Trusted Design

Win32.AutoIt Trojan

概要

IOCs derived from VirusTotal and Hybrid Analysis for Win32.AutoIt-KI.Trj, which is a Trojan horse infection that can target all the windows based system. After it gets itself installed on your computer, it can active itself via adding the registry to the startup items to modify your default computer settings. Therefore, your computer will become vulnerable for other computer virus like Trojan, worms, rogue programs, browser hijacker redirect virus.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

APT41

Score: 19.99
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1546.008 - Accessibility Features
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1012 - Query Registry
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

APT29

Score: 16.70
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1546.008 - Accessibility Features
  • T1546.003 - Windows Management Instrumentation Event Subscription
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Rocke

Score: 11.89
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1055.002 - Portable Executable Injection
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

UNC3886

Score: 11.14
Matched TTPs:
  • T1037 - Boot or Logon Initialization Scripts
  • T1587.001 - Malware
  • T1078.001 - Default Accounts
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

TeamTNT

Score: 8.17
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1543.003 - Windows Service
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Gamaredon Group

Score: 10.49
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1106 - Native API
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1012 - Query Registry
MITREへのリンク →

Volt Typhoon

Score: 7.54
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1112 - Modify Registry
  • T1012 - Query Registry
  • T1003.003 - NTDS
MITREへのリンク →

BRONZE BUTLER

Score: 5.91
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1189 - Drive-by Compromise
MITREへのリンク →

TA2541

Score: 4.14
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

APT42

Score: 7.50
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547 - Boot or Logon Autostart Execution
  • T1112 - Modify Registry
MITREへのリンク →

Storm-1811

Score: 4.87
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Indrik Spider

Score: 9.09
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
  • T1012 - Query Registry
MITREへのリンク →

FIN7

Score: 17.85
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1543.003 - Windows Service
  • T1546.011 - Application Shimming
  • T1674 - Input Injection
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1569.002 - Service Execution
MITREへのリンク →

MuddyWater

Score: 8.27
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1218.003 - CMSTP
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

WIRTE

Score: 3.88
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1218.010 - Regsvr32
MITREへのリンク →

Patchwork

Score: 5.94
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
MITREへのリンク →

Earth Lusca

Score: 6.67
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1189 - Drive-by Compromise
MITREへのリンク →

RedCurl

Score: 8.57
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1552.002 - Credentials in Registry
  • T1547.001 - Registry Run Keys / Startup Folder
MITREへのリンク →

APT28

Score: 15.52
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1546.015 - Component Object Model Hijacking
  • T1189 - Drive-by Compromise
  • T1137.002 - Office Test
  • T1003.003 - NTDS
MITREへのリンク →

Chimera

Score: 14.94
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1106 - Native API
  • T1012 - Query Registry
  • T1556.001 - Domain Controller Authentication
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

Aquatic Panda

Score: 6.70
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

APT32

Score: 19.39
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1543.003 - Windows Service
  • T1552.002 - Credentials in Registry
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1218.010 - Regsvr32
  • T1012 - Query Registry
  • T1189 - Drive-by Compromise
  • T1569.002 - Service Execution
MITREへのリンク →

Ke3chang

Score: 14.73
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1543.003 - Windows Service
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1614.001 - System Language Discovery
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

Tropic Trooper

Score: 10.41
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1543.003 - Windows Service
  • T1106 - Native API
  • T1547.004 - Winlogon Helper DLL
  • T1547.001 - Registry Run Keys / Startup Folder
MITREへのリンク →

Magic Hound

Score: 18.01
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1562 - Impair Defenses
  • T1112 - Modify Registry
  • T1078.001 - Default Accounts
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

PROMETHIUM

Score: 6.04
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1543.003 - Windows Service
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
MITREへのリンク →

INC Ransom

Score: 5.33
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1562.001 - Disable or Modify Tools
  • T1569.002 - Service Execution
MITREへのリンク →

LuminousMoth

Score: 6.27
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
MITREへのリンク →

OilRig

Score: 11.76
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1012 - Query Registry
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Machete

Score: 6.19
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1218.007 - Msiexec
  • T1189 - Drive-by Compromise
MITREへのリンク →

Carbanak

Score: 3.07
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1543.003 - Windows Service
MITREへのリンク →

Lazarus Group

Score: 28.36
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1543.003 - Windows Service
  • T1106 - Native API
  • T1547.009 - Shortcut Modification
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1012 - Query Registry
  • T1189 - Drive-by Compromise
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Darkhotel

Score: 4.11
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
MITREへのリンク →

Blue Mockingbird

Score: 12.88
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1546.003 - Windows Management Instrumentation Event Subscription
  • T1218.010 - Regsvr32
  • T1569.002 - Service Execution
MITREへのリンク →

menuPass

Score: 5.76
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1106 - Native API
  • T1003.003 - NTDS
MITREへのリンク →

Ember Bear

Score: 8.39
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1112 - Modify Registry
  • T1078.001 - Default Accounts
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

APT39

Score: 19.67
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1059.010 - AutoHotKey & AutoIT
  • T1547.009 - Shortcut Modification
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1012 - Query Registry
  • T1546.010 - AppInit DLLs
  • T1569.002 - Service Execution
MITREへのリンク →

Velvet Ant

Score: 5.33
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1562.001 - Disable or Modify Tools
  • T1569.002 - Service Execution
MITREへのリンク →

Kimsuky

Score: 19.52
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1546.001 - Change Default File Association
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1218.010 - Regsvr32
  • T1012 - Query Registry
MITREへのリンク →

Silence

Score: 8.86
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1106 - Native API
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1569.002 - Service Execution
MITREへのリンク →

Fox Kitten

Score: 9.00
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1546.008 - Accessibility Features
  • T1012 - Query Registry
  • T1003.003 - NTDS
MITREへのリンク →

ToddyCat

Score: 5.95
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1106 - Native API
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

SideCopy

Score: 3.42
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1106 - Native API
MITREへのリンク →

Turla

Score: 21.03
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1106 - Native API
  • T1112 - Modify Registry
  • T1547.004 - Winlogon Helper DLL
  • T1546.003 - Windows Management Instrumentation Event Subscription
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1012 - Query Registry
  • T1189 - Drive-by Compromise
MITREへのリンク →

Mustang Panda

Score: 25.11
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1106 - Native API
  • T1546.003 - Windows Management Instrumentation Event Subscription
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1678 - Delay Execution
  • T1622 - Debugger Evasion
  • T1027.007 - Dynamic API Resolution
  • T1003.003 - NTDS
MITREへのリンク →

FIN13

Score: 10.40
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1078.001 - Default Accounts
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1003.003 - NTDS
MITREへのリンク →

Sandworm Team

Score: 7.86
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1587.001 - Malware
  • T1106 - Native API
  • T1003.003 - NTDS
MITREへのリンク →

Moonstone Sleet

Score: 8.22
Matched TTPs:
  • T1587.001 - Malware
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Contagious Interview

Score: 12.16
Matched TTPs:
  • T1587.001 - Malware
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1547.013 - XDG Autostart Entries
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Play

Score: 3.89
Matched TTPs:
  • T1587.001 - Malware
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Medusa Group

Score: 16.21
Matched TTPs:
  • T1543.003 - Windows Service
  • T1106 - Native API
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

APT38

Score: 23.46
Matched TTPs:
  • T1543.003 - Windows Service
  • T1218.007 - Msiexec
  • T1106 - Native API
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
  • T1189 - Drive-by Compromise
  • T1036.006 - Space after Filename
  • T1569.002 - Service Execution
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Lotus Blossom

Score: 6.00
Matched TTPs:
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1012 - Query Registry
MITREへのリンク →

Wizard Spider

Score: 15.35
Matched TTPs:
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1547.004 - Winlogon Helper DLL
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
MITREへのリンク →

BlackByte

Score: 19.16
Matched TTPs:
  • T1543.003 - Windows Service
  • T1562 - Impair Defenses
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1614.001 - System Language Discovery
  • T1012 - Query Registry
  • T1569.002 - Service Execution
MITREへのリンク →

APT19

Score: 9.48
Matched TTPs:
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
MITREへのリンク →

Threat Group-3390

Score: 8.97
Matched TTPs:
  • T1543.003 - Windows Service
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1012 - Query Registry
  • T1189 - Drive-by Compromise
MITREへのリンク →

APT3

Score: 6.43
Matched TTPs:
  • T1543.003 - Windows Service
  • T1546.008 - Accessibility Features
  • T1547.001 - Registry Run Keys / Startup Folder
MITREへのリンク →

Agrius

Score: 3.73
Matched TTPs:
  • T1543.003 - Windows Service
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Cobalt Group

Score: 10.02
Matched TTPs:
  • T1543.003 - Windows Service
  • T1218.003 - CMSTP
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1218.010 - Regsvr32
MITREへのリンク →

Molerats

Score: 4.49
Matched TTPs:
  • T1218.007 - Msiexec
  • T1547.001 - Registry Run Keys / Startup Folder
MITREへのリンク →

TA505

Score: 9.20
Matched TTPs:
  • T1218.007 - Msiexec
  • T1106 - Native API
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Rancor

Score: 6.12
Matched TTPs:
  • T1218.007 - Msiexec
  • T1546.003 - Windows Management Instrumentation Event Subscription
MITREへのリンク →

ZIRCONIUM

Score: 6.73
Matched TTPs:
  • T1218.007 - Msiexec
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1012 - Query Registry
MITREへのリンク →

Higaisa

Score: 3.49
Matched TTPs:
  • T1106 - Native API
  • T1547.001 - Registry Run Keys / Startup Folder
MITREへのリンク →

Gorgon Group

Score: 14.87
Matched TTPs:
  • T1106 - Native API
  • T1547.009 - Shortcut Modification
  • T1112 - Modify Registry
  • T1055.002 - Portable Executable Injection
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

APT37

Score: 8.88
Matched TTPs:
  • T1106 - Native API
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
  • T1529 - System Shutdown/Reboot
MITREへのリンク →

Leviathan

Score: 12.17
Matched TTPs:
  • T1547.009 - Shortcut Modification
  • T1546.003 - Windows Management Instrumentation Event Subscription
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
MITREへのリンク →

Dragonfly

Score: 9.38
Matched TTPs:
  • T1112 - Modify Registry
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1012 - Query Registry
  • T1189 - Drive-by Compromise
  • T1003.003 - NTDS
MITREへのリンク →

Saint Bear

Score: 3.63
Matched TTPs:
  • T1112 - Modify Registry
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

FIN8

Score: 9.20
Matched TTPs:
  • T1112 - Modify Registry
  • T1055.004 - Asynchronous Procedure Call
  • T1546.003 - Windows Management Instrumentation Event Subscription
MITREへのリンク →

Deep Panda

Score: 6.03
Matched TTPs:
  • T1546.008 - Accessibility Features
  • T1218.010 - Regsvr32
MITREへのリンク →

Axiom

Score: 5.05
Matched TTPs:
  • T1546.008 - Accessibility Features
  • T1189 - Drive-by Compromise
MITREへのリンク →

APT33

Score: 4.04
Matched TTPs:
  • T1546.003 - Windows Management Instrumentation Event Subscription
  • T1547.001 - Registry Run Keys / Startup Folder
MITREへのリンク →

Inception

Score: 3.95
Matched TTPs:
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1218.010 - Regsvr32
MITREへのリンク →

FIN6

Score: 10.26
Matched TTPs:
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
  • T1003.003 - NTDS
  • T1569.002 - Service Execution
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Putter Panda

Score: 3.00
Matched TTPs:
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1562.001 - Disable or Modify Tools
MITREへのリンク →

Windshift

Score: 5.49
Matched TTPs:
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Dark Caracal

Score: 5.49
Matched TTPs:
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Scattered Spider

Score: 4.14
Matched TTPs:
  • T1562.001 - Disable or Modify Tools
  • T1003.003 - NTDS
MITREへのリンク →

Storm-0501

Score: 6.37
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1614.001 - System Language Discovery
MITREへのリンク →

Malteiro

Score: 3.62
Matched TTPs:
  • T1614.001 - System Language Discovery
MITREへのリンク →

Daggerfly

Score: 4.00
Matched TTPs:
  • T1012 - Query Registry
  • T1189 - Drive-by Compromise
MITREへのリンク →

PLATINUM

Score: 6.30
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1056.004 - Credential API Hooking
MITREへのリンク →

CURIUM

Score: 4.29
Matched TTPs:
  • T1189 - Drive-by Compromise
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Lazarus Group

Score: 0.76
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
  • T1547.009 - Shortcut Modification
  • T1562.001 - Disable or Modify Tools
  • T1012 - Query Registry
  • T1027.007 - Dynamic API Resolution
  • T1566.003 - Spearphishing via Service
  • T1587.001 - Malware
  • T1529 - System Shutdown/Reboot
  • T1543.003 - Windows Service
  • T1106 - Native API
MITREへのリンク →

Mustang Panda

Score: 0.66
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1678 - Delay Execution
  • T1003.003 - NTDS
  • T1027.007 - Dynamic API Resolution
  • T1587.001 - Malware
  • T1622 - Debugger Evasion
  • T1546.003 - Windows Management Instrumentation Event Subscription
  • T1106 - Native API
MITREへのリンク →

APT38

Score: 0.64
Matched TTPs:
  • T1036.006 - Space after Filename
  • T1189 - Drive-by Compromise
  • T1569.002 - Service Execution
  • T1218.007 - Msiexec
  • T1562.001 - Disable or Modify Tools
  • T1529 - System Shutdown/Reboot
  • T1112 - Modify Registry
  • T1543.003 - Windows Service
  • T1106 - Native API
MITREへのリンク →

Turla

Score: 0.63
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
  • T1547.004 - Winlogon Helper DLL
  • T1562.001 - Disable or Modify Tools
  • T1012 - Query Registry
  • T1587.001 - Malware
  • T1546.003 - Windows Management Instrumentation Event Subscription
  • T1112 - Modify Registry
  • T1106 - Native API
MITREへのリンク →

APT32

Score: 0.57
Matched TTPs:
  • T1036.005 - Match Legitimate Resource Name or Location
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1189 - Drive-by Compromise
  • T1569.002 - Service Execution
  • T1552.002 - Credentials in Registry
  • T1012 - Query Registry
  • T1112 - Modify Registry
  • T1218.010 - Regsvr32
  • T1543.003 - Windows Service
MITREへのリンク →

BlackByte

Score: 0.55
Matched TTPs:
  • T1547.001 - Registry Run Keys / Startup Folder
  • T1543.003 - Windows Service
  • T1569.002 - Service Execution
  • T1562.001 - Disable or Modify Tools
  • T1012 - Query Registry
  • T1112 - Modify Registry
  • T1562 - Impair Defenses
  • T1614.001 - System Language Discovery
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る