New Armored Likho tools target Telegram and eavesdropping
概要
In May 2026, a cyber-espionage campaign by the Armored Likho group (also known as Eagle Werewolf) targeted private individuals and organizations across Russia, including major corporations, public sector entities, IT companies, and educational institutions. The attackers employed fake donation service applications as initial infection vectors. The campaign introduced the Still Toolkit, comprising two Rust-based components: Still Sync, which steals Telegram session data and leverages the Telegram API to extract chat logs and media files, and Still Audio, an implant that conducts covert audio surveillance by detecting speech patterns and recording conversations. The toolkit demonstrates sophisticated capabilities including Dead Drop Resolver techniques, RMS-based voice activity detection, and gRPC-based C2 communications. The campaign shows significant code overlap with previous Armored Likho operations, particularly from February 2026, including identical dropper architecture, encryption algorithms, and inf...
Created: 2026-09-13
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 11.20
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1487 - Disk Structure Wipe
- T1608.005 - Link Target
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 14.48
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
MITREへのリンク →
Score: 16.73
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1183 - Image File Execution Options Injection
- T1588.001 - Malware
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 11.93
Matched TTPs:
- T1560.001 - Archive via Utility
- T1562 - Impair Defenses
- T1051 - Shared Webroot
- T1562.001 - Disable or Modify Tools
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 15.28
Matched TTPs:
- T1560.001 - Archive via Utility
- T1177 - LSASS Driver
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1051 - Shared Webroot
- T1656 - Impersonation
MITREへのリンク →
Score: 32.41
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1560.003 - Archive via Custom Method
- T1686.003 - Windows Host Firewall
- T1003.007 - Proc Filesystem
- T1562 - Impair Defenses
- T1547.005 - Security Support Provider
- T1083 - File and Directory Discovery
- T1065 - Uncommonly Used Port
- T1159 - Launch Agent
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 10.11
Matched TTPs:
- T1560.001 - Archive via Utility
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 31.51
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1546.011 - Application Shimming
- T1183 - Image File Execution Options Injection
- T1055.013 - Process Doppelgänging
- T1608.005 - Link Target
- T1136.003 - Cloud Account
- T1159 - Launch Agent
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 8.58
Matched TTPs:
- T1560.001 - Archive via Utility
- T1552.003 - Shell History
- T1597 - Search Closed Sources
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 13.67
Matched TTPs:
- T1560.001 - Archive via Utility
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1574 - Hijack Execution Flow
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 5.78
Matched TTPs:
- T1560.001 - Archive via Utility
- T1098.007 - Additional Local or Domain Groups
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 11.69
Matched TTPs:
- T1560.001 - Archive via Utility
- T1562 - Impair Defenses
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 18.30
Matched TTPs:
- T1560.001 - Archive via Utility
- T1487 - Disk Structure Wipe
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1051 - Shared Webroot
- T1128 - Netsh Helper DLL
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.19
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
MITREへのリンク →
Score: 8.17
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 6.93
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1547.011 - Plist Modification
MITREへのリンク →
Score: 29.17
Matched TTPs:
- T1560.001 - Archive via Utility
- T1560.003 - Archive via Custom Method
- T1584.008 - Network Devices
- T1562 - Impair Defenses
- T1177 - LSASS Driver
- T1588.001 - Malware
- T1208 - Kerberoasting
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 20.40
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1562 - Impair Defenses
- T1547.011 - Plist Modification
- T1051 - Shared Webroot
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1159 - Launch Agent
MITREへのリンク →
Score: 20.63
Matched TTPs:
- T1560.001 - Archive via Utility
- T1222.002 - Linux and Mac Permissions
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1131 - Authentication Package
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1200 - Hardware Additions
MITREへのリンク →
Score: 24.56
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1099 - Timestomp
- T1003.007 - Proc Filesystem
- T1131 - Authentication Package
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1218.001 - Compiled HTML File
- T1027.004 - Compile After Delivery
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 11.00
Matched TTPs:
- T1560.001 - Archive via Utility
- T1003.007 - Proc Filesystem
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1159 - Launch Agent
MITREへのリンク →
Score: 11.67
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.011 - Application Shimming
- T1588.001 - Malware
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 51.08
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1546.011 - Application Shimming
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1588.001 - Malware
- T1609 - Container Administration Command
- T1051 - Shared Webroot
- T1552.003 - Shell History
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1656 - Impersonation
- T1665 - Hide Infrastructure
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 13.43
Matched TTPs:
- T1560.001 - Archive via Utility
- T1560.003 - Archive via Custom Method
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1051 - Shared Webroot
MITREへのリンク →
Score: 12.17
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 19.06
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1055.013 - Process Doppelgänging
- T1198 - SIP and Trust Provider Hijacking
- T1090 - Proxy
MITREへのリンク →
Score: 4.34
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
MITREへのリンク →
Score: 24.42
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1560.003 - Archive via Custom Method
- T1584.008 - Network Devices
- T1547.005 - Security Support Provider
- T1588.001 - Malware
- T1051 - Shared Webroot
- T1552.003 - Shell History
- T1134.001 - Token Impersonation/Theft
MITREへのリンク →
Score: 19.43
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1110.003 - Password Spraying
- T1608.005 - Link Target
- T1218.001 - Compiled HTML File
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 25.34
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1588.001 - Malware
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 8.01
Matched TTPs:
- T1560.001 - Archive via Utility
- T1003.007 - Proc Filesystem
- T1588.001 - Malware
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 11.88
Matched TTPs:
- T1560.001 - Archive via Utility
- T1083 - File and Directory Discovery
- T1552.003 - Shell History
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 8.25
Matched TTPs:
- T1560.001 - Archive via Utility
- T1552.003 - Shell History
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 4.43
Matched TTPs:
- T1560.001 - Archive via Utility
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 35.04
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1202 - Indirect Command Execution
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1608.005 - Link Target
- T1027.012 - LNK Icon Smuggling
- T1556.008 - Network Provider DLL
- T1027.004 - Compile After Delivery
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 33.79
Matched TTPs:
- T1044 - File System Permissions Weakness
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1552.003 - Shell History
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
- T1656 - Impersonation
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 23.96
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1556 - Modify Authentication Process
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 8.12
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1055.013 - Process Doppelgänging
- T1608.005 - Link Target
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 18.55
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1562 - Impair Defenses
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 10.19
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1090 - Proxy
- T1159 - Launch Agent
MITREへのリンク →
Score: 17.02
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1055.013 - Process Doppelgänging
- T1090 - Proxy
- T1588.001 - Malware
- T1218.001 - Compiled HTML File
MITREへのリンク →
Score: 7.12
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 5.50
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
MITREへのリンク →
Score: 20.90
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1560.003 - Archive via Custom Method
- T1527 - Application Access Token
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 23.89
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1055.013 - Process Doppelgänging
- T1588.001 - Malware
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1065 - Uncommonly Used Port
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 12.19
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.004 - Spearphishing Voice
- T1573 - Encrypted Channel
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 6.90
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1588.001 - Malware
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 13.44
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1183 - Image File Execution Options Injection
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 11.70
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1562 - Impair Defenses
- T1101 - Security Support Provider
- T1051 - Shared Webroot
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
MITREへのリンク →
Score: 4.64
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1562 - Impair Defenses
MITREへのリンク →
Score: 12.15
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1609 - Container Administration Command
MITREへのリンク →
Score: 18.51
Matched TTPs:
- T1099 - Timestomp
- T1562 - Impair Defenses
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1065 - Uncommonly Used Port
- T1159 - Launch Agent
MITREへのリンク →
Score: 31.20
Matched TTPs:
- T1099 - Timestomp
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1608.005 - Link Target
- T1554 - Compromise Host Software Binary
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1200 - Hardware Additions
- T1086 - PowerShell
MITREへのリンク →
Score: 10.82
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1682 - Query Public AI Services
MITREへのリンク →
Score: 35.80
Matched TTPs:
- T1560.003 - Archive via Custom Method
- T1685.004 - Disable or Modify Linux Audit System Log
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1083 - File and Directory Discovery
- T1051 - Shared Webroot
- T1552.003 - Shell History
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 9.37
Matched TTPs:
- T1584.008 - Network Devices
- T1530 - Data from Cloud Storage
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 19.00
Matched TTPs:
- T1584.008 - Network Devices
- T1098.007 - Additional Local or Domain Groups
- T1055.013 - Process Doppelgänging
- T1531 - Account Access Removal
- T1573 - Encrypted Channel
- T1027.004 - Compile After Delivery
- T1200 - Hardware Additions
MITREへのリンク →
Score: 13.36
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1218.003 - CMSTP
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 14.94
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1656 - Impersonation
MITREへのリンク →
Score: 19.07
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1588.001 - Malware
- T1552.003 - Shell History
- T1027.012 - LNK Icon Smuggling
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 31.45
Matched TTPs:
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1075 - Pass the Hash
MITREへのリンク →
Score: 12.07
Matched TTPs:
- T1484.002 - Trust Modification
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1554 - Compromise Host Software Binary
MITREへのリンク →
Score: 7.27
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 10.18
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1608.005 - Link Target
- T1200 - Hardware Additions
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 19.25
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1562 - Impair Defenses
- T1098.007 - Additional Local or Domain Groups
- T1055.013 - Process Doppelgänging
- T1051 - Shared Webroot
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 8.86
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1530 - Data from Cloud Storage
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 23.75
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1090 - Proxy
- T1136.003 - Cloud Account
- T1128 - Netsh Helper DLL
- T1200 - Hardware Additions
- T1159 - Launch Agent
- T1665 - Hide Infrastructure
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 15.04
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1110.003 - Password Spraying
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 8.61
Matched TTPs:
- T1530 - Data from Cloud Storage
- T1588.001 - Malware
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 5.01
Matched TTPs:
- T1562 - Impair Defenses
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 5.19
Matched TTPs:
- T1562 - Impair Defenses
- T1552.003 - Shell History
MITREへのリンク →
Score: 8.40
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1027 - Obfuscated Files or Information
- T1486 - Data Encrypted for Impact
MITREへのリンク →
Score: 6.55
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 3.53
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
MITREへのリンク →
Score: 7.97
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1588.001 - Malware
- T1608.005 - Link Target
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.66
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 33.24
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1547.011 - Plist Modification
- T1588.001 - Malware
- T1608.005 - Link Target
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1055.005 - Thread Local Storage
- T1665 - Hide Infrastructure
- T1086 - PowerShell
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 3.80
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 11.09
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 10.19
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1590 - Gather Victim Network Information
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 9.07
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 3.61
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1588.001 - Malware
MITREへのリンク →
Score: 7.43
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1218.001 - Compiled HTML File
MITREへのリンク →
Score: 17.84
Matched TTPs:
- T1218.003 - CMSTP
- T1183 - Image File Execution Options Injection
- T1552.003 - Shell History
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 17.68
Matched TTPs:
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1065 - Uncommonly Used Port
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 5.81
Matched TTPs:
- T1131 - Authentication Package
- T1552.003 - Shell History
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.59
Matched TTPs:
- T1110.003 - Password Spraying
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 4.68
Matched TTPs:
- T1055.013 - Process Doppelgänging
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1055.013 - Process Doppelgänging
- T1159 - Launch Agent
MITREへのリンク →
Score: 4.49
Matched TTPs:
- T1588.001 - Malware
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 4.86
Matched TTPs:
- T1552.003 - Shell History
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.86
Matched TTPs:
- T1552.003 - Shell History
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 5.45
Matched TTPs:
- T1608.005 - Link Target
- T1656 - Impersonation
MITREへのリンク →
Score: 8.27
Matched TTPs:
- T1134.001 - Token Impersonation/Theft
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 9.61
Matched TTPs:
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 6.54
Matched TTPs:
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 7.28
Matched TTPs:
- T1531 - Account Access Removal
- T1200 - Hardware Additions
MITREへのリンク →
Score: 5.90
Matched TTPs:
- T1200 - Hardware Additions
- T1159 - Launch Agent
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1546.011 - Application Shimming
- T1665 - Hide Infrastructure
- T1051 - Shared Webroot
- T1608.005 - Link Target
- T1546.013 - PowerShell Profile
- T1588.001 - Malware
- T1656 - Impersonation
- T1098.007 - Additional Local or Domain Groups
- T1609 - Container Administration Command
- T1131 - Authentication Package
- T1490 - Inhibit System Recovery
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1003.007 - Proc Filesystem
- T1560.001 - Archive via Utility
- T1213.006 - Databases
- T1552.003 - Shell History
- T1546.008 - Accessibility Features
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る