Msil malware on Metadefender.com
概要
Msil malware has shown the following behaviors: backdoor,adware,trojan,keylogger,riskware ; Msil malware has targeted following platforms: win32,win,vbscripts,js,script ; Msil malware has used the following delivery mechanisms: downloader,dropper,packed,client,bundle ;
Created: 2026-02-23
Indicators
Indicatorsは見つかっていない。
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 29.38
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1562.009 - Safe Mode Boot
- T1058 - Service Registry Permissions Weakness
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1218.012 - Verclsid
- T1608 - Stage Capabilities
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1059.013 - Container CLI/API
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 34.28
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1058 - Service Registry Permissions Weakness
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1140 - Deobfuscate/Decode Files or Information
- T1011.001 - Exfiltration Over Bluetooth
- T1218.012 - Verclsid
- T1583.006 - Web Services
- T1564.002 - Hidden Users
- T1199 - Trusted Relationship
- T1573 - Encrypted Channel
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 13.32
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 34.60
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1213.006 - Databases
- T1176.001 - Browser Extensions
- T1003.007 - Proc Filesystem
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1140 - Deobfuscate/Decode Files or Information
- T1218.012 - Verclsid
- T1608 - Stage Capabilities
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1027.014 - Polymorphic Code
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 16.05
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1499.001 - OS Exhaustion Flood
- T1606.002 - SAML Tokens
- T1140 - Deobfuscate/Decode Files or Information
- T1136.002 - Domain Account
- T1583.006 - Web Services
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 4.72
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1176.001 - Browser Extensions
- T1199 - Trusted Relationship
MITREへのリンク →
Score: 12.68
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1177 - LSASS Driver
- T1583.006 - Web Services
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 17.27
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1140 - Deobfuscate/Decode Files or Information
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1187 - Forced Authentication
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 10.77
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1558 - Steal or Forge Kerberos Tickets
- T1218.012 - Verclsid
- T1027.014 - Polymorphic Code
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 11.33
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1176.001 - Browser Extensions
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 16.22
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1003.001 - LSASS Memory
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 26.21
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1091 - Replication Through Removable Media
- T1558 - Steal or Forge Kerberos Tickets
- T1218.012 - Verclsid
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1174 - Password Filter DLL
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 45.98
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1132.001 - Standard Encoding
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1070.008 - Clear Mailbox Data
- T1050 - New Service
- T1070.006 - Timestomp
- T1218.012 - Verclsid
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1174 - Password Filter DLL
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1055.005 - Thread Local Storage
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 19.28
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1136.002 - Domain Account
- T1138 - Application Shimming
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 22.09
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1499.001 - OS Exhaustion Flood
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1199 - Trusted Relationship
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 30.29
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1005 - Data from Local System
- T1140 - Deobfuscate/Decode Files or Information
- T1558 - Steal or Forge Kerberos Tickets
- T1199 - Trusted Relationship
- T1187 - Forced Authentication
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1075 - Pass the Hash
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 25.21
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1499.001 - OS Exhaustion Flood
- T1087.002 - Domain Account
- T1058 - Service Registry Permissions Weakness
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1558 - Steal or Forge Kerberos Tickets
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1548.004 - Elevated Execution with Prompt
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.70
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1140 - Deobfuscate/Decode Files or Information
- T1583.006 - Web Services
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 29.99
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1138 - Application Shimming
- T1218.012 - Verclsid
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1174 - Password Filter DLL
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 12.43
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1089 - Disabling Security Tools
- T1573 - Encrypted Channel
- T1174 - Password Filter DLL
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 8.95
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1574.010 - Services File Permissions Weakness
MITREへのリンク →
Score: 12.46
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1558 - Steal or Forge Kerberos Tickets
- T1136.002 - Domain Account
- T1218.012 - Verclsid
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 15.91
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1003.007 - Proc Filesystem
- T1136.002 - Domain Account
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 9.57
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1140 - Deobfuscate/Decode Files or Information
- T1583.006 - Web Services
- T1027.014 - Polymorphic Code
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 28.67
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1518.002 - Backup Software Discovery
- T1218.012 - Verclsid
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
- T1059.013 - Container CLI/API
- T1506 - Web Session Cookie
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1132.001 - Standard Encoding
MITREへのリンク →
Score: 18.90
Matched TTPs:
- T1132.001 - Standard Encoding
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1573 - Encrypted Channel
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 25.63
Matched TTPs:
- T1056.001 - Keylogging
- T1606.002 - SAML Tokens
- T1003.007 - Proc Filesystem
- T1059.010 - AutoHotKey & AutoIT
- T1003.001 - LSASS Memory
- T1136.002 - Domain Account
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 37.97
Matched TTPs:
- T1003 - OS Credential Dumping
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1058 - Service Registry Permissions Weakness
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1136.001 - Local Account
- T1218.012 - Verclsid
- T1608 - Stage Capabilities
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 5.58
Matched TTPs:
- T1499.001 - OS Exhaustion Flood
- T1583.006 - Web Services
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 15.93
Matched TTPs:
- T1499.001 - OS Exhaustion Flood
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1583.006 - Web Services
- T1597 - Search Closed Sources
- T1059.013 - Container CLI/API
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 21.56
Matched TTPs:
- T1499.001 - OS Exhaustion Flood
- T1606.002 - SAML Tokens
- T1176.001 - Browser Extensions
- T1003.007 - Proc Filesystem
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1558 - Steal or Forge Kerberos Tickets
- T1583.006 - Web Services
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 9.05
Matched TTPs:
- T1682 - Query Public AI Services
- T1091 - Replication Through Removable Media
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 10.68
Matched TTPs:
- T1606.002 - SAML Tokens
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1558 - Steal or Forge Kerberos Tickets
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 7.98
Matched TTPs:
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1003.007 - Proc Filesystem
- T1597 - Search Closed Sources
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 21.29
Matched TTPs:
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1558 - Steal or Forge Kerberos Tickets
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1059.006 - Python
- T1221 - Template Injection
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 27.51
Matched TTPs:
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1562.009 - Safe Mode Boot
- T1003.007 - Proc Filesystem
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1005 - Data from Local System
- T1558 - Steal or Forge Kerberos Tickets
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 12.92
Matched TTPs:
- T1606.002 - SAML Tokens
- T1089 - Disabling Security Tools
- T1058 - Service Registry Permissions Weakness
- T1091 - Replication Through Removable Media
- T1136.002 - Domain Account
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.41
Matched TTPs:
- T1606.002 - SAML Tokens
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
MITREへのリンク →
Score: 19.47
Matched TTPs:
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1138 - Application Shimming
- T1218.012 - Verclsid
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 10.40
Matched TTPs:
- T1606.002 - SAML Tokens
- T1140 - Deobfuscate/Decode Files or Information
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 10.45
Matched TTPs:
- T1606.002 - SAML Tokens
- T1087.002 - Domain Account
- T1058 - Service Registry Permissions Weakness
- T1558 - Steal or Forge Kerberos Tickets
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 5.19
Matched TTPs:
- T1606.002 - SAML Tokens
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 15.13
Matched TTPs:
- T1606.002 - SAML Tokens
- T1176.001 - Browser Extensions
- T1003.007 - Proc Filesystem
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 4.25
Matched TTPs:
- T1087.002 - Domain Account
- T1059.010 - AutoHotKey & AutoIT
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 5.84
Matched TTPs:
- T1087.002 - Domain Account
- T1685.002 - Disable or Modify Cloud Log
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 4.82
Matched TTPs:
- T1087.002 - Domain Account
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.05
Matched TTPs:
- T1087.002 - Domain Account
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 10.07
Matched TTPs:
- T1087.002 - Domain Account
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.73
Matched TTPs:
- T1087.002 - Domain Account
- T1059.010 - AutoHotKey & AutoIT
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.29
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 5.08
Matched TTPs:
- T1087.002 - Domain Account
- T1059.012 - Hypervisor CLI
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 21.34
Matched TTPs:
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1058 - Service Registry Permissions Weakness
- T1059.010 - AutoHotKey & AutoIT
- T1003.001 - LSASS Memory
- T1583.006 - Web Services
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.08
Matched TTPs:
- T1087.002 - Domain Account
- T1059.012 - Hypervisor CLI
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 5.52
Matched TTPs:
- T1087.002 - Domain Account
- T1558 - Steal or Forge Kerberos Tickets
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 12.66
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1558 - Steal or Forge Kerberos Tickets
- T1199 - Trusted Relationship
- T1174 - Password Filter DLL
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 12.50
Matched TTPs:
- T1087.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1070.006 - Timestomp
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.31
Matched TTPs:
- T1087.002 - Domain Account
- T1199 - Trusted Relationship
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 21.41
Matched TTPs:
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1140 - Deobfuscate/Decode Files or Information
- T1218.003 - CMSTP
- T1199 - Trusted Relationship
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.88
Matched TTPs:
- T1087.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.34
Matched TTPs:
- T1087.002 - Domain Account
- T1583.006 - Web Services
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.49
Matched TTPs:
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 20.55
Matched TTPs:
- T1087.002 - Domain Account
- T1499.002 - Service Exhaustion Flood
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1050 - New Service
- T1199 - Trusted Relationship
- T1564.007 - VBA Stomping
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 3.61
Matched TTPs:
- T1087.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1199 - Trusted Relationship
MITREへのリンク →
Score: 7.10
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1583.006 - Web Services
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 4.85
Matched TTPs:
- T1087.002 - Domain Account
- T1685.002 - Disable or Modify Cloud Log
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.92
Matched TTPs:
- T1087.002 - Domain Account
- T1574.010 - Services File Permissions Weakness
MITREへのリンク →
Score: 17.55
Matched TTPs:
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1518.002 - Backup Software Discovery
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 10.43
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 12.48
Matched TTPs:
- T1087.002 - Domain Account
- T1218.012 - Verclsid
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1027.014 - Polymorphic Code
- T1218.010 - Regsvr32
- T1159 - Launch Agent
MITREへのリンク →
Score: 6.78
Matched TTPs:
- T1087.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1218.010 - Regsvr32
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 4.09
Matched TTPs:
- T1087.002 - Domain Account
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 6.05
Matched TTPs:
- T1087.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 8.36
Matched TTPs:
- T1087.002 - Domain Account
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1027.007 - Dynamic API Resolution
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 9.31
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.15
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.75
Matched TTPs:
- T1087.002 - Domain Account
- T1558 - Steal or Forge Kerberos Tickets
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 9.40
Matched TTPs:
- T1087.002 - Domain Account
- T1059.010 - AutoHotKey & AutoIT
- T1050 - New Service
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 12.88
Matched TTPs:
- T1087.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1136.002 - Domain Account
- T1218.012 - Verclsid
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 20.92
Matched TTPs:
- T1087.002 - Domain Account
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1003.007 - Proc Filesystem
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1140 - Deobfuscate/Decode Files or Information
- T1136.002 - Domain Account
- T1218.012 - Verclsid
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 12.26
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1091 - Replication Through Removable Media
- T1218.012 - Verclsid
- T1506 - Web Session Cookie
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 14.23
Matched TTPs:
- T1087.002 - Domain Account
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1050 - New Service
- T1027.014 - Polymorphic Code
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.79
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 12.64
Matched TTPs:
- T1087.002 - Domain Account
- T1136.002 - Domain Account
- T1583.006 - Web Services
- T1187 - Forced Authentication
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 18.23
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1003.007 - Proc Filesystem
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.42
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 7.94
Matched TTPs:
- T1087.002 - Domain Account
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1583.006 - Web Services
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.80
Matched TTPs:
- T1087.002 - Domain Account
- T1003.007 - Proc Filesystem
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 20.41
Matched TTPs:
- T1087.002 - Domain Account
- T1562.009 - Safe Mode Boot
- T1058 - Service Registry Permissions Weakness
- T1059.010 - AutoHotKey & AutoIT
- T1583.006 - Web Services
- T1564.002 - Hidden Users
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.18
Matched TTPs:
- T1087.002 - Domain Account
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 3.91
Matched TTPs:
- T1087.002 - Domain Account
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.81
Matched TTPs:
- T1087.002 - Domain Account
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 13.30
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1218.012 - Verclsid
- T1583.006 - Web Services
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.40
Matched TTPs:
- T1087.002 - Domain Account
- T1218.012 - Verclsid
- T1218.010 - Regsvr32
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.34
Matched TTPs:
- T1087.002 - Domain Account
- T1089 - Disabling Security Tools
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 14.20
Matched TTPs:
- T1087.002 - Domain Account
- T1558 - Steal or Forge Kerberos Tickets
- T1583.006 - Web Services
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 16.77
Matched TTPs:
- T1176.001 - Browser Extensions
- T1140 - Deobfuscate/Decode Files or Information
- T1218.003 - CMSTP
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 13.82
Matched TTPs:
- T1176.001 - Browser Extensions
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1140 - Deobfuscate/Decode Files or Information
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 8.96
Matched TTPs:
- T1176.001 - Browser Extensions
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1558 - Steal or Forge Kerberos Tickets
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 8.33
Matched TTPs:
- T1176.001 - Browser Extensions
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.95
Matched TTPs:
- T1562.009 - Safe Mode Boot
- T1089 - Disabling Security Tools
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 22.87
Matched TTPs:
- T1562.009 - Safe Mode Boot
- T1003.007 - Proc Filesystem
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1070.008 - Clear Mailbox Data
- T1070.006 - Timestomp
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1159 - Launch Agent
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 9.80
Matched TTPs:
- T1089 - Disabling Security Tools
- T1003.007 - Proc Filesystem
- T1583.006 - Web Services
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 5.93
Matched TTPs:
- T1089 - Disabling Security Tools
- T1597 - Search Closed Sources
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 8.12
Matched TTPs:
- T1089 - Disabling Security Tools
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
- T1174 - Password Filter DLL
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 7.29
Matched TTPs:
- T1089 - Disabling Security Tools
- T1140 - Deobfuscate/Decode Files or Information
- T1136.002 - Domain Account
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.04
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1583.006 - Web Services
MITREへのリンク →
Score: 7.35
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1136.002 - Domain Account
- T1583.006 - Web Services
- T1199 - Trusted Relationship
MITREへのリンク →
Score: 7.82
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 7.77
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1140 - Deobfuscate/Decode Files or Information
- T1558 - Steal or Forge Kerberos Tickets
- T1059.012 - Hypervisor CLI
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.72
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1199 - Trusted Relationship
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 13.25
Matched TTPs:
- T1005 - Data from Local System
- T1140 - Deobfuscate/Decode Files or Information
- T1558 - Steal or Forge Kerberos Tickets
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 4.40
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 7.43
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
- T1218.010 - Regsvr32
- T1059.013 - Container CLI/API
MITREへのリンク →
Score: 5.53
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 7.41
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1583.006 - Web Services
- T1506 - Web Session Cookie
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 7.29
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1547.013 - XDG Autostart Entries
- T1027.007 - Dynamic API Resolution
MITREへのリンク →
Score: 17.09
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1114.002 - Remote Email Collection
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1160 - Launch Daemon
MITREへのリンク →
Score: 7.55
Matched TTPs:
- T1177 - LSASS Driver
- T1583.006 - Web Services
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 3.31
Matched TTPs:
- T1136.002 - Domain Account
- T1199 - Trusted Relationship
MITREへのリンク →
Score: 4.08
Matched TTPs:
- T1136.002 - Domain Account
- T1199 - Trusted Relationship
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.88
Matched TTPs:
- T1136.002 - Domain Account
- T1199 - Trusted Relationship
- T1597 - Search Closed Sources
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.51
Matched TTPs:
- T1059.012 - Hypervisor CLI
- T1159 - Launch Agent
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.77
Matched TTPs:
- T1606.002 - SAML Tokens
- T1218.010 - Regsvr32
- T1087.002 - Domain Account
- T1583 - Acquire Infrastructure
- T1199 - Trusted Relationship
- T1059.010 - AutoHotKey & AutoIT
- T1547.013 - XDG Autostart Entries
- T1055.005 - Thread Local Storage
- T1597 - Search Closed Sources
- T1050 - New Service
- T1089 - Disabling Security Tools
- T1132.001 - Standard Encoding
- T1070.008 - Clear Mailbox Data
- T1070.006 - Timestomp
- T1176.001 - Browser Extensions
- T1174 - Password Filter DLL
- T1547.008 - LSASS Driver
- T1218.012 - Verclsid
- T1059.012 - Hypervisor CLI
- T1583.006 - Web Services
MITREへのリンク →
Score: 0.66
Matched TTPs:
- T1058 - Service Registry Permissions Weakness
- T1606.002 - SAML Tokens
- T1218.012 - Verclsid
- T1573 - Encrypted Channel
- T1199 - Trusted Relationship
- T1027.007 - Dynamic API Resolution
- T1140 - Deobfuscate/Decode Files or Information
- T1091 - Replication Through Removable Media
- T1011.001 - Exfiltration Over Bluetooth
- T1087.002 - Domain Account
- T1564.002 - Hidden Users
- T1547.013 - XDG Autostart Entries
- T1059.010 - AutoHotKey & AutoIT
- T1583.006 - Web Services
- T1583 - Acquire Infrastructure
- T1176.001 - Browser Extensions
MITREへのリンク →
Score: 0.62
Matched TTPs:
- T1218.012 - Verclsid
- T1606.002 - SAML Tokens
- T1218.010 - Regsvr32
- T1199 - Trusted Relationship
- T1055.005 - Thread Local Storage
- T1091 - Replication Through Removable Media
- T1087.002 - Domain Account
- T1003 - OS Credential Dumping
- T1547.013 - XDG Autostart Entries
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1136.001 - Local Account
- T1583.006 - Web Services
- T1058 - Service Registry Permissions Weakness
- T1608 - Stage Capabilities
- T1159 - Launch Agent
MITREへのリンク →
Score: 0.60
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1606.002 - SAML Tokens
- T1218.012 - Verclsid
- T1199 - Trusted Relationship
- T1506 - Web Session Cookie
- T1140 - Deobfuscate/Decode Files or Information
- T1091 - Replication Through Removable Media
- T1608 - Stage Capabilities
- T1087.002 - Domain Account
- T1597 - Search Closed Sources
- T1027.014 - Polymorphic Code
- T1547.013 - XDG Autostart Entries
- T1059.010 - AutoHotKey & AutoIT
- T1213.006 - Databases
- T1583.006 - Web Services
- T1583 - Acquire Infrastructure
- T1176.001 - Browser Extensions
MITREへのリンク →
Score: 0.55
Matched TTPs:
- T1606.002 - SAML Tokens
- T1218.010 - Regsvr32
- T1199 - Trusted Relationship
- T1140 - Deobfuscate/Decode Files or Information
- T1091 - Replication Through Removable Media
- T1087.002 - Domain Account
- T1075 - Pass the Hash
- T1059.010 - AutoHotKey & AutoIT
- T1005 - Data from Local System
- T1187 - Forced Authentication
- T1547.013 - XDG Autostart Entries
- T1583 - Acquire Infrastructure
- T1573 - Encrypted Channel
- T1558 - Steal or Forge Kerberos Tickets
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る