Trusted Design

BlackEnergy by the SSHBearDoor

概要

The cybercriminal group behind BlackEnergy, the malware family that has been around since 2007 and has made a comeback in 2014 (see our previous blog posts on Back in BlackEnergy *: 2014 Targeted Attacks in Ukraine and Poland and BlackEnergy PowerPoint Campaigns, as well as our Virus Bulletin talk on the subject), was also active in the year 2015. ESET has recently discovered that the BlackEnergy trojan was recently used as a backdoor to deliver a destructive KillDisk component in attacks against Ukrainian news media companies and against the electrical power industry. In this blog, we provide details on the BlackEnergy samples ESET has detected in 2015, as well as the KillDisk components used in the attacks. Furthermore, we examine a previously unknown SSH backdoor that was also used as another channel of accessing the infected systems, in addition to BlackEnergy.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Ember Bear

Score: 10.94
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
MITREへのリンク →

Sandworm Team

Score: 24.91
Matched TTPs:
  • T1564.008 - Email Hiding Rules
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Winnti Group

Score: 3.29
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
MITREへのリンク →

APT41

Score: 12.72
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1560.003 - Archive via Custom Method
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Rocke

Score: 4.76
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

TeamTNT

Score: 9.88
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
MITREへのリンク →

APT28

Score: 33.20
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1552.005 - Cloud Instance Metadata API
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1548.004 - Elevated Execution with Prompt
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
  • T1146 - Clear Command History
  • T1548.006 - TCC Manipulation
  • T1546.007 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 15.63
Matched TTPs:
  • T1499.001 - OS Exhaustion Flood
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1021.006 - Windows Remote Management
  • T1059.004 - Unix Shell
  • T1218.010 - Regsvr32
MITREへのリンク →

Scattered Spider

Score: 17.85
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1552.003 - Shell History
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1027.002 - Software Packing
  • T1548.006 - TCC Manipulation
MITREへのリンク →

TA505

Score: 6.11
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
MITREへのリンク →

Volt Typhoon

Score: 10.47
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT3

Score: 9.90
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1087.004 - Cloud Account
  • T1059.004 - Unix Shell
  • T1218.010 - Regsvr32
MITREへのリンク →

FIN13

Score: 12.56
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

OilRig

Score: 24.82
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1199 - Trusted Relationship
  • T1059.004 - Unix Shell
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1547.008 - LSASS Driver
MITREへのリンク →

Gamaredon Group

Score: 19.49
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1091 - Replication Through Removable Media
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1061 - Graphical User Interface
  • T1547.002 - Authentication Package
  • T1086 - PowerShell
MITREへのリンク →

Turla

Score: 14.64
Matched TTPs:
  • T1552.005 - Cloud Instance Metadata API
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1199 - Trusted Relationship
  • T1059.004 - Unix Shell
  • T1547.002 - Authentication Package
MITREへのリンク →

Kimsuky

Score: 20.89
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1027.014 - Polymorphic Code
  • T1547.002 - Authentication Package
MITREへのリンク →

Moonstone Sleet

Score: 8.93
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1565 - Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

Indrik Spider

Score: 4.62
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
MITREへのリンク →

Lazarus Group

Score: 25.56
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1547.008 - LSASS Driver
  • T1086 - PowerShell
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Contagious Interview

Score: 18.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1021.006 - Windows Remote Management
  • T1552.003 - Shell History
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

LuminousMoth

Score: 6.89
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
MITREへのリンク →

Salt Typhoon

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

APT29

Score: 8.43
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

Play

Score: 6.94
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

Aoqin Dragon

Score: 4.44
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

RedCurl

Score: 4.84
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Cleaver

Score: 5.29
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
MITREへのリンク →

Moses Staff

Score: 4.41
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

Ke3chang

Score: 11.25
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1003.007 - Proc Filesystem
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Mustang Panda

Score: 14.86
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1055.005 - Thread Local Storage
  • T1548.006 - TCC Manipulation
MITREへのリンク →

FIN7

Score: 13.32
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1011.001 - Exfiltration Over Bluetooth
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

BRONZE BUTLER

Score: 4.87
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Aquatic Panda

Score: 3.37
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1199 - Trusted Relationship
MITREへのリンク →

Chimera

Score: 7.69
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Earth Lusca

Score: 6.82
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
MITREへのリンク →

admin@338

Score: 4.02
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1218.010 - Regsvr32
MITREへのリンク →

APT1

Score: 3.37
Matched TTPs:
  • T1003.007 - Proc Filesystem
  • T1199 - Trusted Relationship
MITREへのリンク →

BlackByte

Score: 9.55
Matched TTPs:
  • T1070.003 - Clear Command History
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
MITREへのリンク →

Magic Hound

Score: 13.71
Matched TTPs:
  • T1070.003 - Clear Command History
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
  • T1547.008 - LSASS Driver
MITREへのリンク →

TA2541

Score: 5.57
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Star Blizzard

Score: 5.16
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
MITREへのリンク →

Threat Group-3390

Score: 9.92
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

BITTER

Score: 4.32
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

APT32

Score: 11.38
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
MITREへのリンク →

HEXANE

Score: 7.56
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1547.002 - Authentication Package
MITREへのリンク →

Saint Bear

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

EXOTIC LILY

Score: 8.33
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1565 - Data Manipulation
  • T1218.010 - Regsvr32
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT42

Score: 5.57
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

BlackTech

Score: 3.81
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Medusa Group

Score: 24.56
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.003 - CMSTP
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
  • T1565 - Data Manipulation
  • T1128 - Netsh Helper DLL
  • T1598 - Phishing for Information
  • T1548.006 - TCC Manipulation
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Sea Turtle

Score: 3.81
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Storm-0501

Score: 6.74
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Fox Kitten

Score: 6.15
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1565 - Data Manipulation
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Cinnamon Tempest

Score: 4.84
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

Agrius

Score: 3.44
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
MITREへのリンク →

menuPass

Score: 4.66
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

ToddyCat

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1547.008 - LSASS Driver
MITREへのリンク →

Blue Mockingbird

Score: 5.07
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

GALLIUM

Score: 7.44
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1059.004 - Unix Shell
MITREへのリンク →

Winter Vivern

Score: 3.44
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
MITREへのリンク →

Leviathan

Score: 10.02
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1565 - Data Manipulation
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
MITREへのリンク →

INC Ransom

Score: 4.84
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

Dragonfly

Score: 6.15
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Axiom

Score: 7.50
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1160 - Launch Daemon
MITREへのリンク →

HAFNIUM

Score: 3.81
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1548.006 - TCC Manipulation
MITREへのリンク →

MuddyWater

Score: 8.18
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
MITREへのリンク →

APT39

Score: 6.69
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

MoustachedBouncer

Score: 4.54
Matched TTPs:
  • T1055.003 - Thread Execution Hijacking
MITREへのリンク →

Equation

Score: 4.54
Matched TTPs:
  • T1589.003 - Employee Names
MITREへのリンク →

Water Galura

Score: 4.86
Matched TTPs:
  • T1552.003 - Shell History
  • T1565 - Data Manipulation
MITREへのリンク →

APT33

Score: 6.48
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

Wizard Spider

Score: 9.30
Matched TTPs:
  • T1567.001 - Exfiltration to Code Repository
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Higaisa

Score: 3.47
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
MITREへのリンク →

ZIRCONIUM

Score: 4.37
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1547.002 - Authentication Package
MITREへのリンク →

Confucius

Score: 3.47
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
MITREへのリンク →

CURIUM

Score: 6.84
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1565 - Data Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

Inception

Score: 5.09
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
MITREへのリンク →

LAPSUS$

Score: 3.19
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Storm-1811

Score: 3.37
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.008 - LSASS Driver
MITREへのリンク →

FIN8

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
MITREへのリンク →

FIN6

Score: 8.46
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1548.006 - TCC Manipulation
  • T1547.008 - LSASS Driver
MITREへのリンク →

Patchwork

Score: 5.49
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1059.004 - Unix Shell
  • T1218.010 - Regsvr32
MITREへのリンク →

WIRTE

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Cobalt Group

Score: 7.83
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
MITREへのリンク →

POLONIUM

Score: 3.25
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

APT38

Score: 4.47
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT19

Score: 3.60
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
MITREへのリンク →

Carbanak

Score: 3.25
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1547.002 - Authentication Package
MITREへのリンク →

Deep Panda

Score: 5.90
Matched TTPs:
  • T1059.004 - Unix Shell
  • T1027.014 - Polymorphic Code
MITREへのリンク →

APT37

Score: 7.51
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT12

Score: 3.89
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1218.010 - Regsvr32
MITREへのリンク →

Tropic Trooper

Score: 4.24
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Velvet Ant

Score: 6.88
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1146 - Clear Command History
  • T1499.001 - OS Exhaustion Flood
  • T1546.007 - Netsh Helper DLL
  • T1552.005 - Cloud Instance Metadata API
  • T1548.006 - TCC Manipulation
  • T1218.010 - Regsvr32
  • T1566.003 - Spearphishing via Service
  • T1548.004 - Elevated Execution with Prompt
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
MITREへのリンク →

Lazarus Group

Score: 0.69
Matched TTPs:
  • T1547.008 - LSASS Driver
  • T1087.004 - Cloud Account
  • T1606.002 - SAML Tokens
  • T1565 - Data Manipulation
  • T1218.010 - Regsvr32
  • T1086 - PowerShell
  • T1216 - System Script Proxy Execution
  • T1055.005 - Thread Local Storage
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
MITREへのリンク →

Sandworm Team

Score: 0.67
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1005 - Data from Local System
  • T1606.002 - SAML Tokens
  • T1548.006 - TCC Manipulation
  • T1565 - Data Manipulation
  • T1218.010 - Regsvr32
  • T1564.008 - Email Hiding Rules
  • T1091 - Replication Through Removable Media
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
MITREへのリンク →

Medusa Group

Score: 0.66
Matched TTPs:
  • T1218.003 - CMSTP
  • T1140 - Deobfuscate/Decode Files or Information
  • T1598 - Phishing for Information
  • T1548.006 - TCC Manipulation
  • T1128 - Netsh Helper DLL
  • T1565 - Data Manipulation
  • T1216 - System Script Proxy Execution
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

OilRig

Score: 0.64
Matched TTPs:
  • T1547.008 - LSASS Driver
  • T1005 - Data from Local System
  • T1552.005 - Cloud Instance Metadata API
  • T1606.002 - SAML Tokens
  • T1059.004 - Unix Shell
  • T1128 - Netsh Helper DLL
  • T1218.010 - Regsvr32
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
MITREへのリンク →

Kimsuky

Score: 0.59
Matched TTPs:
  • T1547.002 - Authentication Package
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1606.002 - SAML Tokens
  • T1565 - Data Manipulation
  • T1027.014 - Polymorphic Code
  • T1003.007 - Proc Filesystem
  • T1091 - Replication Through Removable Media
  • T1552.003 - Shell History
  • T1199 - Trusted Relationship
MITREへのリンク →

Gamaredon Group

Score: 0.57
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1552.005 - Cloud Instance Metadata API
  • T1061 - Graphical User Interface
  • T1086 - PowerShell
  • T1091 - Replication Through Removable Media
  • T1547.002 - Authentication Package
  • T1199 - Trusted Relationship
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る