Trusted Design

Covert Channels and Poor Decisions: The Tale of DNSMessenger

概要

(Cisco) What initially drew our interest to this particular malware sample was a tweet published by security researcher on Twitter (thanks simpo!) regarding a Powershell script that he was analyzing that contained the base64 encoded string 'SourceFireSux'. Interestingly enough, Sourcefire was the only security vendor directly referenced in the Powershell script. We searched for the base64 encoded value which was referenced in the tweet, and were able to identify a sample that had been uploaded to the public malware analysis sandbox, Hybrid Analysis. Additionally, when we searched for the decoded string value we found a single search engine result that pointed to a Pastebin page. The hash listed in the Pastebin led us to a malicious Word document that had also been uploaded to a public sandbox. The Word document initiated the same multiple-stage infection process as the file from the Hybrid Analysis report we previously discovered and allowed us to reconstruct a more complete infection process.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Lazarus Group

Score: 36.31
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1491.002 - External Defacement
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1205 - Traffic Signaling
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1174 - Password Filter DLL
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1055.005 - Thread Local Storage
  • T1055.015 - ListPlanting
  • T1665 - Hide Infrastructure
MITREへのリンク →

TA577

Score: 3.84
Matched TTPs:
  • T1132.001 - Standard Encoding
MITREへのリンク →

Moonstone Sleet

Score: 19.88
Matched TTPs:
  • T1132.001 - Standard Encoding
  • T1491.002 - External Defacement
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1057 - Process Discovery
  • T1059.011 - Lua
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Turla

Score: 15.11
Matched TTPs:
  • T1056.001 - Keylogging
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Contagious Interview

Score: 37.28
Matched TTPs:
  • T1044 - File System Permissions Weakness
  • T1491.002 - External Defacement
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1021.006 - Windows Remote Management
  • T1218.008 - Odbcconf
  • T1064 - Scripting
  • T1562.010 - Downgrade Attack
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1601.001 - Patch System Image
  • T1221 - Template Injection
MITREへのリンク →

Inception

Score: 11.35
Matched TTPs:
  • T1491.002 - External Defacement
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
MITREへのリンク →

Elderwood

Score: 3.86
Matched TTPs:
  • T1491.002 - External Defacement
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Darkhotel

Score: 12.69
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1064 - Scripting
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Transparent Tribe

Score: 3.09
Matched TTPs:
  • T1491.002 - External Defacement
  • T1218.010 - Regsvr32
MITREへのリンク →

APT28

Score: 28.79
Matched TTPs:
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1542.004 - ROMMONkit
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Leviathan

Score: 16.34
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1087.004 - Cloud Account
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

Sidewinder

Score: 15.22
Matched TTPs:
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1657 - Financial Theft
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT39

Score: 6.76
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Saint Bear

Score: 8.90
Matched TTPs:
  • T1491.002 - External Defacement
  • T1091 - Replication Through Removable Media
  • T1064 - Scripting
  • T1218.010 - Regsvr32
MITREへのリンク →

APT33

Score: 4.71
Matched TTPs:
  • T1491.002 - External Defacement
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

BITTER

Score: 6.69
Matched TTPs:
  • T1491.002 - External Defacement
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

TA505

Score: 11.91
Matched TTPs:
  • T1491.002 - External Defacement
  • T1560.003 - Archive via Custom Method
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Higaisa

Score: 14.13
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
  • T1665 - Hide Infrastructure
  • T1546.017 - Udev Rules
MITREへのリンク →

APT19

Score: 8.62
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1601.001 - Patch System Image
MITREへのリンク →

Fox Kitten

Score: 11.11
Matched TTPs:
  • T1491.002 - External Defacement
  • T1542.004 - ROMMONkit
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
  • T1588.005 - Exploits
MITREへのリンク →

Threat Group-3390

Score: 15.54
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1218.003 - CMSTP
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

TA2541

Score: 12.99
Matched TTPs:
  • T1491.002 - External Defacement
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1506 - Web Session Cookie
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

Malteiro

Score: 8.68
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1102.002 - Bidirectional Communication
  • T1506 - Web Session Cookie
MITREへのリンク →

Magic Hound

Score: 12.90
Matched TTPs:
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1187 - Forced Authentication
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Storm-1811

Score: 6.97
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Blue Mockingbird

Score: 9.73
Matched TTPs:
  • T1491.002 - External Defacement
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1001.001 - Junk Data
MITREへのリンク →

Tropic Trooper

Score: 20.61
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1562.011 - Spoof Security Alerting
  • T1506 - Web Session Cookie
  • T1200 - Hardware Additions
  • T1547.013 - XDG Autostart Entries
  • T1665 - Hide Infrastructure
MITREへのリンク →

Mofang

Score: 4.75
Matched TTPs:
  • T1491.002 - External Defacement
  • T1546.017 - Udev Rules
MITREへのリンク →

Whitefly

Score: 3.22
Matched TTPs:
  • T1491.002 - External Defacement
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

menuPass

Score: 13.29
Matched TTPs:
  • T1491.002 - External Defacement
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1542.004 - ROMMONkit
  • T1174 - Password Filter DLL
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Moses Staff

Score: 5.31
Matched TTPs:
  • T1491.002 - External Defacement
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

TeamTNT

Score: 16.44
Matched TTPs:
  • T1491.002 - External Defacement
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1583.006 - Web Services
  • T1506 - Web Session Cookie
  • T1547.013 - XDG Autostart Entries
  • T1665 - Hide Infrastructure
MITREへのリンク →

Metador

Score: 3.22
Matched TTPs:
  • T1491.002 - External Defacement
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

OilRig

Score: 28.62
Matched TTPs:
  • T1491.002 - External Defacement
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1558 - Steal or Forge Kerberos Tickets
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1592.002 - Software
  • T1128 - Netsh Helper DLL
  • T1547.013 - XDG Autostart Entries
  • T1055.015 - ListPlanting
MITREへのリンク →

APT32

Score: 23.95
Matched TTPs:
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1174 - Password Filter DLL
  • T1218.010 - Regsvr32
  • T1601.001 - Patch System Image
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT41

Score: 23.14
Matched TTPs:
  • T1539 - Steal Web Session Cookie
  • T1560.003 - Archive via Custom Method
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1218.010 - Regsvr32
  • T1002 - Data Compressed
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
  • T1055.015 - ListPlanting
MITREへのリンク →

TA551

Score: 14.74
Matched TTPs:
  • T1539 - Steal Web Session Cookie
  • T1558 - Steal or Forge Kerberos Tickets
  • T1027.014 - Polymorphic Code
  • T1562.011 - Spoof Security Alerting
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Scattered Spider

Score: 20.94
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1566.002 - Spearphishing Link
  • T1083 - File and Directory Discovery
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1090.004 - Domain Fronting
  • T1547.013 - XDG Autostart Entries
  • T1588.005 - Exploits
MITREへのリンク →

Volt Typhoon

Score: 21.58
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1013 - Port Monitors
  • T1059.010 - AutoHotKey & AutoIT
  • T1083 - File and Directory Discovery
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
  • T1665 - Hide Infrastructure
MITREへのリンク →

APT3

Score: 11.33
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1059.011 - Lua
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

FIN13

Score: 13.51
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

BlackByte

Score: 19.50
Matched TTPs:
  • T1013 - Port Monitors
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1562.010 - Downgrade Attack
  • T1087.004 - Cloud Account
  • T1102.002 - Bidirectional Communication
  • T1506 - Web Session Cookie
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Mustang Panda

Score: 33.35
Matched TTPs:
  • T1013 - Port Monitors
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1169 - Sudo
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1218.010 - Regsvr32
  • T1547.013 - XDG Autostart Entries
  • T1055.005 - Thread Local Storage
MITREへのリンク →

Kimsuky

Score: 42.88
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1205 - Traffic Signaling
  • T1683.001 - Written Content
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1027.014 - Polymorphic Code
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
  • T1665 - Hide Infrastructure
MITREへのリンク →

UNC3886

Score: 12.68
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1021.006 - Windows Remote Management
  • T1583.006 - Web Services
  • T1218.010 - Regsvr32
  • T1055.015 - ListPlanting
MITREへのリンク →

LuminousMoth

Score: 7.67
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Sandworm Team

Score: 31.06
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1566.002 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1558 - Steal or Forge Kerberos Tickets
  • T1193 - Spearphishing Attachment
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

APT29

Score: 9.75
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1223 - Compiled HTML File
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Play

Score: 9.00
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Aoqin Dragon

Score: 6.62
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
MITREへのリンク →

RedCurl

Score: 10.16
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1542.004 - ROMMONkit
  • T1059.011 - Lua
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Ke3chang

Score: 14.69
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1102.002 - Bidirectional Communication
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

FIN7

Score: 25.53
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1205 - Traffic Signaling
  • T1011.001 - Exfiltration Over Bluetooth
  • T1583.006 - Web Services
  • T1057 - Process Discovery
  • T1199 - Trusted Relationship
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
  • T1055.015 - ListPlanting
MITREへのリンク →

Silent Librarian

Score: 3.31
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1199 - Trusted Relationship
MITREへのリンク →

ZIRCONIUM

Score: 8.96
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1087.004 - Cloud Account
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Star Blizzard

Score: 8.90
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
  • T1199 - Trusted Relationship
MITREへのリンク →

CURIUM

Score: 4.43
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1087.004 - Cloud Account
MITREへのリンク →

Dragonfly

Score: 16.20
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1193 - Spearphishing Attachment
  • T1657 - Financial Theft
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Patchwork

Score: 12.17
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
  • T1665 - Hide Infrastructure
MITREへのリンク →

BRONZE BUTLER

Score: 12.94
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1542.004 - ROMMONkit
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

WIRTE

Score: 5.94
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Gorgon Group

Score: 3.19
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Agrius

Score: 5.73
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1087.004 - Cloud Account
MITREへのリンク →

APT38

Score: 9.90
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1174 - Password Filter DLL
  • T1506 - Web Session Cookie
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Molerats

Score: 7.01
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

Earth Lusca

Score: 11.23
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1562.011 - Spoof Security Alerting
MITREへのリンク →

MuddyWater

Score: 18.60
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1059.013 - Container CLI/API
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Gamaredon Group

Score: 43.51
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1091 - Replication Through Removable Media
  • T1205 - Traffic Signaling
  • T1562.010 - Downgrade Attack
  • T1608 - Stage Capabilities
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1061 - Graphical User Interface
  • T1542.004 - ROMMONkit
  • T1059.011 - Lua
  • T1059.013 - Container CLI/API
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1200 - Hardware Additions
  • T1547.013 - XDG Autostart Entries
  • T1546.017 - Udev Rules
MITREへのリンク →

Winter Vivern

Score: 6.50
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1558 - Steal or Forge Kerberos Tickets
  • T1087.004 - Cloud Account
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Cinnamon Tempest

Score: 3.19
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Rocke

Score: 11.67
Matched TTPs:
  • T1059.010 - AutoHotKey & AutoIT
  • T1583.006 - Web Services
  • T1059.011 - Lua
  • T1059.013 - Container CLI/API
  • T1506 - Web Session Cookie
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Mustard Tempest

Score: 7.29
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1543.002 - Systemd Service
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

LazyScripter

Score: 6.80
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1558 - Steal or Forge Kerberos Tickets
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

SideCopy

Score: 8.27
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1657 - Financial Theft
  • T1506 - Web Session Cookie
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

HEXANE

Score: 6.98
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

APT42

Score: 7.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1506 - Web Session Cookie
MITREへのリンク →

Ember Bear

Score: 10.27
Matched TTPs:
  • T1005 - Data from Local System
  • T1558 - Steal or Forge Kerberos Tickets
  • T1218.010 - Regsvr32
  • T1668 - Exclusive Control
MITREへのリンク →

Windshift

Score: 8.67
Matched TTPs:
  • T1558 - Steal or Forge Kerberos Tickets
  • T1583.006 - Web Services
  • T1059.011 - Lua
  • T1506 - Web Session Cookie
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Wizard Spider

Score: 18.27
Matched TTPs:
  • T1038 - DLL Search Order Hijacking
  • T1083 - File and Directory Discovery
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Medusa Group

Score: 18.32
Matched TTPs:
  • T1218.003 - CMSTP
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

LAPSUS$

Score: 12.38
Matched TTPs:
  • T1193 - Spearphishing Attachment
  • T1218.008 - Odbcconf
  • T1199 - Trusted Relationship
  • T1588.005 - Exploits
MITREへのリンク →

HAFNIUM

Score: 6.14
Matched TTPs:
  • T1218.008 - Odbcconf
  • T1583.006 - Web Services
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

INC Ransom

Score: 5.25
Matched TTPs:
  • T1083 - File and Directory Discovery
  • T1199 - Trusted Relationship
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Deep Panda

Score: 4.26
Matched TTPs:
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
MITREへのリンク →

APT1

Score: 5.11
Matched TTPs:
  • T1583.006 - Web Services
  • T1199 - Trusted Relationship
  • T1668 - Exclusive Control
MITREへのリンク →

Stealth Falcon

Score: 3.49
Matched TTPs:
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
MITREへのリンク →

Chimera

Score: 15.59
Matched TTPs:
  • T1583.006 - Web Services
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1542.004 - ROMMONkit
  • T1601.001 - Patch System Image
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
  • T1665 - Hide Infrastructure
MITREへのリンク →

Andariel

Score: 10.67
Matched TTPs:
  • T1583.006 - Web Services
  • T1187 - Forced Authentication
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Storm-0501

Score: 13.92
Matched TTPs:
  • T1583.006 - Web Services
  • T1027.014 - Polymorphic Code
  • T1102.002 - Bidirectional Communication
  • T1506 - Web Session Cookie
  • T1090.004 - Domain Fronting
MITREへのリンク →

ToddyCat

Score: 6.25
Matched TTPs:
  • T1583.006 - Web Services
  • T1506 - Web Session Cookie
  • T1665 - Hide Infrastructure
MITREへのリンク →

APT37

Score: 9.11
Matched TTPs:
  • T1583.006 - Web Services
  • T1059.011 - Lua
  • T1218.010 - Regsvr32
  • T1562.011 - Spoof Security Alerting
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

GALLIUM

Score: 11.92
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1174 - Password Filter DLL
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Confucius

Score: 10.23
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
  • T1200 - Hardware Additions
  • T1547.013 - XDG Autostart Entries
  • T1665 - Hide Infrastructure
MITREへのリンク →

FIN8

Score: 8.13
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

BackdoorDiplomacy

Score: 3.91
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

FIN6

Score: 5.46
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1128 - Netsh Helper DLL
  • T1601.001 - Patch System Image
MITREへのリンク →

Sea Turtle

Score: 5.96
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1218.010 - Regsvr32
  • T1059.013 - Container CLI/API
MITREへのリンク →

APT-C-36

Score: 3.91
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Cobalt Group

Score: 12.37
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Aquatic Panda

Score: 8.13
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1506 - Web Session Cookie
  • T1601.001 - Patch System Image
  • T1668 - Exclusive Control
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Silence

Score: 3.49
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

DarkHydrus

Score: 4.00
Matched TTPs:
  • T1199 - Trusted Relationship
  • T1200 - Hardware Additions
MITREへのリンク →

Sowbug

Score: 3.03
Matched TTPs:
  • T1542.004 - ROMMONkit
MITREへのリンク →

Daggerfly

Score: 4.06
Matched TTPs:
  • T1174 - Password Filter DLL
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

The White Company

Score: 3.39
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1506 - Web Session Cookie
MITREへのリンク →

Volatile Cedar

Score: 4.91
Matched TTPs:
  • T1002 - Data Compressed
  • T1547.013 - XDG Autostart Entries
MITREへのリンク →

Velvet Ant

Score: 6.88
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Gamaredon Group

Score: 0.81
Matched TTPs:
  • T1205 - Traffic Signaling
  • T1562.010 - Downgrade Attack
  • T1087.004 - Cloud Account
  • T1061 - Graphical User Interface
  • T1608 - Stage Capabilities
  • T1506 - Web Session Cookie
  • T1546.017 - Udev Rules
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1059.013 - Container CLI/API
  • T1583.006 - Web Services
  • T1091 - Replication Through Removable Media
  • T1542.004 - ROMMONkit
  • T1059.010 - AutoHotKey & AutoIT
  • T1200 - Hardware Additions
MITREへのリンク →

Kimsuky

Score: 0.80
Matched TTPs:
  • T1205 - Traffic Signaling
  • T1606.002 - SAML Tokens
  • T1665 - Hide Infrastructure
  • T1057 - Process Discovery
  • T1087.004 - Cloud Account
  • T1566.002 - Spearphishing Link
  • T1608 - Stage Capabilities
  • T1683.001 - Written Content
  • T1506 - Web Session Cookie
  • T1027.014 - Polymorphic Code
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
  • T1668 - Exclusive Control
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1583.006 - Web Services
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
MITREへのリンク →

Contagious Interview

Score: 0.70
Matched TTPs:
  • T1064 - Scripting
  • T1606.002 - SAML Tokens
  • T1562.010 - Downgrade Attack
  • T1491.002 - External Defacement
  • T1087.004 - Cloud Account
  • T1221 - Template Injection
  • T1601.001 - Patch System Image
  • T1021.006 - Windows Remote Management
  • T1558 - Steal or Forge Kerberos Tickets
  • T1199 - Trusted Relationship
  • T1218.008 - Odbcconf
  • T1044 - File System Permissions Weakness
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Lazarus Group

Score: 0.70
Matched TTPs:
  • T1205 - Traffic Signaling
  • T1606.002 - SAML Tokens
  • T1665 - Hide Infrastructure
  • T1218.010 - Regsvr32
  • T1057 - Process Discovery
  • T1491.002 - External Defacement
  • T1087.004 - Cloud Account
  • T1547.013 - XDG Autostart Entries
  • T1174 - Password Filter DLL
  • T1199 - Trusted Relationship
  • T1055.015 - ListPlanting
  • T1583.006 - Web Services
  • T1055.005 - Thread Local Storage
  • T1059.010 - AutoHotKey & AutoIT
  • T1132.001 - Standard Encoding
MITREへのリンク →

Mustang Panda

Score: 0.63
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1169 - Sudo
  • T1218.010 - Regsvr32
  • T1087.004 - Cloud Account
  • T1566.002 - Spearphishing Link
  • T1013 - Port Monitors
  • T1608 - Stage Capabilities
  • T1547.013 - XDG Autostart Entries
  • T1199 - Trusted Relationship
  • T1059.011 - Lua
  • T1583.006 - Web Services
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
  • T1055.005 - Thread Local Storage
MITREへのリンク →

Sandworm Team

Score: 0.62
Matched TTPs:
  • T1187 - Forced Authentication
  • T1193 - Spearphishing Attachment
  • T1606.002 - SAML Tokens
  • T1218.010 - Regsvr32
  • T1087.004 - Cloud Account
  • T1566.002 - Spearphishing Link
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
  • T1199 - Trusted Relationship
  • T1558 - Steal or Forge Kerberos Tickets
  • T1059.011 - Lua
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
  • T1005 - Data from Local System
MITREへのリンク →

APT28

Score: 0.60
Matched TTPs:
  • T1566.003 - Spearphishing via Service
  • T1218.010 - Regsvr32
  • T1057 - Process Discovery
  • T1491.002 - External Defacement
  • T1566.002 - Spearphishing Link
  • T1547.013 - XDG Autostart Entries
  • T1668 - Exclusive Control
  • T1199 - Trusted Relationship
  • T1558 - Steal or Forge Kerberos Tickets
  • T1583.006 - Web Services
  • T1542.004 - ROMMONkit
  • T1059.010 - AutoHotKey & AutoIT
  • T1200 - Hardware Additions
MITREへのリンク →

OilRig

Score: 0.56
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1606.002 - SAML Tokens
  • T1592.002 - Software
  • T1218.010 - Regsvr32
  • T1491.002 - External Defacement
  • T1547.013 - XDG Autostart Entries
  • T1199 - Trusted Relationship
  • T1558 - Steal or Forge Kerberos Tickets
  • T1055.015 - ListPlanting
  • T1583.006 - Web Services
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
  • T1005 - Data from Local System
MITREへのリンク →

FIN7

Score: 0.56
Matched TTPs:
  • T1205 - Traffic Signaling
  • T1606.002 - SAML Tokens
  • T1057 - Process Discovery
  • T1583.006 - Web Services
  • T1601.001 - Patch System Image
  • T1547.013 - XDG Autostart Entries
  • T1199 - Trusted Relationship
  • T1055.015 - ListPlanting
  • T1011.001 - Exfiltration Over Bluetooth
  • T1091 - Replication Through Removable Media
  • T1059.010 - AutoHotKey & AutoIT
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る