Trusted Design

EngineBox Malware Supports 10+ Brazilian Banks - SANS Internet Storm Center

概要

After receiving quite a big amount of malspam with similar messages in my honeypots this week, I decided to dedicate some time to analyze what it was about. To my surprise, after peeling multiple encoding layers protecting the malware’s core (felt like peeling an onion), I could finally find a sophisticated and well structured banker malware capable of stealing victims' credentials of at least 10 of the biggest Brazilian public and private banks and other financial institutions. Additionally, it can also steal browser, SSH and FTP local stored credentials. The main malware capabilities include a privilege escalation attempt using MS16–032 exploitation; a HTTP Proxy to intercept banking transactions; a backdoor to make it possible for the attacker to issue arbitrary remote commands and a C&C through a IRC channel. As it's being identified as a "Generic Trojan" by most of VirusTotal (VT) engines, let's name it "EngineBox"— the core malware class I saw after reverse engineering it.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 40.91
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.001 - Malware
  • T1552.003 - Shell History
  • T1087.004 - Cloud Account
  • T1027.014 - Polymorphic Code
  • T1197 - BITS Jobs
  • T1565.002 - Transmitted Data Manipulation
  • T1556.005 - Reversible Encryption
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
  • T1126 - Network Share Connection Removal
  • T1003.003 - NTDS
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Sea Turtle

Score: 9.85
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Ember Bear

Score: 19.18
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

Indrik Spider

Score: 6.78
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1622 - Debugger Evasion
MITREへのリンク →

Agrius

Score: 8.12
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Contagious Interview

Score: 18.37
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1552.003 - Shell History
  • T1087.004 - Cloud Account
  • T1565.002 - Transmitted Data Manipulation
  • T1126 - Network Share Connection Removal
MITREへのリンク →

Sandworm Team

Score: 17.07
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Star Blizzard

Score: 5.01
Matched TTPs:
  • T1033 - System Owner/User Discovery
  • T1091 - Replication Through Removable Media
MITREへのリンク →

Mustard Tempest

Score: 12.81
Matched TTPs:
  • T1682 - Query Public AI Services
  • T1091 - Replication Through Removable Media
  • T1059.012 - Hypervisor CLI
  • T1543.002 - Systemd Service
MITREへのリンク →

FIN13

Score: 11.02
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.001 - Malware
  • T1552.003 - Shell History
  • T1556.005 - Reversible Encryption
  • T1622 - Debugger Evasion
MITREへのリンク →

Moonstone Sleet

Score: 15.83
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1491 - Defacement
  • T1197 - BITS Jobs
  • T1556.005 - Reversible Encryption
  • T1126 - Network Share Connection Removal
MITREへのリンク →

Lazarus Group

Score: 22.60
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1677 - Poisoned Pipeline Execution
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1055.005 - Thread Local Storage
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

OilRig

Score: 21.76
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1005 - Data from Local System
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1556.009 - Conditional Access Policies
  • T1556.005 - Reversible Encryption
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
MITREへのリンク →

UNC3886

Score: 16.34
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1588.001 - Malware
  • T1547.015 - Login Items
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

LuminousMoth

Score: 9.69
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1087.004 - Cloud Account
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Salt Typhoon

Score: 3.57
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

APT29

Score: 16.11
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1592.004 - Client Configurations
  • T1218.010 - Regsvr32
  • T1218.009 - Regsvcs/Regasm
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Play

Score: 8.75
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Aoqin Dragon

Score: 3.59
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1218.010 - Regsvr32
MITREへのリンク →

RedCurl

Score: 6.03
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Moses Staff

Score: 3.57
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →

Turla

Score: 20.01
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1136.002 - Domain Account
  • T1218.001 - Compiled HTML File
  • T1556.009 - Conditional Access Policies
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1578.001 - Create Snapshot
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Ke3chang

Score: 6.73
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Mustang Panda

Score: 22.56
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1677 - Poisoned Pipeline Execution
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
  • T1565.002 - Transmitted Data Manipulation
  • T1556.005 - Reversible Encryption
  • T1526 - Cloud Service Discovery
  • T1055.005 - Thread Local Storage
MITREへのリンク →

TeamTNT

Score: 8.70
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1535 - Unused/Unsupported Cloud Regions
  • T1556.005 - Reversible Encryption
MITREへのリンク →

FIN7

Score: 21.82
Matched TTPs:
  • T1606.002 - SAML Tokens
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1011.001 - Exfiltration Over Bluetooth
  • T1588.001 - Malware
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
  • T1490 - Inhibit System Recovery
MITREへのリンク →

TA2541

Score: 7.18
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1128 - Netsh Helper DLL
MITREへのリンク →

Earth Lusca

Score: 14.03
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1059.001 - PowerShell
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

LazyScripter

Score: 4.43
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
MITREへのリンク →

Gamaredon Group

Score: 9.67
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1087.004 - Cloud Account
  • T1061 - Graphical User Interface
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Threat Group-3390

Score: 13.79
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1526 - Cloud Service Discovery
MITREへのリンク →

SideCopy

Score: 6.11
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1584.002 - DNS Server
MITREへのリンク →

TA505

Score: 5.62
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1136.002 - Domain Account
  • T1556.005 - Reversible Encryption
MITREへのリンク →

BlackByte

Score: 8.25
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1556.005 - Reversible Encryption
  • T1622 - Debugger Evasion
MITREへのリンク →

BITTER

Score: 6.75
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT32

Score: 19.75
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1592.004 - Client Configurations
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1490 - Inhibit System Recovery
MITREへのリンク →

HEXANE

Score: 3.62
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1622 - Debugger Evasion
MITREへのリンク →

Saint Bear

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1218.010 - Regsvr32
MITREへのリンク →

APT42

Score: 9.53
Matched TTPs:
  • T1091 - Replication Through Removable Media
  • T1677 - Poisoned Pipeline Execution
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Rocke

Score: 6.10
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1535 - Unused/Unsupported Cloud Regions
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Volt Typhoon

Score: 16.57
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1491 - Defacement
  • T1535 - Unused/Unsupported Cloud Regions
  • T1584.002 - DNS Server
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

APT28

Score: 19.67
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1592.003 - Firmware
  • T1218.010 - Regsvr32
  • T1197 - BITS Jobs
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

BackdoorDiplomacy

Score: 6.02
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1136.002 - Domain Account
  • T1588.001 - Malware
MITREへのリンク →

BlackTech

Score: 6.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1526 - Cloud Service Discovery
MITREへのリンク →

Magic Hound

Score: 11.61
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.001 - Malware
  • T1592.003 - Firmware
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1622 - Debugger Evasion
MITREへのリンク →

Medusa Group

Score: 14.11
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1128 - Netsh Helper DLL
  • T1598 - Phishing for Information
  • T1556.005 - Reversible Encryption
  • T1622 - Debugger Evasion
MITREへのリンク →

Storm-0501

Score: 19.34
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1535 - Unused/Unsupported Cloud Regions
  • T1588.001 - Malware
  • T1552.003 - Shell History
  • T1027.014 - Polymorphic Code
  • T1090.004 - Domain Fronting
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

Fox Kitten

Score: 11.24
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1491 - Defacement
  • T1588.001 - Malware
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
MITREへのリンク →

Cinnamon Tempest

Score: 3.99
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
MITREへのリンク →

menuPass

Score: 5.86
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
MITREへのリンク →

Blue Mockingbird

Score: 5.86
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.014 - Polymorphic Code
  • T1622 - Debugger Evasion
MITREへのリンク →

GALLIUM

Score: 3.44
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
MITREへのリンク →

Winter Vivern

Score: 16.65
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1548 - Abuse Elevation Control Mechanism
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Leviathan

Score: 14.53
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1027.014 - Polymorphic Code
  • T1592.003 - Firmware
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
MITREへのリンク →

INC Ransom

Score: 5.64
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1552.003 - Shell History
  • T1622 - Debugger Evasion
MITREへのリンク →

Dragonfly

Score: 9.12
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
MITREへのリンク →

Axiom

Score: 10.91
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
  • T1160 - Launch Daemon
MITREへのリンク →

APT41

Score: 7.89
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1588.001 - Malware
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
  • T1622 - Debugger Evasion
MITREへのリンク →

HAFNIUM

Score: 5.32
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1556.005 - Reversible Encryption
  • T1490 - Inhibit System Recovery
MITREへのリンク →

APT5

Score: 6.74
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1677 - Poisoned Pipeline Execution
  • T1622 - Debugger Evasion
MITREへのリンク →

MuddyWater

Score: 8.87
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT39

Score: 6.28
Matched TTPs:
  • T1140 - Deobfuscate/Decode Files or Information
  • T1087.004 - Cloud Account
  • T1556.005 - Reversible Encryption
  • T1622 - Debugger Evasion
MITREへのリンク →

APT38

Score: 6.24
Matched TTPs:
  • T1491 - Defacement
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Scattered Spider

Score: 25.83
Matched TTPs:
  • T1491 - Defacement
  • T1535 - Unused/Unsupported Cloud Regions
  • T1136.002 - Domain Account
  • T1552.003 - Shell History
  • T1087.004 - Cloud Account
  • T1197 - BITS Jobs
  • T1090.004 - Domain Fronting
  • T1565.002 - Transmitted Data Manipulation
  • T1622 - Debugger Evasion
MITREへのリンク →

Chimera

Score: 14.13
Matched TTPs:
  • T1491 - Defacement
  • T1087.004 - Cloud Account
  • T1592.003 - Firmware
  • T1556.005 - Reversible Encryption
  • T1622 - Debugger Evasion
  • T1578.001 - Create Snapshot
MITREへのリンク →

LAPSUS$

Score: 5.90
Matched TTPs:
  • T1136.002 - Domain Account
  • T1592.003 - Firmware
MITREへのリンク →

Metador

Score: 3.65
Matched TTPs:
  • T1136.002 - Domain Account
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT1

Score: 4.11
Matched TTPs:
  • T1136.002 - Domain Account
  • T1622 - Debugger Evasion
MITREへのリンク →

Aquatic Panda

Score: 6.20
Matched TTPs:
  • T1136.002 - Domain Account
  • T1588.001 - Malware
  • T1622 - Debugger Evasion
MITREへのリンク →

Andariel

Score: 5.72
Matched TTPs:
  • T1136.002 - Domain Account
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

BRONZE BUTLER

Score: 10.88
Matched TTPs:
  • T1592.004 - Client Configurations
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
  • T1578.001 - Create Snapshot
MITREへのリンク →

Wizard Spider

Score: 16.42
Matched TTPs:
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1059.001 - PowerShell
  • T1556.009 - Conditional Access Policies
  • T1556.005 - Reversible Encryption
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
MITREへのリンク →

FIN6

Score: 6.49
Matched TTPs:
  • T1588.001 - Malware
  • T1128 - Netsh Helper DLL
  • T1622 - Debugger Evasion
MITREへのリンク →

PROMETHIUM

Score: 10.66
Matched TTPs:
  • T1588.001 - Malware
  • T1547.015 - Login Items
  • T1059.012 - Hypervisor CLI
  • T1490 - Inhibit System Recovery
MITREへのリンク →

ZIRCONIUM

Score: 10.10
Matched TTPs:
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1197 - BITS Jobs
  • T1578.001 - Create Snapshot
MITREへのリンク →

Higaisa

Score: 9.34
Matched TTPs:
  • T1588.001 - Malware
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
  • T1578.001 - Create Snapshot
MITREへのリンク →

Akira

Score: 4.17
Matched TTPs:
  • T1552.003 - Shell History
  • T1622 - Debugger Evasion
MITREへのリンク →

SilverTerrier

Score: 3.71
Matched TTPs:
  • T1552.003 - Shell History
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT3

Score: 5.11
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

Confucius

Score: 4.65
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Stealth Falcon

Score: 6.78
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1556.009 - Conditional Access Policies
  • T1556.005 - Reversible Encryption
MITREへのリンク →

CURIUM

Score: 9.95
Matched TTPs:
  • T1087.004 - Cloud Account
  • T1218.001 - Compiled HTML File
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
MITREへのリンク →

Tonto Team

Score: 4.24
Matched TTPs:
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
MITREへのリンク →

TA551

Score: 3.93
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Cobalt Group

Score: 9.82
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
  • T1622 - Debugger Evasion
MITREへのリンク →

Inception

Score: 5.43
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
MITREへのリンク →

WIRTE

Score: 3.93
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1556.005 - Reversible Encryption
MITREへのリンク →

APT19

Score: 5.70
Matched TTPs:
  • T1027.014 - Polymorphic Code
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Sidewinder

Score: 5.27
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1556.005 - Reversible Encryption
  • T1578.001 - Create Snapshot
MITREへのリンク →

The White Company

Score: 4.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1578.001 - Create Snapshot
MITREへのリンク →

Patchwork

Score: 4.91
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1622 - Debugger Evasion
MITREへのリンク →

APT37

Score: 4.45
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1556.005 - Reversible Encryption
MITREへのリンク →

Transparent Tribe

Score: 3.26
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Tropic Trooper

Score: 8.09
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Elderwood

Score: 3.26
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Darkhotel

Score: 5.85
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1059.012 - Hypervisor CLI
  • T1578.001 - Create Snapshot
MITREへのリンク →

Velvet Ant

Score: 9.54
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1490 - Inhibit System Recovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

RedEcho

Score: 3.93
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
MITREへのリンク →

FIN8

Score: 8.73
Matched TTPs:
  • T1128 - Netsh Helper DLL
  • T1556.005 - Reversible Encryption
  • T1526 - Cloud Service Discovery
  • T1622 - Debugger Evasion
MITREへのリンク →

RTM

Score: 4.69
Matched TTPs:
  • T1565.002 - Transmitted Data Manipulation
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

FIN10

Score: 4.31
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1490 - Inhibit System Recovery
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.78
Matched TTPs:
  • T1003.003 - NTDS
  • T1622 - Debugger Evasion
  • T1140 - Deobfuscate/Decode Files or Information
  • T1027.014 - Polymorphic Code
  • T1197 - BITS Jobs
  • T1526 - Cloud Service Discovery
  • T1490 - Inhibit System Recovery
  • T1087.004 - Cloud Account
  • T1126 - Network Share Connection Removal
  • T1588.001 - Malware
  • T1606.002 - SAML Tokens
  • T1556.005 - Reversible Encryption
  • T1552.003 - Shell History
  • T1033 - System Owner/User Discovery
  • T1091 - Replication Through Removable Media
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

Scattered Spider

Score: 0.55
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1197 - BITS Jobs
  • T1087.004 - Cloud Account
  • T1491 - Defacement
  • T1535 - Unused/Unsupported Cloud Regions
  • T1552.003 - Shell History
  • T1090.004 - Domain Fronting
  • T1136.002 - Domain Account
  • T1565.002 - Transmitted Data Manipulation
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る