Trusted Design

Rovnix Downloader Updated with SinkHole and Time Checks

概要

McAfee Labs has found that the latest Rovnix downloader now comes with the capability to check for the sinkholing of its control servers. This relatively new technique makes it difficult to detect the malware—especially on behavior-based malware detection systems. The malware checks for sinkholing of its control servers before each network communication session and does not initiate its malicious activities—such as downloading and running the malicious payload(s)—if it thinks the Domain Name Service (DNS) records have been sinkholed. The downloader also uses an uncommon technique to perform a timing check to decide whether it should perform its malicious activities.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Magic Hound

Score: 19.17
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1592.002 - Software
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1584.001 - Domains
MITREへのリンク →

HEXANE

Score: 6.35
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT29

Score: 12.48
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1562.008 - Disable or Modify Cloud Logs
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Gamaredon Group

Score: 13.22
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1608.001 - Upload Malware
  • T1090 - Proxy
  • T1588.002 - Tool
  • T1001 - Data Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TA2541

Score: 8.80
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Lotus Blossom

Score: 8.29
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1090.001 - Internal Proxy
MITREへのリンク →

FIN13

Score: 16.91
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1090.001 - Internal Proxy
MITREへのリンク →

HAFNIUM

Score: 4.99
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1190 - Exploit Public-Facing Application
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Turla

Score: 22.14
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1090 - Proxy
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
MITREへのリンク →

Volt Typhoon

Score: 20.82
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1007 - System Service Discovery
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1588.002 - Tool
  • T1584.004 - Server
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
MITREへのリンク →

FIN8

Score: 4.37
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Kimsuky

Score: 21.10
Matched TTPs:
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
  • T1102.001 - Dead Drop Resolver
  • T1584.001 - Domains
MITREへのリンク →

Moonstone Sleet

Score: 7.24
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Indrik Spider

Score: 8.23
Matched TTPs:
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Lazarus Group

Score: 27.13
Matched TTPs:
  • T1587.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1584.004 - Server
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1027.007 - Dynamic API Resolution
  • T1008 - Fallback Channels
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Contagious Interview

Score: 9.45
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1090 - Proxy
  • T1588.002 - Tool
MITREへのリンク →

OilRig

Score: 19.45
Matched TTPs:
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1008 - Fallback Channels
MITREへのリンク →

UNC3886

Score: 14.15
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1008 - Fallback Channels
  • T1124 - System Time Discovery
MITREへのリンク →

LuminousMoth

Score: 8.15
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Sandworm Team

Score: 22.21
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1090 - Proxy
  • T1588.002 - Tool
  • T1592.002 - Software
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Salt Typhoon

Score: 4.41
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
MITREへのリンク →

Play

Score: 5.19
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Aoqin Dragon

Score: 5.13
Matched TTPs:
  • T1587.001 - Malware
  • T1036 - Masquerading
  • T1588.002 - Tool
MITREへのリンク →

RedCurl

Score: 3.86
Matched TTPs:
  • T1587.001 - Malware
  • T1046 - Network Service Discovery
MITREへのリンク →

Moses Staff

Score: 5.19
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Ke3chang

Score: 10.11
Matched TTPs:
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Mustang Panda

Score: 20.67
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1678 - Delay Execution
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1622 - Debugger Evasion
  • T1105 - Ingress Tool Transfer
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

TeamTNT

Score: 11.32
Matched TTPs:
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN7

Score: 21.82
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1497.002 - User Activity Based Checks
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1008 - Fallback Channels
  • T1124 - System Time Discovery
MITREへのリンク →

BRONZE BUTLER

Score: 12.21
Matched TTPs:
  • T1007 - System Service Discovery
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Aquatic Panda

Score: 8.70
Matched TTPs:
  • T1007 - System Service Discovery
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Chimera

Score: 10.90
Matched TTPs:
  • T1007 - System Service Discovery
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Earth Lusca

Score: 14.45
Matched TTPs:
  • T1007 - System Service Discovery
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1584.004 - Server
MITREへのリンク →

APT1

Score: 9.12
Matched TTPs:
  • T1007 - System Service Discovery
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1584.001 - Domains
MITREへのリンク →

Mustard Tempest

Score: 6.03
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1105 - Ingress Tool Transfer
  • T1584.001 - Domains
MITREへのリンク →

LazyScripter

Score: 7.39
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1588.001 - Malware
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Threat Group-3390

Score: 10.97
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

SideCopy

Score: 6.03
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1105 - Ingress Tool Transfer
  • T1584.001 - Domains
MITREへのリンク →

TA505

Score: 6.06
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

BlackByte

Score: 8.38
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

BITTER

Score: 5.69
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT32

Score: 14.79
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Ember Bear

Score: 11.73
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1588.001 - Malware
  • T1046 - Network Service Discovery
MITREへのリンク →

Rocke

Score: 7.30
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

APT28

Score: 14.36
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1137.002 - Office Test
  • T1669 - Wi-Fi Networks
MITREへのリンク →

BackdoorDiplomacy

Score: 9.42
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

BlackTech

Score: 4.08
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
MITREへのリンク →

Medusa Group

Score: 19.55
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1608.002 - Upload Tool
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1529 - System Shutdown/Reboot
  • T1218.014 - MMC
MITREへのリンク →

Storm-0501

Score: 6.31
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1218.010 - Regsvr32
MITREへのリンク →

Fox Kitten

Score: 8.45
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1036.004 - Masquerade Task or Service
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Cinnamon Tempest

Score: 5.44
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Agrius

Score: 5.42
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1046 - Network Service Discovery
MITREへのリンク →

menuPass

Score: 7.05
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Blue Mockingbird

Score: 9.80
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1569.002 - Service Execution
MITREへのリンク →

GALLIUM

Score: 3.10
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Winter Vivern

Score: 6.53
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036 - Masquerading
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Leviathan

Score: 7.83
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

INC Ransom

Score: 7.26
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

Dragonfly

Score: 5.93
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Axiom

Score: 6.01
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1563.002 - RDP Hijacking
MITREへのリンク →

APT41

Score: 18.42
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1008 - Fallback Channels
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

MuddyWater

Score: 3.10
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT39

Score: 10.19
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1090.001 - Internal Proxy
MITREへのリンク →

ZIRCONIUM

Score: 7.65
Matched TTPs:
  • T1036 - Masquerading
  • T1036.004 - Masquerade Task or Service
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
MITREへのリンク →

Storm-1811

Score: 3.81
Matched TTPs:
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TA551

Score: 5.71
Matched TTPs:
  • T1036 - Masquerading
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

CopyKittens

Score: 3.19
Matched TTPs:
  • T1090 - Proxy
  • T1588.002 - Tool
MITREへのリンク →

LAPSUS$

Score: 5.65
Matched TTPs:
  • T1090 - Proxy
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

POLONIUM

Score: 3.19
Matched TTPs:
  • T1090 - Proxy
  • T1588.002 - Tool
MITREへのリンク →

Scattered Spider

Score: 6.43
Matched TTPs:
  • T1090 - Proxy
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Metador

Score: 4.08
Matched TTPs:
  • T1588.001 - Malware
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Andariel

Score: 7.08
Matched TTPs:
  • T1588.001 - Malware
  • T1592.002 - Software
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT-C-36

Score: 3.72
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Wizard Spider

Score: 6.12
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

FIN6

Score: 7.11
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1046 - Network Service Discovery
  • T1569.002 - Service Execution
MITREへのリンク →

Naikon

Score: 3.86
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1046 - Network Service Discovery
MITREへのリンク →

Higaisa

Score: 7.62
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1124 - System Time Discovery
  • T1090.001 - Internal Proxy
MITREへのリンク →

Darkhotel

Score: 7.50
Matched TTPs:
  • T1497.002 - User Activity Based Checks
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
MITREへのリンク →

Inception

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
MITREへのリンク →

Patchwork

Score: 4.91
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

WIRTE

Score: 4.37
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Cobalt Group

Score: 6.14
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1046 - Network Service Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT38

Score: 7.65
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Silence

Score: 4.02
Matched TTPs:
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
MITREへのリンク →

APT19

Score: 3.60
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
MITREへのリンク →

Daggerfly

Score: 3.61
Matched TTPs:
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT37

Score: 4.40
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Sidewinder

Score: 3.37
Matched TTPs:
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
MITREへのリンク →

Velvet Ant

Score: 5.33
Matched TTPs:
  • T1569.002 - Service Execution
  • T1090.001 - Internal Proxy
MITREへのリンク →

RTM

Score: 3.29
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
MITREへのリンク →

Transparent Tribe

Score: 3.29
Matched TTPs:
  • T1584.001 - Domains
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.79
Matched TTPs:
  • T1090.001 - Internal Proxy
  • T1046 - Network Service Discovery
  • T1529 - System Shutdown/Reboot
  • T1587.001 - Malware
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1036.004 - Masquerade Task or Service
  • T1008 - Fallback Channels
  • T1124 - System Time Discovery
  • T1588.002 - Tool
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Turla

Score: 0.70
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1090.001 - Internal Proxy
  • T1587.001 - Malware
  • T1090 - Proxy
  • T1007 - System Service Discovery
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
  • T1588.001 - Malware
  • T1588.002 - Tool
MITREへのリンク →

FIN7

Score: 0.69
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1587.001 - Malware
  • T1497.002 - User Activity Based Checks
  • T1105 - Ingress Tool Transfer
  • T1036.004 - Masquerade Task or Service
  • T1008 - Fallback Channels
  • T1569.002 - Service Execution
  • T1124 - System Time Discovery
  • T1588.002 - Tool
MITREへのリンク →

Sandworm Team

Score: 0.66
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1587.001 - Malware
  • T1090 - Proxy
  • T1592.002 - Software
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1588.002 - Tool
  • T1195 - Supply Chain Compromise
  • T1036 - Masquerading
MITREへのリンク →

Kimsuky

Score: 0.62
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
  • T1608.001 - Upload Malware
  • T1218.010 - Regsvr32
  • T1190 - Exploit Public-Facing Application
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1584.001 - Domains
MITREへのリンク →

Volt Typhoon

Score: 0.61
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1090.001 - Internal Proxy
  • T1046 - Network Service Discovery
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1007 - System Service Discovery
  • T1584.004 - Server
  • T1105 - Ingress Tool Transfer
  • T1124 - System Time Discovery
  • T1588.002 - Tool
MITREへのリンク →

Medusa Group

Score: 0.60
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1046 - Network Service Discovery
  • T1218.014 - MMC
  • T1190 - Exploit Public-Facing Application
  • T1529 - System Shutdown/Reboot
  • T1105 - Ingress Tool Transfer
  • T1569.002 - Service Execution
  • T1588.002 - Tool
MITREへのリンク →

Mustang Panda

Score: 0.60
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1046 - Network Service Discovery
  • T1587.001 - Malware
  • T1622 - Debugger Evasion
  • T1105 - Ingress Tool Transfer
  • T1678 - Delay Execution
  • T1588.002 - Tool
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

APT41

Score: 0.57
Matched TTPs:
  • T1102.001 - Dead Drop Resolver
  • T1046 - Network Service Discovery
  • T1190 - Exploit Public-Facing Application
  • T1090 - Proxy
  • T1105 - Ingress Tool Transfer
  • T1036.004 - Masquerade Task or Service
  • T1008 - Fallback Channels
  • T1569.002 - Service Execution
  • T1588.002 - Tool
MITREへのリンク →

OilRig

Score: 0.57
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1046 - Network Service Discovery
  • T1587.001 - Malware
  • T1007 - System Service Discovery
  • T1105 - Ingress Tool Transfer
  • T1588.002 - Tool
  • T1008 - Fallback Channels
  • T1195 - Supply Chain Compromise
  • T1036 - Masquerading
MITREへのリンク →

Magic Hound

Score: 0.56
Matched TTPs:
  • T1016.001 - Internet Connection Discovery
  • T1046 - Network Service Discovery
  • T1190 - Exploit Public-Facing Application
  • T1592.002 - Software
  • T1090 - Proxy
  • T1105 - Ingress Tool Transfer
  • T1036.004 - Masquerade Task or Service
  • T1588.002 - Tool
  • T1584.001 - Domains
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る