Trusted Design

EngineBox Malware Supports 10+ Brazilian Banks - SANS Internet Storm Center

概要

After receiving quite a big amount of malspam with similar messages in my honeypots this week, I decided to dedicate some time to analyze what it was about. To my surprise, after peeling multiple encoding layers protecting the malware’s core (felt like peeling an onion), I could finally find a sophisticated and well structured banker malware capable of stealing victims' credentials of at least 10 of the biggest Brazilian public and private banks and other financial institutions. Additionally, it can also steal browser, SSH and FTP local stored credentials. The main malware capabilities include a privilege escalation attempt using MS16–032 exploitation; a HTTP Proxy to intercept banking transactions; a backdoor to make it possible for the attacker to issue arbitrary remote commands and a C&C through a IRC channel. As it's being identified as a "Generic Trojan" by most of VirusTotal (VT) engines, let's name it "EngineBox"— the core malware class I saw after reverse engineering it.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Kimsuky

Score: 40.91
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1218.010 - Regsvr32
  • T1598 - Phishing for Information
  • T1219.002 - Remote Desktop Software
  • T1071.001 - Web Protocols
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
  • T1587 - Develop Capabilities
  • T1588.005 - Exploits
  • T1078.003 - Local Accounts
MITREへのリンク →

Sea Turtle

Score: 9.85
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
  • T1078.003 - Local Accounts
MITREへのリンク →

Ember Bear

Score: 19.18
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
  • T1588.005 - Exploits
MITREへのリンク →

Indrik Spider

Score: 6.78
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Agrius

Score: 8.12
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1190 - Exploit Public-Facing Application
  • T1041 - Exfiltration Over C2 Channel
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Contagious Interview

Score: 18.37
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1219.002 - Remote Desktop Software
  • T1587 - Develop Capabilities
MITREへのリンク →

Sandworm Team

Score: 17.07
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1190 - Exploit Public-Facing Application
  • T1041 - Exfiltration Over C2 Channel
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
MITREへのリンク →

Star Blizzard

Score: 5.01
Matched TTPs:
  • T1583 - Acquire Infrastructure
  • T1608.001 - Upload Malware
MITREへのリンク →

Mustard Tempest

Score: 12.81
Matched TTPs:
  • T1583.008 - Malvertising
  • T1608.001 - Upload Malware
  • T1189 - Drive-by Compromise
  • T1608.006 - SEO Poisoning
MITREへのリンク →

FIN13

Score: 11.02
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1071.001 - Web Protocols
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Moonstone Sleet

Score: 15.83
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1217 - Browser Information Discovery
  • T1598 - Phishing for Information
  • T1071.001 - Web Protocols
  • T1587 - Develop Capabilities
MITREへのリンク →

Lazarus Group

Score: 22.60
Matched TTPs:
  • T1587.001 - Malware
  • T1070 - Indicator Removal
  • T1036.004 - Masquerade Task or Service
  • T1041 - Exfiltration Over C2 Channel
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
  • T1027.007 - Dynamic API Resolution
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
MITREへのリンク →

OilRig

Score: 21.76
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1195 - Supply Chain Compromise
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1555.004 - Windows Credential Manager
  • T1071.001 - Web Protocols
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

UNC3886

Score: 16.34
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

LuminousMoth

Score: 9.69
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1041 - Exfiltration Over C2 Channel
  • T1071.001 - Web Protocols
MITREへのリンク →

Salt Typhoon

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

APT29

Score: 16.11
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1090.004 - Domain Fronting
  • T1078.003 - Local Accounts
MITREへのリンク →

Play

Score: 8.75
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1078.003 - Local Accounts
MITREへのリンク →

Aoqin Dragon

Score: 3.59
Matched TTPs:
  • T1587.001 - Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

RedCurl

Score: 6.03
Matched TTPs:
  • T1587.001 - Malware
  • T1573.002 - Asymmetric Cryptography
  • T1071.001 - Web Protocols
MITREへのリンク →

Moses Staff

Score: 3.57
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
MITREへのリンク →

Turla

Score: 20.01
Matched TTPs:
  • T1587.001 - Malware
  • T1588.001 - Malware
  • T1584.006 - Web Services
  • T1555.004 - Windows Credential Manager
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
  • T1124 - System Time Discovery
  • T1078.003 - Local Accounts
MITREへのリンク →

Ke3chang

Score: 6.73
Matched TTPs:
  • T1587.001 - Malware
  • T1190 - Exploit Public-Facing Application
  • T1041 - Exfiltration Over C2 Channel
  • T1071.001 - Web Protocols
MITREへのリンク →

Mustang Panda

Score: 22.56
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1070 - Indicator Removal
  • T1041 - Exfiltration Over C2 Channel
  • T1203 - Exploitation for Client Execution
  • T1219.002 - Remote Desktop Software
  • T1071.001 - Web Protocols
  • T1588.003 - Code Signing Certificates
  • T1027.007 - Dynamic API Resolution
MITREへのリンク →

TeamTNT

Score: 8.70
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1552.004 - Private Keys
  • T1071.001 - Web Protocols
MITREへのリンク →

FIN7

Score: 21.82
Matched TTPs:
  • T1587.001 - Malware
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1674 - Input Injection
  • T1036.004 - Masquerade Task or Service
  • T1210 - Exploitation of Remote Services
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
  • T1078.003 - Local Accounts
MITREへのリンク →

TA2541

Score: 7.18
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1573.002 - Asymmetric Cryptography
MITREへのリンク →

Earth Lusca

Score: 14.03
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1210 - Exploitation of Remote Services
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
MITREへのリンク →

LazyScripter

Score: 4.43
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
MITREへのリンク →

Gamaredon Group

Score: 9.67
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1041 - Exfiltration Over C2 Channel
  • T1001 - Data Obfuscation
  • T1071.001 - Web Protocols
MITREへのリンク →

Threat Group-3390

Score: 13.79
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

SideCopy

Score: 6.11
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1614 - System Location Discovery
MITREへのリンク →

TA505

Score: 5.62
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1588.001 - Malware
  • T1071.001 - Web Protocols
MITREへのリンク →

BlackByte

Score: 8.25
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1190 - Exploit Public-Facing Application
  • T1041 - Exfiltration Over C2 Channel
  • T1071.001 - Web Protocols
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

BITTER

Score: 6.75
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
MITREへのリンク →

APT32

Score: 19.75
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1550.003 - Pass the Ticket
  • T1036.004 - Masquerade Task or Service
  • T1041 - Exfiltration Over C2 Channel
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
  • T1078.003 - Local Accounts
MITREへのリンク →

HEXANE

Score: 3.62
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Saint Bear

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

EXOTIC LILY

Score: 3.47
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

APT42

Score: 9.53
Matched TTPs:
  • T1608.001 - Upload Malware
  • T1070 - Indicator Removal
  • T1573.002 - Asymmetric Cryptography
  • T1071.001 - Web Protocols
MITREへのリンク →

Rocke

Score: 6.10
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1552.004 - Private Keys
  • T1071.001 - Web Protocols
MITREへのリンク →

Volt Typhoon

Score: 16.57
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1552.004 - Private Keys
  • T1614 - System Location Discovery
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
MITREへのリンク →

APT28

Score: 19.67
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1589.001 - Credentials
  • T1203 - Exploitation for Client Execution
  • T1598 - Phishing for Information
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

BackdoorDiplomacy

Score: 6.02
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
MITREへのリンク →

BlackTech

Score: 6.12
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1588.003 - Code Signing Certificates
MITREへのリンク →

Magic Hound

Score: 11.61
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1589.001 - Credentials
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Medusa Group

Score: 14.11
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1573.002 - Asymmetric Cryptography
  • T1650 - Acquire Access
  • T1071.001 - Web Protocols
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Storm-0501

Score: 19.34
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1552.004 - Private Keys
  • T1036.004 - Masquerade Task or Service
  • T1657 - Financial Theft
  • T1218.010 - Regsvr32
  • T1556.009 - Conditional Access Policies
  • T1219.002 - Remote Desktop Software
MITREへのリンク →

Fox Kitten

Score: 11.24
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1217 - Browser Information Discovery
  • T1036.004 - Masquerade Task or Service
  • T1210 - Exploitation of Remote Services
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Cinnamon Tempest

Score: 3.99
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
MITREへのリンク →

menuPass

Score: 5.86
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Blue Mockingbird

Score: 5.86
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1218.010 - Regsvr32
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

GALLIUM

Score: 3.44
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1041 - Exfiltration Over C2 Channel
MITREへのリンク →

Winter Vivern

Score: 16.65
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1056.003 - Web Portal Capture
  • T1036.004 - Masquerade Task or Service
  • T1041 - Exfiltration Over C2 Channel
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
MITREへのリンク →

Leviathan

Score: 14.53
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1041 - Exfiltration Over C2 Channel
  • T1218.010 - Regsvr32
  • T1589.001 - Credentials
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

INC Ransom

Score: 5.64
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1657 - Financial Theft
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Dragonfly

Score: 9.12
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Axiom

Score: 10.91
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1021.001 - Remote Desktop Protocol
  • T1001.002 - Steganography
MITREへのリンク →

APT41

Score: 7.89
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1036.004 - Masquerade Task or Service
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

HAFNIUM

Score: 5.32
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1071.001 - Web Protocols
  • T1078.003 - Local Accounts
MITREへのリンク →

APT5

Score: 6.74
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1070 - Indicator Removal
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

MuddyWater

Score: 8.87
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1041 - Exfiltration Over C2 Channel
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
MITREへのリンク →

APT39

Score: 6.28
Matched TTPs:
  • T1190 - Exploit Public-Facing Application
  • T1041 - Exfiltration Over C2 Channel
  • T1071.001 - Web Protocols
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT38

Score: 6.24
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
MITREへのリンク →

Scattered Spider

Score: 25.83
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1552.004 - Private Keys
  • T1588.001 - Malware
  • T1657 - Financial Theft
  • T1041 - Exfiltration Over C2 Channel
  • T1598 - Phishing for Information
  • T1556.009 - Conditional Access Policies
  • T1219.002 - Remote Desktop Software
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Chimera

Score: 14.13
Matched TTPs:
  • T1217 - Browser Information Discovery
  • T1041 - Exfiltration Over C2 Channel
  • T1589.001 - Credentials
  • T1071.001 - Web Protocols
  • T1021.001 - Remote Desktop Protocol
  • T1124 - System Time Discovery
MITREへのリンク →

LAPSUS$

Score: 5.90
Matched TTPs:
  • T1588.001 - Malware
  • T1589.001 - Credentials
MITREへのリンク →

Metador

Score: 3.65
Matched TTPs:
  • T1588.001 - Malware
  • T1071.001 - Web Protocols
MITREへのリンク →

APT1

Score: 4.11
Matched TTPs:
  • T1588.001 - Malware
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Aquatic Panda

Score: 6.20
Matched TTPs:
  • T1588.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Andariel

Score: 5.72
Matched TTPs:
  • T1588.001 - Malware
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

BRONZE BUTLER

Score: 10.88
Matched TTPs:
  • T1550.003 - Pass the Ticket
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
  • T1124 - System Time Discovery
MITREへのリンク →

Wizard Spider

Score: 16.42
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1041 - Exfiltration Over C2 Channel
  • T1210 - Exploitation of Remote Services
  • T1555.004 - Windows Credential Manager
  • T1071.001 - Web Protocols
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

FIN6

Score: 6.49
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1573.002 - Asymmetric Cryptography
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

PROMETHIUM

Score: 10.66
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1205.001 - Port Knocking
  • T1189 - Drive-by Compromise
  • T1078.003 - Local Accounts
MITREへのリンク →

ZIRCONIUM

Score: 10.10
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1041 - Exfiltration Over C2 Channel
  • T1598 - Phishing for Information
  • T1124 - System Time Discovery
MITREへのリンク →

Higaisa

Score: 9.34
Matched TTPs:
  • T1036.004 - Masquerade Task or Service
  • T1041 - Exfiltration Over C2 Channel
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
  • T1124 - System Time Discovery
MITREへのリンク →

Akira

Score: 4.17
Matched TTPs:
  • T1657 - Financial Theft
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

SilverTerrier

Score: 3.71
Matched TTPs:
  • T1657 - Financial Theft
  • T1071.001 - Web Protocols
MITREへのリンク →

APT3

Score: 5.11
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1203 - Exploitation for Client Execution
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Confucius

Score: 4.65
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
MITREへのリンク →

Stealth Falcon

Score: 6.78
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1555.004 - Windows Credential Manager
  • T1071.001 - Web Protocols
MITREへのリンク →

CURIUM

Score: 9.95
Matched TTPs:
  • T1041 - Exfiltration Over C2 Channel
  • T1584.006 - Web Services
  • T1189 - Drive-by Compromise
  • T1124 - System Time Discovery
MITREへのリンク →

Tonto Team

Score: 4.24
Matched TTPs:
  • T1210 - Exploitation of Remote Services
  • T1203 - Exploitation for Client Execution
MITREへのリンク →

TA551

Score: 3.93
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1071.001 - Web Protocols
MITREへのリンク →

Cobalt Group

Score: 9.82
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1071.001 - Web Protocols
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

Inception

Score: 5.43
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
MITREへのリンク →

WIRTE

Score: 3.93
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1071.001 - Web Protocols
MITREへのリンク →

APT19

Score: 5.70
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
MITREへのリンク →

Sidewinder

Score: 5.27
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1071.001 - Web Protocols
  • T1124 - System Time Discovery
MITREへのリンク →

The White Company

Score: 4.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1124 - System Time Discovery
MITREへのリンク →

Patchwork

Score: 4.91
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

APT37

Score: 4.45
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1071.001 - Web Protocols
MITREへのリンク →

Transparent Tribe

Score: 3.26
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Tropic Trooper

Score: 8.09
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1573.002 - Asymmetric Cryptography
  • T1071.001 - Web Protocols
  • T1078.003 - Local Accounts
MITREへのリンク →

Elderwood

Score: 3.26
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
MITREへのリンク →

Darkhotel

Score: 5.85
Matched TTPs:
  • T1203 - Exploitation for Client Execution
  • T1189 - Drive-by Compromise
  • T1124 - System Time Discovery
MITREへのリンク →

Velvet Ant

Score: 9.54
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1078.003 - Local Accounts
  • T1211 - Exploitation for Defense Evasion
MITREへのリンク →

RedEcho

Score: 3.93
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1071.001 - Web Protocols
MITREへのリンク →

FIN8

Score: 8.73
Matched TTPs:
  • T1573.002 - Asymmetric Cryptography
  • T1071.001 - Web Protocols
  • T1588.003 - Code Signing Certificates
  • T1021.001 - Remote Desktop Protocol
MITREへのリンク →

RTM

Score: 4.69
Matched TTPs:
  • T1219.002 - Remote Desktop Software
  • T1189 - Drive-by Compromise
MITREへのリンク →

FIN10

Score: 4.31
Matched TTPs:
  • T1021.001 - Remote Desktop Protocol
  • T1078.003 - Local Accounts
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Kimsuky

Score: 0.78
Matched TTPs:
  • T1078.003 - Local Accounts
  • T1041 - Exfiltration Over C2 Channel
  • T1657 - Financial Theft
  • T1587 - Develop Capabilities
  • T1588.005 - Exploits
  • T1588.003 - Code Signing Certificates
  • T1218.010 - Regsvr32
  • T1190 - Exploit Public-Facing Application
  • T1219.002 - Remote Desktop Software
  • T1021.001 - Remote Desktop Protocol
  • T1071.001 - Web Protocols
  • T1608.001 - Upload Malware
  • T1587.001 - Malware
  • T1036.004 - Masquerade Task or Service
  • T1583 - Acquire Infrastructure
  • T1598 - Phishing for Information
MITREへのリンク →

Scattered Spider

Score: 0.55
Matched TTPs:
  • T1556.009 - Conditional Access Policies
  • T1041 - Exfiltration Over C2 Channel
  • T1657 - Financial Theft
  • T1217 - Browser Information Discovery
  • T1588.001 - Malware
  • T1552.004 - Private Keys
  • T1219.002 - Remote Desktop Software
  • T1021.001 - Remote Desktop Protocol
  • T1598 - Phishing for Information
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る