Trusted Design

Covert Channels and Poor Decisions: The Tale of DNSMessenger

概要

(Cisco) What initially drew our interest to this particular malware sample was a tweet published by security researcher on Twitter (thanks simpo!) regarding a Powershell script that he was analyzing that contained the base64 encoded string 'SourceFireSux'. Interestingly enough, Sourcefire was the only security vendor directly referenced in the Powershell script. We searched for the base64 encoded value which was referenced in the tweet, and were able to identify a sample that had been uploaded to the public malware analysis sandbox, Hybrid Analysis. Additionally, when we searched for the decoded string value we found a single search engine result that pointed to a Pastebin page. The hash listed in the Pastebin led us to a malicious Word document that had also been uploaded to a public sandbox. The Word document initiated the same multiple-stage infection process as the file from the Hybrid Analysis report we previously discovered and allowed us to reconstruct a more complete infection process.

Created: 2026-02-23

Indicators

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Lazarus Group

Score: 36.31
Matched TTPs:
  • T1027.009 - Embedded Payloads
  • T1027.013 - Encrypted/Encoded File
  • T1587.001 - Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1620 - Reflective Code Loading
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1027.007 - Dynamic API Resolution
  • T1008 - Fallback Channels
  • T1680 - Local Storage Discovery
MITREへのリンク →

TA577

Score: 3.84
Matched TTPs:
  • T1027.009 - Embedded Payloads
MITREへのリンク →

Moonstone Sleet

Score: 19.88
Matched TTPs:
  • T1027.009 - Embedded Payloads
  • T1027.013 - Encrypted/Encoded File
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1591 - Gather Victim Org Information
  • T1027 - Obfuscated Files or Information
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Turla

Score: 15.11
Matched TTPs:
  • T1564.012 - File/Path Exclusions
  • T1587.001 - Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Contagious Interview

Score: 37.28
Matched TTPs:
  • T1588.007 - Artificial Intelligence
  • T1027.013 - Encrypted/Encoded File
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1681 - Search Threat Vendor Data
  • T1593.003 - Code Repositories
  • T1497 - Virtualization/Sandbox Evasion
  • T1480 - Execution Guardrails
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1027.010 - Command Obfuscation
  • T1204.004 - Malicious Copy and Paste
MITREへのリンク →

Inception

Score: 11.35
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
MITREへのリンク →

Elderwood

Score: 3.86
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Darkhotel

Score: 12.69
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1497 - Virtualization/Sandbox Evasion
  • T1057 - Process Discovery
  • T1203 - Exploitation for Client Execution
  • T1518.001 - Security Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Transparent Tribe

Score: 3.09
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT28

Score: 28.79
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1036 - Masquerading
  • T1057 - Process Discovery
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Leviathan

Score: 16.34
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1041 - Exfiltration Over C2 Channel
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1027.003 - Steganography
  • T1105 - Ingress Tool Transfer
  • T1027.015 - Compression
MITREへのリンク →

Sidewinder

Score: 15.22
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1598.003 - Spearphishing Link
  • T1598.002 - Spearphishing Attachment
  • T1057 - Process Discovery
  • T1203 - Exploitation for Client Execution
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT39

Score: 6.76
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Saint Bear

Score: 8.90
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1608.001 - Upload Malware
  • T1497 - Virtualization/Sandbox Evasion
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT33

Score: 4.71
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

BITTER

Score: 6.69
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TA505

Score: 11.91
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1069 - Permission Groups Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Higaisa

Score: 14.13
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1203 - Exploitation for Client Execution
  • T1680 - Local Storage Discovery
  • T1027.015 - Compression
MITREへのリンク →

APT19

Score: 8.62
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Fox Kitten

Score: 11.11
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1039 - Data from Network Shared Drive
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
  • T1213.005 - Messaging Applications
MITREへのリンク →

Threat Group-3390

Score: 15.54
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1608.002 - Upload Tool
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1027.015 - Compression
MITREへのリンク →

TA2541

Score: 12.99
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1518.001 - Security Software Discovery
  • T1105 - Ingress Tool Transfer
  • T1027.015 - Compression
MITREへのリンク →

Malteiro

Score: 8.68
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1614.001 - System Language Discovery
  • T1518.001 - Security Software Discovery
MITREへのリンク →

Magic Hound

Score: 12.90
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1598.003 - Spearphishing Link
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1592.002 - Software
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Storm-1811

Score: 6.97
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Blue Mockingbird

Score: 9.73
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1574.012 - COR_PROFILER
MITREへのリンク →

Tropic Trooper

Score: 20.61
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1027.003 - Steganography
  • T1518.001 - Security Software Discovery
  • T1221 - Template Injection
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

Mofang

Score: 4.75
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1027.015 - Compression
MITREへのリンク →

Whitefly

Score: 3.22
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

menuPass

Score: 13.29
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1036.003 - Rename Legitimate Utilities
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Moses Staff

Score: 5.31
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

TeamTNT

Score: 16.44
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1587.001 - Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1057 - Process Discovery
  • T1518.001 - Security Software Discovery
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

Metador

Score: 3.22
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

OilRig

Score: 28.62
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1587.001 - Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1036 - Masquerading
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1137.004 - Outlook Home Page
  • T1573.002 - Asymmetric Cryptography
  • T1105 - Ingress Tool Transfer
  • T1008 - Fallback Channels
MITREへのリンク →

APT32

Score: 23.95
Matched TTPs:
  • T1027.013 - Encrypted/Encoded File
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT41

Score: 23.14
Matched TTPs:
  • T1568.002 - Domain Generation Algorithms
  • T1069 - Permission Groups Discovery
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1203 - Exploitation for Client Execution
  • T1595.003 - Wordlist Scanning
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1008 - Fallback Channels
MITREへのリンク →

TA551

Score: 14.74
Matched TTPs:
  • T1568.002 - Domain Generation Algorithms
  • T1036 - Masquerading
  • T1218.010 - Regsvr32
  • T1027.003 - Steganography
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Scattered Spider

Score: 20.94
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1598.003 - Spearphishing Link
  • T1074 - Data Staged
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1556.009 - Conditional Access Policies
  • T1105 - Ingress Tool Transfer
  • T1213.005 - Messaging Applications
MITREへのリンク →

Volt Typhoon

Score: 21.58
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1036.008 - Masquerade File Type
  • T1140 - Deobfuscate/Decode Files or Information
  • T1074 - Data Staged
  • T1057 - Process Discovery
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

APT3

Score: 11.33
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1027 - Obfuscated Files or Information
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN13

Score: 13.51
Matched TTPs:
  • T1069 - Permission Groups Discovery
  • T1587.001 - Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

BlackByte

Score: 19.50
Matched TTPs:
  • T1036.008 - Masquerade File Type
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1480 - Execution Guardrails
  • T1041 - Exfiltration Over C2 Channel
  • T1614.001 - System Language Discovery
  • T1518.001 - Security Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Mustang Panda

Score: 33.35
Matched TTPs:
  • T1036.008 - Masquerade File Type
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1027.012 - LNK Icon Smuggling
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1678 - Delay Execution
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

Kimsuky

Score: 42.88
Matched TTPs:
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1620 - Reflective Code Loading
  • T1593.002 - Search Engines
  • T1027.012 - LNK Icon Smuggling
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1218.010 - Regsvr32
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

UNC3886

Score: 12.68
Matched TTPs:
  • T1587.001 - Malware
  • T1681 - Search Threat Vendor Data
  • T1057 - Process Discovery
  • T1203 - Exploitation for Client Execution
  • T1008 - Fallback Channels
MITREへのリンク →

LuminousMoth

Score: 7.67
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Sandworm Team

Score: 31.06
Matched TTPs:
  • T1587.001 - Malware
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1036 - Masquerading
  • T1591.002 - Business Relationships
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

APT29

Score: 9.75
Matched TTPs:
  • T1587.001 - Malware
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1027.006 - HTML Smuggling
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Play

Score: 9.00
Matched TTPs:
  • T1587.001 - Malware
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Aoqin Dragon

Score: 6.62
Matched TTPs:
  • T1587.001 - Malware
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

RedCurl

Score: 10.16
Matched TTPs:
  • T1587.001 - Malware
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Ke3chang

Score: 14.69
Matched TTPs:
  • T1587.001 - Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1614.001 - System Language Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN7

Score: 25.53
Matched TTPs:
  • T1587.001 - Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1620 - Reflective Code Loading
  • T1674 - Input Injection
  • T1057 - Process Discovery
  • T1591 - Gather Victim Org Information
  • T1588.002 - Tool
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
  • T1008 - Fallback Channels
MITREへのリンク →

Silent Librarian

Score: 3.31
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1588.002 - Tool
MITREへのリンク →

ZIRCONIUM

Score: 8.96
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1140 - Deobfuscate/Decode Files or Information
  • T1036 - Masquerading
  • T1041 - Exfiltration Over C2 Channel
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Star Blizzard

Score: 8.90
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
  • T1588.002 - Tool
MITREへのリンク →

CURIUM

Score: 4.43
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

Dragonfly

Score: 16.20
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1591.002 - Business Relationships
  • T1598.002 - Spearphishing Attachment
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Patchwork

Score: 12.17
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

BRONZE BUTLER

Score: 12.94
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1036 - Masquerading
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1203 - Exploitation for Client Execution
  • T1027.003 - Steganography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

WIRTE

Score: 5.94
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Gorgon Group

Score: 3.19
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Agrius

Score: 5.73
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1036 - Masquerading
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

APT38

Score: 9.90
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1036.003 - Rename Legitimate Utilities
  • T1518.001 - Security Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Molerats

Score: 7.01
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1105 - Ingress Tool Transfer
  • T1027.015 - Compression
MITREへのリンク →

Earth Lusca

Score: 11.23
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1027.003 - Steganography
MITREへのリンク →

MuddyWater

Score: 18.60
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1027.003 - Steganography
  • T1027.004 - Compile After Delivery
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Gamaredon Group

Score: 43.51
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1608.001 - Upload Malware
  • T1620 - Reflective Code Loading
  • T1480 - Execution Guardrails
  • T1027.012 - LNK Icon Smuggling
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1001 - Data Obfuscation
  • T1039 - Data from Network Shared Drive
  • T1027 - Obfuscated Files or Information
  • T1027.004 - Compile After Delivery
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1221 - Template Injection
  • T1105 - Ingress Tool Transfer
  • T1027.015 - Compression
MITREへのリンク →

Winter Vivern

Score: 6.50
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1036 - Masquerading
  • T1041 - Exfiltration Over C2 Channel
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Cinnamon Tempest

Score: 3.19
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Rocke

Score: 11.67
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
  • T1027.004 - Compile After Delivery
  • T1518.001 - Security Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Mustard Tempest

Score: 7.29
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1608.006 - SEO Poisoning
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

LazyScripter

Score: 6.80
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036 - Masquerading
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

SideCopy

Score: 8.27
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1598.002 - Spearphishing Attachment
  • T1518.001 - Security Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

HEXANE

Score: 6.98
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT42

Score: 7.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1518.001 - Security Software Discovery
MITREへのリンク →

Ember Bear

Score: 10.27
Matched TTPs:
  • T1195 - Supply Chain Compromise
  • T1036 - Masquerading
  • T1203 - Exploitation for Client Execution
  • T1550.002 - Pass the Hash
MITREへのリンク →

Windshift

Score: 8.67
Matched TTPs:
  • T1036 - Masquerading
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
  • T1518.001 - Security Software Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Wizard Spider

Score: 18.27
Matched TTPs:
  • T1518.002 - Backup Software Discovery
  • T1074 - Data Staged
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Medusa Group

Score: 18.32
Matched TTPs:
  • T1608.002 - Upload Tool
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
  • T1218.014 - MMC
MITREへのリンク →

LAPSUS$

Score: 12.38
Matched TTPs:
  • T1591.002 - Business Relationships
  • T1593.003 - Code Repositories
  • T1588.002 - Tool
  • T1213.005 - Messaging Applications
MITREへのリンク →

HAFNIUM

Score: 6.14
Matched TTPs:
  • T1593.003 - Code Repositories
  • T1057 - Process Discovery
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

INC Ransom

Score: 5.25
Matched TTPs:
  • T1074 - Data Staged
  • T1588.002 - Tool
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Deep Panda

Score: 4.26
Matched TTPs:
  • T1057 - Process Discovery
  • T1218.010 - Regsvr32
MITREへのリンク →

APT1

Score: 5.11
Matched TTPs:
  • T1057 - Process Discovery
  • T1588.002 - Tool
  • T1550.002 - Pass the Hash
MITREへのリンク →

Stealth Falcon

Score: 3.49
Matched TTPs:
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

Chimera

Score: 15.59
Matched TTPs:
  • T1057 - Process Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1039 - Data from Network Shared Drive
  • T1027.010 - Command Obfuscation
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

Andariel

Score: 10.67
Matched TTPs:
  • T1057 - Process Discovery
  • T1592.002 - Software
  • T1203 - Exploitation for Client Execution
  • T1027.003 - Steganography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Storm-0501

Score: 13.92
Matched TTPs:
  • T1057 - Process Discovery
  • T1218.010 - Regsvr32
  • T1614.001 - System Language Discovery
  • T1518.001 - Security Software Discovery
  • T1556.009 - Conditional Access Policies
MITREへのリンク →

ToddyCat

Score: 6.25
Matched TTPs:
  • T1057 - Process Discovery
  • T1518.001 - Security Software Discovery
  • T1680 - Local Storage Discovery
MITREへのリンク →

APT37

Score: 9.11
Matched TTPs:
  • T1057 - Process Discovery
  • T1027 - Obfuscated Files or Information
  • T1203 - Exploitation for Client Execution
  • T1027.003 - Steganography
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

GALLIUM

Score: 11.92
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1036.003 - Rename Legitimate Utilities
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Confucius

Score: 10.23
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1203 - Exploitation for Client Execution
  • T1221 - Template Injection
  • T1105 - Ingress Tool Transfer
  • T1680 - Local Storage Discovery
MITREへのリンク →

FIN8

Score: 8.13
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

BackdoorDiplomacy

Score: 3.91
Matched TTPs:
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN6

Score: 5.46
Matched TTPs:
  • T1588.002 - Tool
  • T1573.002 - Asymmetric Cryptography
  • T1027.010 - Command Obfuscation
MITREへのリンク →

Sea Turtle

Score: 5.96
Matched TTPs:
  • T1588.002 - Tool
  • T1203 - Exploitation for Client Execution
  • T1027.004 - Compile After Delivery
MITREへのリンク →

APT-C-36

Score: 3.91
Matched TTPs:
  • T1588.002 - Tool
  • T1027 - Obfuscated Files or Information
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Cobalt Group

Score: 12.37
Matched TTPs:
  • T1588.002 - Tool
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Aquatic Panda

Score: 8.13
Matched TTPs:
  • T1588.002 - Tool
  • T1518.001 - Security Software Discovery
  • T1027.010 - Command Obfuscation
  • T1550.002 - Pass the Hash
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Silence

Score: 3.49
Matched TTPs:
  • T1588.002 - Tool
  • T1027.010 - Command Obfuscation
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

DarkHydrus

Score: 4.00
Matched TTPs:
  • T1588.002 - Tool
  • T1221 - Template Injection
MITREへのリンク →

Sowbug

Score: 3.03
Matched TTPs:
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Daggerfly

Score: 4.06
Matched TTPs:
  • T1036.003 - Rename Legitimate Utilities
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

The White Company

Score: 3.39
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1518.001 - Security Software Discovery
MITREへのリンク →

Volatile Cedar

Score: 4.91
Matched TTPs:
  • T1595.003 - Wordlist Scanning
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Velvet Ant

Score: 6.88
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1564.005 - Hidden File System
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Gamaredon Group

Score: 0.81
Matched TTPs:
  • T1588.002 - Tool
  • T1027.012 - LNK Icon Smuggling
  • T1057 - Process Discovery
  • T1027.004 - Compile After Delivery
  • T1027.015 - Compression
  • T1620 - Reflective Code Loading
  • T1518.001 - Security Software Discovery
  • T1480 - Execution Guardrails
  • T1105 - Ingress Tool Transfer
  • T1041 - Exfiltration Over C2 Channel
  • T1027 - Obfuscated Files or Information
  • T1027.010 - Command Obfuscation
  • T1001 - Data Obfuscation
  • T1221 - Template Injection
  • T1608.001 - Upload Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

Kimsuky

Score: 0.80
Matched TTPs:
  • T1588.002 - Tool
  • T1027.012 - LNK Icon Smuggling
  • T1057 - Process Discovery
  • T1680 - Local Storage Discovery
  • T1620 - Reflective Code Loading
  • T1591 - Gather Victim Org Information
  • T1550.002 - Pass the Hash
  • T1518.001 - Security Software Discovery
  • T1587.001 - Malware
  • T1218.010 - Regsvr32
  • T1105 - Ingress Tool Transfer
  • T1041 - Exfiltration Over C2 Channel
  • T1027 - Obfuscated Files or Information
  • T1027.010 - Command Obfuscation
  • T1593.002 - Search Engines
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Contagious Interview

Score: 0.70
Matched TTPs:
  • T1588.002 - Tool
  • T1588.007 - Artificial Intelligence
  • T1204.004 - Malicious Copy and Paste
  • T1593.003 - Code Repositories
  • T1587.001 - Malware
  • T1480 - Execution Guardrails
  • T1036 - Masquerading
  • T1497 - Virtualization/Sandbox Evasion
  • T1041 - Exfiltration Over C2 Channel
  • T1027.010 - Command Obfuscation
  • T1681 - Search Threat Vendor Data
  • T1027.013 - Encrypted/Encoded File
  • T1608.001 - Upload Malware
MITREへのリンク →

Lazarus Group

Score: 0.70
Matched TTPs:
  • T1588.002 - Tool
  • T1057 - Process Discovery
  • T1680 - Local Storage Discovery
  • T1027.009 - Embedded Payloads
  • T1027.007 - Dynamic API Resolution
  • T1620 - Reflective Code Loading
  • T1591 - Gather Victim Org Information
  • T1036.003 - Rename Legitimate Utilities
  • T1203 - Exploitation for Client Execution
  • T1587.001 - Malware
  • T1105 - Ingress Tool Transfer
  • T1041 - Exfiltration Over C2 Channel
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1008 - Fallback Channels
MITREへのリンク →

Mustang Panda

Score: 0.63
Matched TTPs:
  • T1588.002 - Tool
  • T1027.012 - LNK Icon Smuggling
  • T1057 - Process Discovery
  • T1027.007 - Dynamic API Resolution
  • T1678 - Delay Execution
  • T1203 - Exploitation for Client Execution
  • T1587.001 - Malware
  • T1105 - Ingress Tool Transfer
  • T1036.008 - Masquerade File Type
  • T1041 - Exfiltration Over C2 Channel
  • T1027 - Obfuscated Files or Information
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Sandworm Team

Score: 0.62
Matched TTPs:
  • T1588.002 - Tool
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1592.002 - Software
  • T1587.001 - Malware
  • T1105 - Ingress Tool Transfer
  • T1036 - Masquerading
  • T1591.002 - Business Relationships
  • T1041 - Exfiltration Over C2 Channel
  • T1027 - Obfuscated Files or Information
  • T1027.010 - Command Obfuscation
  • T1598.003 - Spearphishing Link
  • T1608.001 - Upload Malware
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

APT28

Score: 0.60
Matched TTPs:
  • T1588.002 - Tool
  • T1057 - Process Discovery
  • T1591 - Gather Victim Org Information
  • T1550.002 - Pass the Hash
  • T1203 - Exploitation for Client Execution
  • T1105 - Ingress Tool Transfer
  • T1036 - Masquerading
  • T1211 - Exploitation for Defense Evasion
  • T1221 - Template Injection
  • T1598.003 - Spearphishing Link
  • T1027.013 - Encrypted/Encoded File
  • T1140 - Deobfuscate/Decode Files or Information
  • T1039 - Data from Network Shared Drive
MITREへのリンク →

OilRig

Score: 0.56
Matched TTPs:
  • T1588.002 - Tool
  • T1057 - Process Discovery
  • T1137.004 - Outlook Home Page
  • T1573.002 - Asymmetric Cryptography
  • T1203 - Exploitation for Client Execution
  • T1587.001 - Malware
  • T1105 - Ingress Tool Transfer
  • T1036 - Masquerading
  • T1195 - Supply Chain Compromise
  • T1027.013 - Encrypted/Encoded File
  • T1608.001 - Upload Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1008 - Fallback Channels
MITREへのリンク →

FIN7

Score: 0.56
Matched TTPs:
  • T1588.002 - Tool
  • T1057 - Process Discovery
  • T1674 - Input Injection
  • T1620 - Reflective Code Loading
  • T1591 - Gather Victim Org Information
  • T1587.001 - Malware
  • T1105 - Ingress Tool Transfer
  • T1027.010 - Command Obfuscation
  • T1608.001 - Upload Malware
  • T1140 - Deobfuscate/Decode Files or Information
  • T1008 - Fallback Channels
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る