Trusted Design

Fake OWA Page

概要

We just ran the entire scenario in the sandbox. No subsequent processes were triggered. This seems like a reconnaissance exercise at this stage where the intent is to gather relevant data for god knows what (publish details in darknet, access emails to fetch address book, attach files with the intention be executed by the target, send emails on behalf, ,,,,,). From the chatter I've seen it seems like this is design to build a contact list/directory. This is info is hidden in the javascript behind the code once you click the send button and it seems like it is sending the info to a hashed email addresses.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Scattered Spider

Score: 32.13
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
  • T1578 - Modify Cloud Compute Infrastructure
  • T1566.002 - Spearphishing Link
  • T1583.001 - Domains
  • T1144 - Gatekeeper Bypass
  • T1083 - File and Directory Discovery
  • T1619 - Cloud Storage Object Discovery
  • T1548.006 - TCC Manipulation
  • T1588.005 - Exploits
MITREへのリンク →

FIN4

Score: 6.45
Matched TTPs:
  • T1666 - Modify Cloud Resource Hierarchy
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Turla

Score: 12.39
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1131 - Authentication Package
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT32

Score: 22.49
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1131 - Authentication Package
  • T1134.002 - Create Process with Token
  • T1059.012 - Hypervisor CLI
  • T1668 - Exclusive Control
  • T1105 - Ingress Tool Transfer
  • T1556 - Modify Authentication Process
MITREへのリンク →

Saint Bear

Score: 9.22
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1134.002 - Create Process with Token
  • T1064 - Scripting
MITREへのリンク →

FIN6

Score: 10.46
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1548.006 - TCC Manipulation
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Sidewinder

Score: 11.89
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1657 - Financial Theft
  • T1583.006 - Web Services
MITREへのリンク →

MuddyWater

Score: 8.21
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
MITREへのリンク →

Earth Lusca

Score: 6.70
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1583.006 - Web Services
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

TA577

Score: 3.42
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
MITREへのリンク →

Winter Vivern

Score: 4.61
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Contagious Interview

Score: 14.37
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1131 - Authentication Package
  • T1064 - Scripting
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

LazyScripter

Score: 4.29
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
MITREへのリンク →

TA505

Score: 4.29
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
MITREへのリンク →

FIN7

Score: 10.88
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Cobalt Group

Score: 4.29
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
MITREへのリンク →

Higaisa

Score: 10.35
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1665 - Hide Infrastructure
  • T1546.017 - Udev Rules
MITREへのリンク →

Kimsuky

Score: 22.06
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1131 - Authentication Package
  • T1134.002 - Create Process with Token
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1668 - Exclusive Control
  • T1665 - Hide Infrastructure
MITREへのリンク →

Molerats

Score: 8.96
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1546.017 - Udev Rules
MITREへのリンク →

Leafminer

Score: 3.74
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Mustang Panda

Score: 16.02
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1105 - Ingress Tool Transfer
  • T1548.006 - TCC Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

Evilnum

Score: 3.42
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1543.003 - Windows Service
MITREへのリンク →

Star Blizzard

Score: 8.93
Matched TTPs:
  • T1546.013 - PowerShell Profile
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1657 - Financial Theft
MITREへのリンク →

Ember Bear

Score: 6.37
Matched TTPs:
  • T1578 - Modify Cloud Compute Infrastructure
  • T1668 - Exclusive Control
MITREへのリンク →

Silent Librarian

Score: 8.60
Matched TTPs:
  • T1578 - Modify Cloud Compute Infrastructure
  • T1566.002 - Spearphishing Link
  • T1134.002 - Create Process with Token
MITREへのリンク →

Magic Hound

Score: 18.25
Matched TTPs:
  • T1578 - Modify Cloud Compute Infrastructure
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1134.002 - Create Process with Token
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

LuminousMoth

Score: 4.11
Matched TTPs:
  • T1543.003 - Windows Service
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Confucius

Score: 5.15
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1665 - Hide Infrastructure
MITREへのリンク →

Mofang

Score: 5.47
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1546.017 - Udev Rules
MITREへのリンク →

Elderwood

Score: 4.09
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Machete

Score: 4.09
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Mustard Tempest

Score: 3.21
Matched TTPs:
  • T1543.003 - Windows Service
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Sandworm Team

Score: 12.04
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1134.002 - Create Process with Token
  • T1547.002 - Authentication Package
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Transparent Tribe

Score: 6.75
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

FIN8

Score: 5.07
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1556 - Modify Authentication Process
MITREへのリンク →

APT1

Score: 6.59
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1668 - Exclusive Control
MITREへのリンク →

Lazarus Group

Score: 21.29
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1134.002 - Create Process with Token
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
  • T1105 - Ingress Tool Transfer
  • T1665 - Hide Infrastructure
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Leviathan

Score: 7.24
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1546.017 - Udev Rules
MITREへのリンク →

APT33

Score: 5.07
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1556 - Modify Authentication Process
MITREへのリンク →

ZIRCONIUM

Score: 6.30
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1547.002 - Authentication Package
MITREへのリンク →

EXOTIC LILY

Score: 7.37
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1134.002 - Create Process with Token
  • T1547.008 - LSASS Driver
MITREへのリンク →

OilRig

Score: 13.65
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1592.002 - Software
  • T1547.008 - LSASS Driver
  • T1556 - Modify Authentication Process
MITREへのリンク →

Windshift

Score: 8.13
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

APT29

Score: 9.38
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1555.004 - Windows Credential Manager
  • T1547.008 - LSASS Driver
MITREへのリンク →

TA2541

Score: 5.47
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1546.017 - Udev Rules
MITREへのリンク →

RedCurl

Score: 4.99
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Storm-1811

Score: 8.51
Matched TTPs:
  • T1543.003 - Windows Service
  • T1567.003 - Exfiltration to Text Storage Sites
  • T1547.008 - LSASS Driver
MITREへのリンク →

Wizard Spider

Score: 13.78
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1083 - File and Directory Discovery
  • T1668 - Exclusive Control
  • T1548.006 - TCC Manipulation
  • T1556 - Modify Authentication Process
MITREへのリンク →

Patchwork

Score: 9.38
Matched TTPs:
  • T1543.003 - Windows Service
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1665 - Hide Infrastructure
MITREへのリンク →

APT42

Score: 5.58
Matched TTPs:
  • T1543.003 - Windows Service
  • T1583.001 - Domains
MITREへのリンク →

APT39

Score: 4.72
Matched TTPs:
  • T1543.003 - Windows Service
  • T1598.003 - Spearphishing Link
  • T1547.002 - Authentication Package
MITREへのリンク →

APT28

Score: 29.13
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1131 - Authentication Package
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
  • T1146 - Clear Command History
  • T1668 - Exclusive Control
  • T1105 - Ingress Tool Transfer
  • T1548.006 - TCC Manipulation
  • T1546.007 - Netsh Helper DLL
MITREへのリンク →

Moonstone Sleet

Score: 8.38
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1134.002 - Create Process with Token
  • T1547.008 - LSASS Driver
MITREへのリンク →

CURIUM

Score: 7.62
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Dragonfly

Score: 11.06
Matched TTPs:
  • T1566.002 - Spearphishing Link
  • T1598.003 - Spearphishing Link
  • T1657 - Financial Theft
  • T1059.012 - Hypervisor CLI
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Tropic Trooper

Score: 7.89
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1105 - Ingress Tool Transfer
  • T1665 - Hide Infrastructure
MITREへのリンク →

menuPass

Score: 3.22
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Threat Group-3390

Score: 5.79
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1059.012 - Hypervisor CLI
  • T1546.017 - Udev Rules
MITREへのリンク →

Gamaredon Group

Score: 7.94
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1546.017 - Udev Rules
MITREへのリンク →

Darkhotel

Score: 8.00
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1064 - Scripting
  • T1583.006 - Web Services
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Ajax Security Team

Score: 3.40
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1547.008 - LSASS Driver
MITREへのリンク →

TA551

Score: 3.40
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1134.002 - Create Process with Token
MITREへのリンク →

APT41

Score: 5.96
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1668 - Exclusive Control
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT12

Score: 3.27
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1547.002 - Authentication Package
MITREへのリンク →

SideCopy

Score: 4.50
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1657 - Financial Theft
MITREへのリンク →

Andariel

Score: 4.16
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT37

Score: 6.56
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

APT38

Score: 4.16
Matched TTPs:
  • T1598.003 - Spearphishing Link
  • T1583.006 - Web Services
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

SilverTerrier

Score: 3.29
Matched TTPs:
  • T1131 - Authentication Package
MITREへのリンク →

Volt Typhoon

Score: 12.84
Matched TTPs:
  • T1134.002 - Create Process with Token
  • T1083 - File and Directory Discovery
  • T1583.006 - Web Services
  • T1548.006 - TCC Manipulation
  • T1665 - Hide Infrastructure
MITREへのリンク →

HAFNIUM

Score: 9.05
Matched TTPs:
  • T1134.002 - Create Process with Token
  • T1583.006 - Web Services
  • T1105 - Ingress Tool Transfer
  • T1548.006 - TCC Manipulation
MITREへのリンク →

HEXANE

Score: 6.44
Matched TTPs:
  • T1134.002 - Create Process with Token
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
MITREへのリンク →

LAPSUS$

Score: 12.84
Matched TTPs:
  • T1134.002 - Create Process with Token
  • T1619 - Cloud Storage Object Discovery
  • T1548.006 - TCC Manipulation
  • T1588.005 - Exploits
MITREへのリンク →

Aquatic Panda

Score: 6.59
Matched TTPs:
  • T1144 - Gatekeeper Bypass
  • T1668 - Exclusive Control
MITREへのリンク →

FIN13

Score: 11.60
Matched TTPs:
  • T1144 - Gatekeeper Bypass
  • T1668 - Exclusive Control
  • T1105 - Ingress Tool Transfer
  • T1548.006 - TCC Manipulation
MITREへのリンク →

INC Ransom

Score: 3.62
Matched TTPs:
  • T1083 - File and Directory Discovery
MITREへのリンク →

TeamTNT

Score: 4.35
Matched TTPs:
  • T1583.006 - Web Services
  • T1665 - Hide Infrastructure
MITREへのリンク →

Chimera

Score: 9.44
Matched TTPs:
  • T1583.006 - Web Services
  • T1668 - Exclusive Control
  • T1548.006 - TCC Manipulation
  • T1665 - Hide Infrastructure
MITREへのリンク →

Medusa Group

Score: 8.40
Matched TTPs:
  • T1583.006 - Web Services
  • T1548.006 - TCC Manipulation
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

ToddyCat

Score: 6.87
Matched TTPs:
  • T1583.006 - Web Services
  • T1665 - Hide Infrastructure
  • T1547.008 - LSASS Driver
MITREへのリンク →

Rocke

Score: 4.18
Matched TTPs:
  • T1583.006 - Web Services
  • T1105 - Ingress Tool Transfer
MITREへのリンク →

Ke3chang

Score: 3.86
Matched TTPs:
  • T1583.006 - Web Services
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Dark Caracal

Score: 4.29
Matched TTPs:
  • T1059.012 - Hypervisor CLI
  • T1547.008 - LSASS Driver
MITREへのリンク →

Equation

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Strider

Score: 4.13
Matched TTPs:
  • T1130 - Install Root Certificate
MITREへのリンク →

Fox Kitten

Score: 6.19
Matched TTPs:
  • T1548.006 - TCC Manipulation
  • T1588.005 - Exploits
MITREへのリンク →

Blue Mockingbird

Score: 4.54
Matched TTPs:
  • T1001.001 - Junk Data
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

Scattered Spider

Score: 0.80
Matched TTPs:
  • T1588.005 - Exploits
  • T1144 - Gatekeeper Bypass
  • T1666 - Modify Cloud Resource Hierarchy
  • T1083 - File and Directory Discovery
  • T1619 - Cloud Storage Object Discovery
  • T1583.001 - Domains
  • T1548.006 - TCC Manipulation
  • T1566.002 - Spearphishing Link
  • T1578 - Modify Cloud Compute Infrastructure
MITREへのリンク →

APT28

Score: 0.68
Matched TTPs:
  • T1146 - Clear Command History
  • T1598.003 - Spearphishing Link
  • T1105 - Ingress Tool Transfer
  • T1131 - Authentication Package
  • T1546.007 - Netsh Helper DLL
  • T1668 - Exclusive Control
  • T1583.006 - Web Services
  • T1547.002 - Authentication Package
  • T1566.002 - Spearphishing Link
  • T1548.006 - TCC Manipulation
  • T1059.012 - Hypervisor CLI
MITREへのリンク →

Related CVEs

このPulseに見つかったCVEはありません。

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る