Fake AI Tools Deliver Infostealer
概要
In April 2026, a Malware-as-a-Service NodeJS infostealer campaign evolved its delivery methods, shifting from ClickFix social engineering to weaponized GitHub repositories. Attackers clone legitimate AI-related repositories and developer tools, subtly embedding malicious payloads that target developers and AI users. The campaign employs SmartLoader in a redundant two-stage loader chain, with both stages using EtherHiding to resolve C2 addresses from Polygon blockchain smart contracts at runtime. This technique enables operators to redirect all implants by updating blockchain values without code modification. The first stage uses Prometheus-obfuscated Lua scripts, while the second stage likely uses MoonSec obfuscation. Victims are primarily located in North America, Asia, and Southern Europe, with financial services, banking, and technology sectors most affected. The campaign delivers various infostealers including previously documented NodeJS variants, specifically targeting developers' elevated privileges...
Created: 2026-09-04
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 20.73
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1608.005 - Link Target
- T1552.008 - Chat Messages
- T1122 - Component Object Model Hijacking
- T1055.008 - Ptrace System Calls
MITREへのリンク →
Score: 19.57
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 14.74
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1183 - Image File Execution Options Injection
- T1083 - File and Directory Discovery
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 4.87
Matched TTPs:
- T1560.001 - Archive via Utility
- T1598.003 - Spearphishing Link
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 8.69
Matched TTPs:
- T1560.001 - Archive via Utility
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 26.71
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1686.003 - Windows Host Firewall
- T1003.007 - Proc Filesystem
- T1140 - Deobfuscate/Decode Files or Information
- T1547.005 - Security Support Provider
- T1083 - File and Directory Discovery
- T1552.008 - Chat Messages
- T1584.002 - DNS Server
MITREへのリンク →
Score: 10.98
Matched TTPs:
- T1560.001 - Archive via Utility
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 31.15
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1546.011 - Application Shimming
- T1183 - Image File Execution Options Injection
- T1055.013 - Process Doppelgänging
- T1608.005 - Link Target
- T1087.004 - Cloud Account
- T1136.003 - Cloud Account
- T1059.011 - Lua
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 4.86
Matched TTPs:
- T1560.001 - Archive via Utility
- T1140 - Deobfuscate/Decode Files or Information
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 8.28
Matched TTPs:
- T1560.001 - Archive via Utility
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 4.75
Matched TTPs:
- T1560.001 - Archive via Utility
- T1598.003 - Spearphishing Link
- T1059.011 - Lua
MITREへのリンク →
Score: 7.33
Matched TTPs:
- T1560.001 - Archive via Utility
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 17.18
Matched TTPs:
- T1560.001 - Archive via Utility
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
- T1087.004 - Cloud Account
- T1599 - Network Boundary Bridging
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 21.68
Matched TTPs:
- T1560.001 - Archive via Utility
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1122 - Component Object Model Hijacking
- T1059.011 - Lua
- T1128 - Netsh Helper DLL
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 9.50
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1180 - Screensaver
- T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →
Score: 11.61
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 12.66
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1087.004 - Cloud Account
- T1059.011 - Lua
MITREへのリンク →
Score: 21.91
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1059.011 - Lua
- T1208 - Kerberoasting
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 16.78
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 31.23
Matched TTPs:
- T1560.001 - Archive via Utility
- T1222.002 - Linux and Mac Permissions
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1131 - Authentication Package
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1585 - Establish Accounts
- T1055.008 - Ptrace System Calls
MITREへのリンク →
Score: 18.27
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1099 - Timestomp
- T1003.007 - Proc Filesystem
- T1131 - Authentication Package
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 16.82
Matched TTPs:
- T1560.001 - Archive via Utility
- T1598.003 - Spearphishing Link
- T1003.007 - Proc Filesystem
- T1592.004 - Client Configurations
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1591.001 - Determine Physical Locations
MITREへのリンク →
Score: 13.39
Matched TTPs:
- T1560.001 - Archive via Utility
- T1140 - Deobfuscate/Decode Files or Information
- T1546.011 - Application Shimming
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 50.82
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1598.003 - Spearphishing Link
- T1003.007 - Proc Filesystem
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1546.011 - Application Shimming
- T1009 - Binary Padding
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
- T1608.005 - Link Target
- T1654 - Log Enumeration
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1059.011 - Lua
- T1027.014 - Polymorphic Code
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 11.88
Matched TTPs:
- T1560.001 - Archive via Utility
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1087.004 - Cloud Account
- T1059.011 - Lua
MITREへのリンク →
Score: 10.30
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1598.003 - Spearphishing Link
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 24.79
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1140 - Deobfuscate/Decode Files or Information
- T1055.013 - Process Doppelgänging
- T1198 - SIP and Trust Provider Hijacking
- T1090 - Proxy
- T1087.004 - Cloud Account
- T1059.011 - Lua
MITREへのリンク →
Score: 4.34
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
MITREへのリンク →
Score: 15.46
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1547.005 - Security Support Provider
- T1134.001 - Token Impersonation/Theft
MITREへのリンク →
Score: 19.56
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1110.003 - Password Spraying
- T1608.005 - Link Target
- T1059.011 - Lua
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 31.59
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1021.008 - Direct Cloud VM Connections
- T1016.002 - Wi-Fi Discovery
- T1547.005 - Security Support Provider
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 5.91
Matched TTPs:
- T1560.001 - Archive via Utility
- T1003.007 - Proc Filesystem
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 10.82
Matched TTPs:
- T1560.001 - Archive via Utility
- T1140 - Deobfuscate/Decode Files or Information
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 10.27
Matched TTPs:
- T1560.001 - Archive via Utility
- T1137.005 - Outlook Rules
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 5.40
Matched TTPs:
- T1560.001 - Archive via Utility
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
MITREへのリンク →
Score: 40.46
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1202 - Indirect Command Execution
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1592.004 - Client Configurations
- T1036.002 - Right-to-Left Override
- T1608.005 - Link Target
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 27.05
Matched TTPs:
- T1044 - File System Permissions Weakness
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1608.005 - Link Target
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 29.73
Matched TTPs:
- T1666 - Modify Cloud Resource Hierarchy
- T1685.004 - Disable or Modify Linux Audit System Log
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1083 - File and Directory Discovery
- T1087.004 - Cloud Account
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 5.01
Matched TTPs:
- T1666 - Modify Cloud Resource Hierarchy
- T1598.003 - Spearphishing Link
MITREへのリンク →
Score: 25.89
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1055.013 - Process Doppelgänging
- T1592.004 - Client Configurations
- T1608.005 - Link Target
- T1087.004 - Cloud Account
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 9.00
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1055.013 - Process Doppelgänging
- T1608.005 - Link Target
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 11.92
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1055.013 - Process Doppelgänging
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 8.32
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1090 - Proxy
MITREへのリンク →
Score: 15.62
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1055.013 - Process Doppelgänging
- T1090 - Proxy
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 7.99
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1547.011 - Plist Modification
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 6.38
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
MITREへのリンク →
Score: 15.97
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1527 - Application Access Token
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 20.20
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1055.013 - Process Doppelgänging
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 15.81
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1598.004 - Spearphishing Voice
- T1027.014 - Polymorphic Code
- T1573 - Encrypted Channel
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 4.82
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 14.77
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1183 - Image File Execution Options Injection
- T1552.008 - Chat Messages
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1101 - Security Support Provider
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
MITREへのリンク →
Score: 13.02
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1609 - Container Administration Command
MITREへのリンク →
Score: 9.48
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 32.34
Matched TTPs:
- T1099 - Timestomp
- T1527 - Application Access Token
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1036.002 - Right-to-Left Override
- T1608.005 - Link Target
- T1087.004 - Cloud Account
- T1554 - Compromise Host Software Binary
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1059.011 - Lua
MITREへのリンク →
Score: 14.98
Matched TTPs:
- T1099 - Timestomp
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1036.002 - Right-to-Left Override
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1682 - Query Public AI Services
MITREへのリンク →
Score: 9.37
Matched TTPs:
- T1584.008 - Network Devices
- T1530 - Data from Cloud Storage
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 24.67
Matched TTPs:
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1055.013 - Process Doppelgänging
- T1654 - Log Enumeration
- T1531 - Account Access Removal
- T1573 - Encrypted Channel
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 18.16
Matched TTPs:
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1122 - Component Object Model Hijacking
- T1573 - Encrypted Channel
- T1591.001 - Determine Physical Locations
MITREへのリンク →
Score: 10.44
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 14.53
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1140 - Deobfuscate/Decode Files or Information
- T1027 - Obfuscated Files or Information
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 40.80
Matched TTPs:
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1087.004 - Cloud Account
- T1122 - Component Object Model Hijacking
- T1562.001 - Disable or Modify Tools
- T1059.011 - Lua
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1075 - Pass the Hash
MITREへのリンク →
Score: 19.13
Matched TTPs:
- T1484.002 - Trust Modification
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1087.004 - Cloud Account
- T1554 - Compromise Host Software Binary
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 16.48
Matched TTPs:
- T1180 - Screensaver
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1059.011 - Lua
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 21.79
Matched TTPs:
- T1180 - Screensaver
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1590 - Gather Victim Network Information
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1493 - Transmitted Data Manipulation
MITREへのリンク →
Score: 26.62
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1087.004 - Cloud Account
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1055.005 - Thread Local Storage
MITREへのリンク →
Score: 13.22
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1090 - Proxy
- T1136.003 - Cloud Account
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 3.40
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1003.007 - Proc Filesystem
MITREへのリンク →
Score: 3.16
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1059.011 - Lua
MITREへのリンク →
Score: 6.02
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 5.68
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1036.002 - Right-to-Left Override
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 4.68
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 6.91
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1530 - Data from Cloud Storage
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 7.05
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1608.005 - Link Target
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 5.96
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1055.013 - Process Doppelgänging
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 5.01
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1584.002 - DNS Server
MITREへのリンク →
Score: 14.53
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1055.013 - Process Doppelgänging
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 12.23
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1059.011 - Lua
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 5.68
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1036.002 - Right-to-Left Override
MITREへのリンク →
Score: 3.22
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 5.96
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 7.84
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1055.013 - Process Doppelgänging
- T1059.011 - Lua
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.65
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 4.40
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
MITREへのリンク →
Score: 5.01
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1531 - Account Access Removal
MITREへのリンク →
Score: 5.56
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1562.001 - Disable or Modify Tools
- T1059.011 - Lua
MITREへのリンク →
Score: 7.27
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 12.02
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1110.003 - Password Spraying
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1530 - Data from Cloud Storage
MITREへのリンク →
Score: 3.76
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1059.011 - Lua
MITREへのリンク →
Score: 7.14
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1122 - Component Object Model Hijacking
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 14.99
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 3.81
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 14.05
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1134.001 - Token Impersonation/Theft
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 4.22
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 3.81
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
MITREへのリンク →
Score: 4.76
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
MITREへのリンク →
Score: 7.66
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1110.003 - Password Spraying
MITREへのリンク →
Score: 12.24
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1027 - Obfuscated Files or Information
- T1599 - Network Boundary Bridging
- T1486 - Data Encrypted for Impact
MITREへのリンク →
Score: 10.40
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1599 - Network Boundary Bridging
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 7.84
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
- T1087.004 - Cloud Account
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 9.95
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1036.002 - Right-to-Left Override
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 11.09
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 12.96
Matched TTPs:
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 9.28
Matched TTPs:
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 6.03
Matched TTPs:
- T1177 - LSASS Driver
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 4.31
Matched TTPs:
- T1055.013 - Process Doppelgänging
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 4.76
Matched TTPs:
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 3.84
Matched TTPs:
- T1591.001 - Determine Physical Locations
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1598.003 - Spearphishing Link
- T1597 - Search Closed Sources
- T1560.001 - Archive via Utility
- T1009 - Binary Padding
- T1213.006 - Databases
- T1654 - Log Enumeration
- T1140 - Deobfuscate/Decode Files or Information
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1059.011 - Lua
- T1609 - Container Administration Command
- T1027.004 - Compile After Delivery
- T1027.014 - Polymorphic Code
- T1087.004 - Cloud Account
- T1003.007 - Proc Filesystem
- T1608.005 - Link Target
- T1546.011 - Application Shimming
- T1131 - Authentication Package
- T1546.008 - Accessibility Features
MITREへのリンク →
Score: 0.56
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1087.004 - Cloud Account
- T1484.002 - Trust Modification
- T1183 - Image File Execution Options Injection
- T1122 - Component Object Model Hijacking
- T1059.011 - Lua
- T1075 - Pass the Hash
- T1686.003 - Windows Host Firewall
- T1573 - Encrypted Channel
- T1598.003 - Spearphishing Link
- T1016.002 - Wi-Fi Discovery
- T1546.008 - Accessibility Features
- T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →
Score: 0.56
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1556.008 - Network Provider DLL
- T1202 - Indirect Command Execution
- T1122 - Component Object Model Hijacking
- T1592.004 - Client Configurations
- T1584.008 - Network Devices
- T1177 - LSASS Driver
- T1598.003 - Spearphishing Link
- T1036.002 - Right-to-Left Override
- T1027.004 - Compile After Delivery
- T1099 - Timestomp
- T1140 - Deobfuscate/Decode Files or Information
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る