Phantom Stealer Unmasked: Shellcode, Steganography, and Credential Theft
概要
Phantom Stealer is a .NET-based credential-harvesting malware that collects browser credentials, saved passwords, session cookies, cryptocurrency wallet files, and system fingerprints from infected machines. Distributed through phishing emails, cracked software, and malicious links on Discord and Telegram, it employs multiple loader variants including steganography-based delivery and PowerShell shellcode injection. The malware uses extensive anti-analysis techniques including virtualization detection, API patching to disable AMSI and ETW, and timing-based sandbox evasion. It targets Chromium and Gecko-based browsers, cryptocurrency wallets, FileZilla credentials, WinSCP configurations, and Outlook profiles. Additional capabilities include keylogging, screen capture, clipboard monitoring with cryptocurrency address replacement, and Wi-Fi credential theft. The malware achieves persistence through registry Run keys or Startup folder entries.
Created: 2026-07-31
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 14.01
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1590.006 - Network Security Appliances
- T1122 - Component Object Model Hijacking
- T1056 - Input Capture
- T1547.013 - XDG Autostart Entries
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 17.29
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1122 - Component Object Model Hijacking
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 24.42
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1056 - Input Capture
- T1506 - Web Session Cookie
- T1556.009 - Conditional Access Policies
- T1547.013 - XDG Autostart Entries
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 10.04
Matched TTPs:
- T1560.001 - Archive via Utility
- T1051 - Shared Webroot
- T1562.001 - Disable or Modify Tools
- T1547.013 - XDG Autostart Entries
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 11.62
Matched TTPs:
- T1560.001 - Archive via Utility
- T1177 - LSASS Driver
- T1051 - Shared Webroot
- T1656 - Impersonation
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 26.06
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1562.009 - Safe Mode Boot
- T1003.007 - Proc Filesystem
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1083 - File and Directory Discovery
- T1584.002 - DNS Server
- T1547.013 - XDG Autostart Entries
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 9.39
Matched TTPs:
- T1560.001 - Archive via Utility
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
MITREへのリンク →
Score: 22.64
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1136.003 - Cloud Account
- T1056 - Input Capture
- T1547.013 - XDG Autostart Entries
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 13.64
Matched TTPs:
- T1560.001 - Archive via Utility
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
- T1574.009 - Path Interception by Unquoted Path
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 14.14
Matched TTPs:
- T1560.001 - Archive via Utility
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1056 - Input Capture
- T1547.013 - XDG Autostart Entries
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 8.52
Matched TTPs:
- T1560.001 - Archive via Utility
- T1098.007 - Additional Local or Domain Groups
- T1122 - Component Object Model Hijacking
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 11.30
Matched TTPs:
- T1560.001 - Archive via Utility
- T1547.011 - Plist Modification
- T1599 - Network Boundary Bridging
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 19.96
Matched TTPs:
- T1560.001 - Archive via Utility
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1051 - Shared Webroot
- T1122 - Component Object Model Hijacking
- T1027.004 - Compile After Delivery
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 4.19
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
MITREへのリンク →
Score: 5.98
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 9.18
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 24.86
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1574.009 - Path Interception by Unquoted Path
- T1564.003 - Hidden Window
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 25.10
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1547.012 - Print Processors
- T1518.002 - Backup Software Discovery
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 30.81
Matched TTPs:
- T1560.001 - Archive via Utility
- T1222.002 - Linux and Mac Permissions
- T1098.007 - Additional Local or Domain Groups
- T1131 - Authentication Package
- T1562.004 - Disable or Modify System Firewall
- T1547.011 - Plist Modification
- T1122 - Component Object Model Hijacking
- T1574.009 - Path Interception by Unquoted Path
- T1197 - BITS Jobs
- T1547.013 - XDG Autostart Entries
- T1546.007 - Netsh Helper DLL
MITREへのリンク →
Score: 32.84
Matched TTPs:
- T1560.001 - Archive via Utility
- T1113 - Screen Capture
- T1546.013 - PowerShell Profile
- T1099 - Timestomp
- T1003.007 - Proc Filesystem
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
- T1056 - Input Capture
- T1506 - Web Session Cookie
- T1027.004 - Compile After Delivery
- T1556.009 - Conditional Access Policies
- T1547.013 - XDG Autostart Entries
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 9.03
Matched TTPs:
- T1560.001 - Archive via Utility
- T1003.007 - Proc Filesystem
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 12.61
Matched TTPs:
- T1560.001 - Archive via Utility
- T1689 - Downgrade Attack
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 56.67
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
- T1051 - Shared Webroot
- T1654 - Log Enumeration
- T1597 - Search Closed Sources
- T1056 - Input Capture
- T1506 - Web Session Cookie
- T1027.004 - Compile After Delivery
- T1197 - BITS Jobs
- T1656 - Impersonation
- T1547.013 - XDG Autostart Entries
- T1665 - Hide Infrastructure
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 12.39
Matched TTPs:
- T1560.001 - Archive via Utility
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1051 - Shared Webroot
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 15.03
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1504 - PowerShell Profile
- T1027 - Obfuscated Files or Information
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 16.78
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1198 - SIP and Trust Provider Hijacking
- T1090 - Proxy
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 8.74
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
MITREへのリンク →
Score: 18.76
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1051 - Shared Webroot
- T1134.001 - Token Impersonation/Theft
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 18.95
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1056 - Input Capture
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 31.34
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1547.005 - Security Support Provider
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 11.18
Matched TTPs:
- T1560.001 - Archive via Utility
- T1003.007 - Proc Filesystem
- T1562.004 - Disable or Modify System Firewall
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 13.97
Matched TTPs:
- T1560.001 - Archive via Utility
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1055.009 - Proc Memory
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 15.21
Matched TTPs:
- T1560.001 - Archive via Utility
- T1137.005 - Outlook Rules
- T1504 - PowerShell Profile
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1056 - Input Capture
MITREへのリンク →
Score: 10.68
Matched TTPs:
- T1560.001 - Archive via Utility
- T1009 - Binary Padding
- T1056 - Input Capture
- T1506 - Web Session Cookie
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 23.89
Matched TTPs:
- T1113 - Screen Capture
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1562.001 - Disable or Modify Tools
- T1547.013 - XDG Autostart Entries
- T1556 - Modify Authentication Process
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 39.54
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1202 - Indirect Command Execution
- T1562.004 - Disable or Modify System Firewall
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1568 - Dynamic Resolution
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 41.82
Matched TTPs:
- T1666 - Modify Cloud Resource Hierarchy
- T1685.004 - Disable or Modify Linux Audit System Log
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1609 - Container Administration Command
- T1083 - File and Directory Discovery
- T1051 - Shared Webroot
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1056 - Input Capture
- T1197 - BITS Jobs
- T1564.003 - Hidden Window
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1666 - Modify Cloud Resource Hierarchy
MITREへのリンク →
Score: 3.77
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 6.52
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1597 - Search Closed Sources
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 9.40
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 10.14
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1090 - Proxy
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 7.89
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1562.001 - Disable or Modify Tools
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 26.72
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1056 - Input Capture
- T1027.004 - Compile After Delivery
- T1656 - Impersonation
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 4.27
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 18.39
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1527 - Application Access Token
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 18.95
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1056 - Input Capture
- T1547.013 - XDG Autostart Entries
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 16.25
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1518.002 - Backup Software Discovery
- T1598.004 - Spearphishing Voice
- T1573 - Encrypted Channel
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 6.28
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1590.006 - Network Security Appliances
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 16.23
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1183 - Image File Execution Options Injection
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1056 - Input Capture
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.50
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1051 - Shared Webroot
MITREへのリンク →
Score: 6.19
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1562.009 - Safe Mode Boot
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 12.15
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1609 - Container Administration Command
MITREへのリンク →
Score: 13.74
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1056 - Input Capture
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 25.55
Matched TTPs:
- T1099 - Timestomp
- T1527 - Application Access Token
- T1562.009 - Safe Mode Boot
- T1547.012 - Print Processors
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 8.74
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.31
Matched TTPs:
- T1682 - Query Public AI Services
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 10.14
Matched TTPs:
- T1584.008 - Network Devices
- T1530 - Data from Cloud Storage
- T1573 - Encrypted Channel
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 24.82
Matched TTPs:
- T1584.008 - Network Devices
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1654 - Log Enumeration
- T1531 - Account Access Removal
- T1573 - Encrypted Channel
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 21.62
Matched TTPs:
- T1584.008 - Network Devices
- T1098.007 - Additional Local or Domain Groups
- T1218.003 - CMSTP
- T1590.006 - Network Security Appliances
- T1122 - Component Object Model Hijacking
- T1573 - Encrypted Channel
- T1056 - Input Capture
- T1574.009 - Path Interception by Unquoted Path
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 17.35
Matched TTPs:
- T1584.008 - Network Devices
- T1562.004 - Disable or Modify System Firewall
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1056 - Input Capture
- T1656 - Impersonation
MITREへのリンク →
Score: 21.70
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1504 - PowerShell Profile
- T1027 - Obfuscated Files or Information
- T1056 - Input Capture
- T1506 - Web Session Cookie
- T1055.009 - Proc Memory
- T1158 - Hidden Files and Directories
MITREへのリンク →
Score: 29.19
Matched TTPs:
- T1484.002 - Trust Modification
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1122 - Component Object Model Hijacking
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 13.32
Matched TTPs:
- T1484.002 - Trust Modification
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1056 - Input Capture
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 7.58
Matched TTPs:
- T1562.009 - Safe Mode Boot
- T1590.006 - Network Security Appliances
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 25.50
Matched TTPs:
- T1562.009 - Safe Mode Boot
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1051 - Shared Webroot
- T1592.002 - Software
- T1556.009 - Conditional Access Policies
- T1547.013 - XDG Autostart Entries
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 22.90
Matched TTPs:
- T1547.012 - Print Processors
- T1218.003 - CMSTP
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1056 - Input Capture
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 20.27
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1530 - Data from Cloud Storage
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 9.35
Matched TTPs:
- T1530 - Data from Cloud Storage
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 15.95
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1504 - PowerShell Profile
- T1027 - Obfuscated Files or Information
- T1599 - Network Boundary Bridging
- T1486 - Data Encrypted for Impact
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 11.02
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1599 - Network Boundary Bridging
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 11.56
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1056 - Input Capture
- T1027.004 - Compile After Delivery
- T1197 - BITS Jobs
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.92
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 29.58
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1547.013 - XDG Autostart Entries
- T1055.005 - Thread Local Storage
- T1665 - Hide Infrastructure
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 3.80
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 11.09
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 19.75
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1590 - Gather Victim Network Information
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1506 - Web Session Cookie
- T1493 - Transmitted Data Manipulation
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 14.76
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1197 - BITS Jobs
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.80
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 16.80
Matched TTPs:
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1009 - Binary Padding
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 11.55
Matched TTPs:
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1506 - Web Session Cookie
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.59
Matched TTPs:
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 9.20
Matched TTPs:
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 17.69
Matched TTPs:
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1134.001 - Token Impersonation/Theft
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 3.37
Matched TTPs:
- T1562.004 - Disable or Modify System Firewall
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.86
Matched TTPs:
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 8.28
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1584.002 - DNS Server
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 17.06
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1136.003 - Cloud Account
- T1506 - Web Session Cookie
- T1547.013 - XDG Autostart Entries
- T1665 - Hide Infrastructure
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 3.37
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 5.67
Matched TTPs:
- T1122 - Component Object Model Hijacking
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 4.76
Matched TTPs:
- T1122 - Component Object Model Hijacking
- T1056 - Input Capture
MITREへのリンク →
Score: 3.17
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.17
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1531 - Account Access Removal
MITREへのリンク →
Score: 6.23
Matched TTPs:
- T1056 - Input Capture
- T1574.009 - Path Interception by Unquoted Path
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.62
Matched TTPs:
- T1056 - Input Capture
- T1547.013 - XDG Autostart Entries
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 5.13
Matched TTPs:
- T1056 - Input Capture
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 3.12
Matched TTPs:
- T1027.004 - Compile After Delivery
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Score: 5.31
Matched TTPs:
- T1547.013 - XDG Autostart Entries
- T1686 - Disable or Modify System Firewall
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1654 - Log Enumeration
- T1027.004 - Compile After Delivery
- T1609 - Container Administration Command
- T1213.006 - Databases
- T1056 - Input Capture
- T1597 - Search Closed Sources
- T1656 - Impersonation
- T1560.001 - Archive via Utility
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1051 - Shared Webroot
- T1183 - Image File Execution Options Injection
- T1003.007 - Proc Filesystem
- T1197 - BITS Jobs
- T1131 - Authentication Package
- T1546.008 - Accessibility Features
- T1546.013 - PowerShell Profile
- T1506 - Web Session Cookie
- T1490 - Inhibit System Recovery
- T1665 - Hide Infrastructure
- T1547.013 - XDG Autostart Entries
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る