0040eff71 malware on Metadefender.com
概要
0040eff71 malware has shown the following behaviors: trojan,malware,keylogger,hack,riskware ; 0040eff71 malware has targeted following platforms: win64,win32,vbscripts,html,msword ; 0040eff71 malware has used the following delivery mechanisms: downloader,dropper,p2p,packed,blackhole ;
Created: 2026-02-23
Indicators
Indicatorsは見つかっていない。
類似Pulses
このPulseに関連する脅威アクター (事実ベース)
Score: 8.28
Matched TTPs:
- T1682 - Query Public AI Services
- T1091 - Replication Through Removable Media
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 15.92
Matched TTPs:
- T1606.002 - SAML Tokens
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1608 - Stage Capabilities
- T1597 - Search Closed Sources
- T1027.014 - Polymorphic Code
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 7.58
Matched TTPs:
- T1606.002 - SAML Tokens
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
MITREへのリンク →
Score: 11.09
Matched TTPs:
- T1606.002 - SAML Tokens
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1573 - Encrypted Channel
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 3.89
Matched TTPs:
- T1606.002 - SAML Tokens
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 24.53
Matched TTPs:
- T1606.002 - SAML Tokens
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1070.008 - Clear Mailbox Data
- T1597 - Search Closed Sources
- T1174 - Password Filter DLL
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1055.005 - Thread Local Storage
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 19.65
Matched TTPs:
- T1606.002 - SAML Tokens
- T1091 - Replication Through Removable Media
- T1558 - Steal or Forge Kerberos Tickets
- T1597 - Search Closed Sources
- T1059.006 - Python
- T1221 - Template Injection
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 19.12
Matched TTPs:
- T1606.002 - SAML Tokens
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1005 - Data from Local System
- T1558 - Steal or Forge Kerberos Tickets
- T1048 - Exfiltration Over Alternative Protocol
- T1218.010 - Regsvr32
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 7.84
Matched TTPs:
- T1606.002 - SAML Tokens
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 8.26
Matched TTPs:
- T1606.002 - SAML Tokens
- T1089 - Disabling Security Tools
- T1091 - Replication Through Removable Media
- T1136.002 - Domain Account
MITREへのリンク →
Score: 19.93
Matched TTPs:
- T1606.002 - SAML Tokens
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1005 - Data from Local System
- T1558 - Steal or Forge Kerberos Tickets
- T1187 - Forced Authentication
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 14.49
Matched TTPs:
- T1606.002 - SAML Tokens
- T1138 - Application Shimming
- T1218.010 - Regsvr32
- T1223 - Compiled HTML File
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 5.79
Matched TTPs:
- T1606.002 - SAML Tokens
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 5.78
Matched TTPs:
- T1606.002 - SAML Tokens
- T1558 - Steal or Forge Kerberos Tickets
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 11.58
Matched TTPs:
- T1606.002 - SAML Tokens
- T1059.010 - AutoHotKey & AutoIT
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 3.66
Matched TTPs:
- T1606.002 - SAML Tokens
- T1059.010 - AutoHotKey & AutoIT
MITREへのリンク →
Score: 16.84
Matched TTPs:
- T1606.002 - SAML Tokens
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1608 - Stage Capabilities
- T1218.010 - Regsvr32
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 11.52
Matched TTPs:
- T1606.002 - SAML Tokens
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1558 - Steal or Forge Kerberos Tickets
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 13.10
Matched TTPs:
- T1606.002 - SAML Tokens
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1011.001 - Exfiltration Over Bluetooth
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 3.30
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
MITREへのリンク →
Score: 16.25
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1518.002 - Backup Software Discovery
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
- T1059.013 - Container CLI/API
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 3.53
Matched TTPs:
- T1089 - Disabling Security Tools
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 3.50
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 3.23
Matched TTPs:
- T1089 - Disabling Security Tools
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 6.89
Matched TTPs:
- T1089 - Disabling Security Tools
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 7.89
Matched TTPs:
- T1089 - Disabling Security Tools
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 5.02
Matched TTPs:
- T1089 - Disabling Security Tools
- T1174 - Password Filter DLL
MITREへのリンク →
Score: 4.80
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 15.18
Matched TTPs:
- T1089 - Disabling Security Tools
- T1091 - Replication Through Removable Media
- T1558 - Steal or Forge Kerberos Tickets
- T1027.014 - Polymorphic Code
- T1174 - Password Filter DLL
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 8.01
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 6.69
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 9.50
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1136.002 - Domain Account
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 10.54
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 3.23
Matched TTPs:
- T1089 - Disabling Security Tools
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 3.23
Matched TTPs:
- T1089 - Disabling Security Tools
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 5.61
Matched TTPs:
- T1089 - Disabling Security Tools
- T1091 - Replication Through Removable Media
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 9.71
Matched TTPs:
- T1089 - Disabling Security Tools
- T1573 - Encrypted Channel
- T1174 - Password Filter DLL
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 3.63
Matched TTPs:
- T1089 - Disabling Security Tools
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 11.46
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 4.19
Matched TTPs:
- T1089 - Disabling Security Tools
- T1136.002 - Domain Account
MITREへのリンク →
Score: 7.81
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1027.014 - Polymorphic Code
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 5.13
Matched TTPs:
- T1089 - Disabling Security Tools
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 9.60
Matched TTPs:
- T1089 - Disabling Security Tools
- T1048 - Exfiltration Over Alternative Protocol
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 8.77
Matched TTPs:
- T1089 - Disabling Security Tools
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1174 - Password Filter DLL
MITREへのリンク →
Score: 4.85
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
MITREへのリンク →
Score: 14.93
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1136.002 - Domain Account
- T1138 - Application Shimming
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
MITREへのリンク →
Score: 7.04
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
MITREへのリンク →
Score: 5.05
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 20.88
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1138 - Application Shimming
- T1048 - Exfiltration Over Alternative Protocol
- T1597 - Search Closed Sources
- T1174 - Password Filter DLL
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 4.31
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 3.36
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 5.55
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 5.70
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1070.008 - Clear Mailbox Data
MITREへのリンク →
Score: 6.73
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 14.70
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1608 - Stage Capabilities
- T1597 - Search Closed Sources
- T1059.013 - Container CLI/API
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 11.55
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1548.004 - Elevated Execution with Prompt
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 5.52
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1558 - Steal or Forge Kerberos Tickets
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 7.24
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 7.57
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1027.014 - Polymorphic Code
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 8.89
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1597 - Search Closed Sources
- T1059.013 - Container CLI/API
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 3.47
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 8.13
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 6.62
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1558 - Steal or Forge Kerberos Tickets
- T1136.002 - Domain Account
MITREへのリンク →
Score: 3.47
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 5.26
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 5.99
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1218.010 - Regsvr32
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 3.87
Matched TTPs:
- T1091 - Replication Through Removable Media
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 11.78
Matched TTPs:
- T1005 - Data from Local System
- T1558 - Steal or Forge Kerberos Tickets
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 8.37
Matched TTPs:
- T1558 - Steal or Forge Kerberos Tickets
- T1506 - Web Session Cookie
- T1059.012 - Hypervisor CLI
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 4.93
Matched TTPs:
- T1558 - Steal or Forge Kerberos Tickets
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 3.95
Matched TTPs:
- T1558 - Steal or Forge Kerberos Tickets
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 13.20
Matched TTPs:
- T1518.002 - Backup Software Discovery
- T1027.014 - Polymorphic Code
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 9.56
Matched TTPs:
- T1136.002 - Domain Account
- T1187 - Forced Authentication
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 4.26
Matched TTPs:
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 7.73
Matched TTPs:
- T1048 - Exfiltration Over Alternative Protocol
- T1059.012 - Hypervisor CLI
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1048 - Exfiltration Over Alternative Protocol
MITREへのリンク →
Score: 3.70
Matched TTPs:
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 4.32
Matched TTPs:
- T1597 - Search Closed Sources
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 9.93
Matched TTPs:
- T1597 - Search Closed Sources
- T1187 - Forced Authentication
- T1059.012 - Hypervisor CLI
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 3.70
Matched TTPs:
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 4.65
Matched TTPs:
- T1027.014 - Polymorphic Code
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 4.24
Matched TTPs:
- T1027.014 - Polymorphic Code
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 6.19
Matched TTPs:
- T1573 - Encrypted Channel
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 3.39
Matched TTPs:
- T1218.010 - Regsvr32
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 7.80
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
- T1160 - Launch Daemon
MITREへのリンク →
Score: 3.26
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 5.12
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.013 - Container CLI/API
MITREへのリンク →
Score: 3.26
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 3.26
Matched TTPs:
- T1218.010 - Regsvr32
- T1059.012 - Hypervisor CLI
MITREへのリンク →
Score: 4.42
Matched TTPs:
- T1506 - Web Session Cookie
- T1547.008 - LSASS Driver
MITREへのリンク →
Score: 4.29
Matched TTPs:
- T1059.012 - Hypervisor CLI
- T1547.008 - LSASS Driver
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.78
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1059.012 - Hypervisor CLI
- T1547.008 - LSASS Driver
- T1606.002 - SAML Tokens
- T1055.005 - Thread Local Storage
- T1174 - Password Filter DLL
- T1597 - Search Closed Sources
- T1089 - Disabling Security Tools
- T1070.008 - Clear Mailbox Data
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 0.70
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1059.012 - Hypervisor CLI
- T1506 - Web Session Cookie
- T1048 - Exfiltration Over Alternative Protocol
- T1174 - Password Filter DLL
- T1597 - Search Closed Sources
- T1138 - Application Shimming
MITREへのリンク →
Score: 0.67
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1606.002 - SAML Tokens
- T1573 - Encrypted Channel
- T1005 - Data from Local System
- T1558 - Steal or Forge Kerberos Tickets
- T1218.010 - Regsvr32
- T1187 - Forced Authentication
MITREへのリンク →
Score: 0.63
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1547.008 - LSASS Driver
- T1091 - Replication Through Removable Media
- T1606.002 - SAML Tokens
- T1048 - Exfiltration Over Alternative Protocol
- T1005 - Data from Local System
- T1558 - Steal or Forge Kerberos Tickets
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 0.63
Matched TTPs:
- T1547.008 - LSASS Driver
- T1091 - Replication Through Removable Media
- T1606.002 - SAML Tokens
- T1221 - Template Injection
- T1597 - Search Closed Sources
- T1059.006 - Python
- T1558 - Steal or Forge Kerberos Tickets
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1685.002 - Disable or Modify Cloud Log
- T1059.010 - AutoHotKey & AutoIT
- T1136.002 - Domain Account
- T1091 - Replication Through Removable Media
- T1597 - Search Closed Sources
- T1138 - Application Shimming
MITREへのリンク →
Score: 0.57
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1506 - Web Session Cookie
- T1059.013 - Container CLI/API
- T1518.002 - Backup Software Discovery
- T1597 - Search Closed Sources
- T1089 - Disabling Security Tools
- T1218.010 - Regsvr32
MITREへのリンク →
Score: 0.55
Matched TTPs:
- T1059.010 - AutoHotKey & AutoIT
- T1091 - Replication Through Removable Media
- T1606.002 - SAML Tokens
- T1055.005 - Thread Local Storage
- T1608 - Stage Capabilities
- T1089 - Disabling Security Tools
- T1218.010 - Regsvr32
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る