Execution
  • T1529 - System Shutdown/Reboot
  • T1218.014 - MMC
MITREへのリンク →

FIN6

Score: 4.92
Matched TTPs:
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

PLATINUM

Score: 4.54
Matched TTPs:
  • T1056.004 - Credential API Hooking
MITREへのリンク →

Rocke

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Patchwork

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Molerats

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

Higaisa

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1027.015 - Compression
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.83
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1039 - Data from Network Shared Drive
  • T1110 - Brute Force
  • T1669 - Wi-Fi Networks
  • T1498 - Network Denial of Service
MITREへのリンク →

Gamaredon Group

Score: 0.80
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1480 - Execution Guardrails
  • T1608.001 - Upload Malware
  • T1039 - Data from Network Shared Drive
  • T1027.015 - Compression
  • T1016.001 - Internet Connection Discovery
MITREへのリンク →

Lazarus Group

Score: 0.72
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1027.007 - Dynamic API Resolution
  • T1529 - System Shutdown/Reboot
  • T1584.004 - Server
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

APT29

Score: 0.67
Matched TTPs:
  • T1562.008 - Disable or Modify Cloud Logs
  • T1566.003 - Spearphishing via Service
  • T1016.001 - Internet Connection Discovery
  • T1550.003 - Pass the Ticket
MITREへのリンク →

Sandworm Team

Score: 0.60
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1608.001 - Upload Malware
  • T1584.004 - Server
  • T1499 - Endpoint Denial of Service
MITREへのリンク →

Scattered Spider

Score: 0.59
Matched TTPs:
  • T1538 - Cloud Service Dashboard
  • T1114 - Email Collection
  • T1087 - Account Discovery
MITREへのリンク →

Magic Hound

Score: 0.56
Matched TTPs:
  • T1102.002 - Bidirectional Communication
  • T1114 - Email Collection
  • T1016.001 - Internet Connection Discovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る