A Look Into Fysbis: Sofacy’s Linux Backdoor
概要
The Sofacy group, also known as APT28 and Sednit, is a fairly well known cyber espionage group believed to have ties to Russia. Their targets have spanned all across the world, with a focus on government, defense organizations and various Eastern European governments.
From these reports, we know that the group uses an abundance of tools and tactics, ranging across zero-day exploits targeting common applications such as Java or Microsoft Office, heavy use of spear-phishing attacks, compromising legitimate websites to stage watering-hole attacks, and targeting over a variety of operating systems – Windows, OSX, Linux, even mobile iOS.
Created: 2026-02-23
Indicators
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 26.11
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1555.003 - Credentials from Web Browsers
- T1608.005 - Link Target
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1197 - BITS Jobs
- T1547.013 - XDG Autostart Entries
- T1003.003 - NTDS
MITREへのリンク →
Score: 9.89
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1555.003 - Credentials from Web Browsers
- T1122 - Component Object Model Hijacking
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 18.40
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1564.008 - Email Hiding Rules
- T1005 - Data from Local System
- T1555.003 - Credentials from Web Browsers
- T1218.010 - Regsvr32
- T1003.003 - NTDS
MITREへのリンク →
Score: 5.91
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1606.002 - SAML Tokens
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.80
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1555.003 - Credentials from Web Browsers
MITREへのリンク →
Score: 24.15
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1044 - File System Permissions Weakness
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1218.008 - Odbcconf
- T1608.005 - Link Target
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 26.00
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1564.008 - Email Hiding Rules
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1005 - Data from Local System
- T1555.003 - Credentials from Web Browsers
- T1122 - Component Object Model Hijacking
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 9.14
Matched TTPs:
- T1033 - System Owner/User Discovery
- T1091 - Replication Through Removable Media
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
MITREへのリンク →
Score: 5.49
Matched TTPs:
- T1606.002 - SAML Tokens
- T1555.003 - Credentials from Web Browsers
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 10.81
Matched TTPs:
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1197 - BITS Jobs
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 25.71
Matched TTPs:
- T1606.002 - SAML Tokens
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1567.002 - Exfiltration to Cloud Storage
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1055.005 - Thread Local Storage
- T1578.001 - Create Snapshot
- T1547.008 - LSASS Driver
- T1216 - System Script Proxy Execution
MITREへのリンク →
Score: 18.07
Matched TTPs:
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1005 - Data from Local System
- T1555.003 - Credentials from Web Browsers
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1128 - Netsh Helper DLL
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 10.31
Matched TTPs:
- T1606.002 - SAML Tokens
- T1547.015 - Login Items
- T1218.010 - Regsvr32
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 5.69
Matched TTPs:
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 17.88
Matched TTPs:
- T1606.002 - SAML Tokens
- T1555.003 - Credentials from Web Browsers
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1199 - Trusted Relationship
- T1683 - Generate Content
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 3.72
Matched TTPs:
- T1606.002 - SAML Tokens
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.44
Matched TTPs:
- T1606.002 - SAML Tokens
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 7.59
Matched TTPs:
- T1606.002 - SAML Tokens
- T1122 - Component Object Model Hijacking
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 5.49
Matched TTPs:
- T1606.002 - SAML Tokens
- T1555.003 - Credentials from Web Browsers
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 10.09
Matched TTPs:
- T1606.002 - SAML Tokens
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 3.72
Matched TTPs:
- T1606.002 - SAML Tokens
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 29.51
Matched TTPs:
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1555.003 - Credentials from Web Browsers
- T1562.006 - Indicator Blocking
- T1608.005 - Link Target
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1567.002 - Exfiltration to Cloud Storage
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 4.85
Matched TTPs:
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 14.84
Matched TTPs:
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1011.001 - Exfiltration Over Bluetooth
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 8.36
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1128 - Netsh Helper DLL
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.60
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 4.52
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.76
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1608.005 - Link Target
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.61
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 15.50
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1218.003 - CMSTP
- T1555.003 - Credentials from Web Browsers
- T1122 - Component Object Model Hijacking
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.50
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.60
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.52
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1555.003 - Credentials from Web Browsers
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 8.71
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1199 - Trusted Relationship
- T1683 - Generate Content
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 13.38
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1555.003 - Credentials from Web Browsers
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.35
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1199 - Trusted Relationship
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.48
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1608.005 - Link Target
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 5.99
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1218.010 - Regsvr32
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 5.57
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1199 - Trusted Relationship
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 20.44
Matched TTPs:
- T1218.003 - CMSTP
- T1555.003 - Credentials from Web Browsers
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1128 - Netsh Helper DLL
- T1598 - Phishing for Information
- T1547.013 - XDG Autostart Entries
- T1216 - System Script Proxy Execution
MITREへのリンク →
Score: 8.65
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1059.012 - Hypervisor CLI
- T1578.001 - Create Snapshot
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 6.65
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 23.92
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1197 - BITS Jobs
- T1059.012 - Hypervisor CLI
- T1146 - Clear Command History
- T1547.013 - XDG Autostart Entries
- T1588.003 - Code Signing Certificates
MITREへのリンク →
Score: 3.39
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.51
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 3.39
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.67
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1002 - Data Compressed
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.39
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 13.15
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1683 - Generate Content
- T1218.010 - Regsvr32
- T1128 - Netsh Helper DLL
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 11.15
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1218.008 - Odbcconf
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.39
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1547.013 - XDG Autostart Entries
- T1588.005 - Exploits
MITREへのリンク →
Score: 4.04
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 15.64
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1083 - File and Directory Discovery
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 8.78
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1199 - Trusted Relationship
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1216 - System Script Proxy Execution
MITREへのリンク →
Score: 13.31
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1683 - Generate Content
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 8.55
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1027.014 - Polymorphic Code
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 11.28
Matched TTPs:
- T1218.008 - Odbcconf
- T1122 - Component Object Model Hijacking
- T1199 - Trusted Relationship
- T1588.005 - Exploits
MITREへのリンク →
Score: 9.38
Matched TTPs:
- T1083 - File and Directory Discovery
- T1567.001 - Exfiltration to Code Repository
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.25
Matched TTPs:
- T1083 - File and Directory Discovery
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 12.53
Matched TTPs:
- T1083 - File and Directory Discovery
- T1199 - Trusted Relationship
- T1197 - BITS Jobs
- T1547.013 - XDG Autostart Entries
- T1588.005 - Exploits
MITREへのリンク →
Score: 5.90
Matched TTPs:
- T1547.015 - Login Items
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 8.82
Matched TTPs:
- T1608.005 - Link Target
- T1197 - BITS Jobs
- T1547.013 - XDG Autostart Entries
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 7.88
Matched TTPs:
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.28
Matched TTPs:
- T1608.005 - Link Target
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.64
Matched TTPs:
- T1608.005 - Link Target
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.61
Matched TTPs:
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1199 - Trusted Relationship
MITREへのリンク →
Score: 7.25
Matched TTPs:
- T1567.001 - Exfiltration to Code Repository
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.37
Matched TTPs:
- T1122 - Component Object Model Hijacking
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 7.83
Matched TTPs:
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1218.010 - Regsvr32
- T1159 - Launch Agent
MITREへのリンク →
Score: 4.15
Matched TTPs:
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 10.22
Matched TTPs:
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 7.25
Matched TTPs:
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1002 - Data Compressed
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.37
Matched TTPs:
- T1199 - Trusted Relationship
- T1128 - Netsh Helper DLL
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.12
Matched TTPs:
- T1199 - Trusted Relationship
- T1128 - Netsh Helper DLL
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 4.88
Matched TTPs:
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.37
Matched TTPs:
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 8.61
Matched TTPs:
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1218.010 - Regsvr32
- T1128 - Netsh Helper DLL
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.22
Matched TTPs:
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 5.36
Matched TTPs:
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 3.60
Matched TTPs:
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 3.52
Matched TTPs:
- T1027.014 - Polymorphic Code
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 7.61
Matched TTPs:
- T1218.010 - Regsvr32
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 4.04
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.09
Matched TTPs:
- T1218.010 - Regsvr32
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 3.26
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 7.93
Matched TTPs:
- T1218.010 - Regsvr32
- T1567.002 - Exfiltration to Cloud Storage
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 7.66
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1216 - System Script Proxy Execution
MITREへのリンク →
Score: 3.26
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 4.04
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.63
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1578.001 - Create Snapshot
MITREへのリンク →
Score: 7.08
Matched TTPs:
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1686 - Disable or Modify System Firewall
MITREへのリンク →
Score: 7.81
Matched TTPs:
- T1059.012 - Hypervisor CLI
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 4.29
Matched TTPs:
- T1059.012 - Hypervisor CLI
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 4.51
Matched TTPs:
- T1059.012 - Hypervisor CLI
- T1159 - Launch Agent
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1130 - Install Root Certificate
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1130 - Install Root Certificate
MITREへのリンク →
Score: 3.30
Matched TTPs:
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.85
Matched TTPs:
- T1555.003 - Credentials from Web Browsers
- T1608.005 - Link Target
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1159 - Launch Agent
- T1606.002 - SAML Tokens
- T1547.013 - XDG Autostart Entries
- T1562.006 - Indicator Blocking
- T1091 - Replication Through Removable Media
- T1055.005 - Thread Local Storage
- T1567.002 - Exfiltration to Cloud Storage
MITREへのリンク →
Score: 0.78
Matched TTPs:
- T1608.005 - Link Target
- T1033 - System Owner/User Discovery
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1547.013 - XDG Autostart Entries
- T1606.002 - SAML Tokens
- T1003.003 - NTDS
- T1555.003 - Credentials from Web Browsers
- T1091 - Replication Through Removable Media
- T1197 - BITS Jobs
MITREへのリンク →
Score: 0.76
Matched TTPs:
- T1122 - Component Object Model Hijacking
- T1005 - Data from Local System
- T1033 - System Owner/User Discovery
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1606.002 - SAML Tokens
- T1555.003 - Credentials from Web Browsers
- T1091 - Replication Through Removable Media
- T1564.008 - Email Hiding Rules
MITREへのリンク →
Score: 0.75
Matched TTPs:
- T1146 - Clear Command History
- T1122 - Component Object Model Hijacking
- T1608.005 - Link Target
- T1588.003 - Code Signing Certificates
- T1059.012 - Hypervisor CLI
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1555.003 - Credentials from Web Browsers
- T1197 - BITS Jobs
MITREへのリンク →
Score: 0.74
Matched TTPs:
- T1608.005 - Link Target
- T1547.008 - LSASS Driver
- T1059.012 - Hypervisor CLI
- T1199 - Trusted Relationship
- T1055.005 - Thread Local Storage
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1606.002 - SAML Tokens
- T1216 - System Script Proxy Execution
- T1578.001 - Create Snapshot
- T1567.002 - Exfiltration to Cloud Storage
MITREへのリンク →
Score: 0.67
Matched TTPs:
- T1608.005 - Link Target
- T1547.008 - LSASS Driver
- T1033 - System Owner/User Discovery
- T1102.003 - One-Way Communication
- T1199 - Trusted Relationship
- T1606.002 - SAML Tokens
- T1044 - File System Permissions Weakness
- T1091 - Replication Through Removable Media
- T1218.008 - Odbcconf
MITREへのリンク →
Score: 0.63
Matched TTPs:
- T1218.003 - CMSTP
- T1598 - Phishing for Information
- T1608.005 - Link Target
- T1128 - Netsh Helper DLL
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
- T1216 - System Script Proxy Execution
- T1555.003 - Credentials from Web Browsers
MITREへのリンク →
Score: 0.59
Matched TTPs:
- T1122 - Component Object Model Hijacking
- T1608.005 - Link Target
- T1683 - Generate Content
- T1547.008 - LSASS Driver
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1606.002 - SAML Tokens
- T1555.003 - Credentials from Web Browsers
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1005 - Data from Local System
- T1033 - System Owner/User Discovery
- T1003.003 - NTDS
- T1218.010 - Regsvr32
- T1555.003 - Credentials from Web Browsers
- T1564.008 - Email Hiding Rules
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1005 - Data from Local System
- T1547.008 - LSASS Driver
- T1128 - Netsh Helper DLL
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1606.002 - SAML Tokens
- T1555.003 - Credentials from Web Browsers
- T1091 - Replication Through Removable Media
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る