Inside a Packed Android RAT Loader
概要
Hagaseca is an Android malware cluster linked to exposed Android Debug Bridge (ADB) services, focusing on the THost9 RAT loader variant. The malware conceals executable code within an APK that loads tc9.dex, a stage providing shell access, file transfer, and ADB propagation capabilities. Public incidents connect THost4 and THost9 to exposed Android and Redroid systems from October 2024 through 2026. The loader uses XOR and gzip packing, establishes persistence through foreground services, exploits accessibility features for device control, and downloads additional stages from test.hagaseca.com. The tc9.dex stage implements remote administration, discovers ADB endpoints via mDNS, scans entire /16 networks, authenticates with prepared keys, and installs itself on vulnerable systems. The malware exhibits worm-like behavior, spreading opportunistically through unsecured ADB services exposed to the internet, particularly affecting Redroid container deployments and devices with public ADB over Wi-Fi.
Created: 2026-09-09
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 22.46
Matched TTPs:
- T1044 - File System Permissions Weakness
- T1098.007 - Additional Local or Domain Groups
- T1131 - Authentication Package
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
- T1601.001 - Patch System Image
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 25.89
Matched TTPs:
- T1099 - Timestomp
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 9.33
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 44.55
Matched TTPs:
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1202 - Indirect Command Execution
- T1140 - Deobfuscate/Decode Files or Information
- T1562.004 - Disable or Modify System Firewall
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1592.004 - Client Configurations
- T1104 - Multi-Stage Channels
- T1027.012 - LNK Icon Smuggling
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1027.004 - Compile After Delivery
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 22.49
Matched TTPs:
- T1099 - Timestomp
- T1527 - Application Access Token
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 6.94
Matched TTPs:
- T1099 - Timestomp
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 5.95
Matched TTPs:
- T1099 - Timestomp
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 16.67
Matched TTPs:
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1134.001 - Token Impersonation/Theft
MITREへのリンク →
Score: 17.42
Matched TTPs:
- T1099 - Timestomp
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1590.006 - Network Security Appliances
- T1122 - Component Object Model Hijacking
- T1055.008 - Ptrace System Calls
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 21.53
Matched TTPs:
- T1099 - Timestomp
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1556.009 - Conditional Access Policies
- T1601.001 - Patch System Image
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 25.00
Matched TTPs:
- T1099 - Timestomp
- T1686.003 - Windows Host Firewall
- T1140 - Deobfuscate/Decode Files or Information
- T1590.006 - Network Security Appliances
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1102 - Web Service
- T1488 - Disk Content Wipe
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 10.57
Matched TTPs:
- T1099 - Timestomp
- T1598.003 - Spearphishing Link
- T1027 - Obfuscated Files or Information
- T1601.001 - Patch System Image
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1682 - Query Public AI Services
MITREへのリンク →
Score: 9.37
Matched TTPs:
- T1584.008 - Network Devices
- T1530 - Data from Cloud Storage
- T1573 - Encrypted Channel
MITREへのリンク →
Score: 11.99
Matched TTPs:
- T1584.008 - Network Devices
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 20.47
Matched TTPs:
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1573 - Encrypted Channel
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 21.59
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1198 - SIP and Trust Provider Hijacking
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 10.02
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 30.01
Matched TTPs:
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
- T1048 - Exfiltration Over Alternative Protocol
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1574.009 - Path Interception by Unquoted Path
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 13.08
Matched TTPs:
- T1584.008 - Network Devices
- T1180 - Screensaver
- T1140 - Deobfuscate/Decode Files or Information
- T1055.004 - Asynchronous Procedure Call
- T1102 - Web Service
MITREへのリンク →
Score: 21.18
Matched TTPs:
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 25.09
Matched TTPs:
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1218.003 - CMSTP
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1122 - Component Object Model Hijacking
- T1573 - Encrypted Channel
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 20.56
Matched TTPs:
- T1584.008 - Network Devices
- T1598.003 - Spearphishing Link
- T1590.006 - Network Security Appliances
- T1083 - File and Directory Discovery
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1556.009 - Conditional Access Policies
- T1601.001 - Patch System Image
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 19.00
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1562.004 - Disable or Modify System Firewall
- T1051 - Shared Webroot
- T1102 - Web Service
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 33.94
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1609 - Container Administration Command
- T1083 - File and Directory Discovery
- T1051 - Shared Webroot
- T1087.004 - Cloud Account
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1197 - BITS Jobs
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 23.20
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1140 - Deobfuscate/Decode Files or Information
- T1027.012 - LNK Icon Smuggling
- T1027 - Obfuscated Files or Information
- T1027.014 - Polymorphic Code
- T1158 - Hidden Files and Directories
MITREへのリンク →
Score: 42.42
Matched TTPs:
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1562.004 - Disable or Modify System Firewall
- T1546.008 - Accessibility Features
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1122 - Component Object Model Hijacking
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1075 - Pass the Hash
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 19.15
Matched TTPs:
- T1484.002 - Trust Modification
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1087.004 - Cloud Account
- T1027.014 - Polymorphic Code
- T1488 - Disk Content Wipe
MITREへのリンク →
Score: 44.96
Matched TTPs:
- T1213.006 - Databases
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
- T1051 - Shared Webroot
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1027.014 - Polymorphic Code
- T1027.004 - Compile After Delivery
- T1197 - BITS Jobs
- T1601.001 - Patch System Image
- T1665 - Hide Infrastructure
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 18.38
Matched TTPs:
- T1527 - Application Access Token
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 14.19
Matched TTPs:
- T1180 - Screensaver
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 26.97
Matched TTPs:
- T1180 - Screensaver
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1590 - Gather Victim Network Information
- T1048 - Exfiltration Over Alternative Protocol
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1493 - Transmitted Data Manipulation
MITREへのリンク →
Score: 17.08
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1518.002 - Backup Software Discovery
- T1598.004 - Spearphishing Voice
- T1027.014 - Polymorphic Code
- T1573 - Encrypted Channel
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 31.10
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1055.005 - Thread Local Storage
- T1665 - Hide Infrastructure
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 5.01
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1055.013 - Process Doppelgänging
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 19.18
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
- T1136.003 - Cloud Account
- T1665 - Hide Infrastructure
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 11.81
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1055.013 - Process Doppelgänging
- T1597 - Search Closed Sources
- T1601.001 - Patch System Image
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 41.64
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1139 - Bash History
- T1131 - Authentication Package
- T1562.004 - Disable or Modify System Firewall
- T1547.011 - Plist Modification
- T1104 - Multi-Stage Channels
- T1122 - Component Object Model Hijacking
- T1574.009 - Path Interception by Unquoted Path
- T1197 - BITS Jobs
- T1055.008 - Ptrace System Calls
- T1546.007 - Netsh Helper DLL
MITREへのリンク →
Score: 4.08
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 8.86
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1592.004 - Client Configurations
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.02
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 22.93
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1518.002 - Backup Software Discovery
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 29.46
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1592.004 - Client Configurations
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
- T1601.001 - Patch System Image
- T1556 - Modify Authentication Process
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 3.62
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 8.54
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1051 - Shared Webroot
- T1562.001 - Disable or Modify Tools
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 11.60
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1530 - Data from Cloud Storage
- T1601.001 - Patch System Image
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 5.48
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1027.014 - Polymorphic Code
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 17.58
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1051 - Shared Webroot
- T1122 - Component Object Model Hijacking
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 16.24
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1055.013 - Process Doppelgänging
- T1090 - Proxy
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 7.15
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1590.006 - Network Security Appliances
- T1087.004 - Cloud Account
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 7.87
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1087.004 - Cloud Account
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 9.30
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1027.014 - Polymorphic Code
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 5.83
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1609 - Container Administration Command
MITREへのリンク →
Score: 4.26
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 26.55
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1055.004 - Asynchronous Procedure Call
- T1102 - Web Service
- T1087.004 - Cloud Account
- T1136.003 - Cloud Account
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 24.79
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1048 - Exfiltration Over Alternative Protocol
- T1556.009 - Conditional Access Policies
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 12.57
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1197 - BITS Jobs
MITREへのリンク →
Score: 3.22
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 5.96
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 9.68
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 20.74
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1055.013 - Process Doppelgänging
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1573 - Encrypted Channel
- T1601.001 - Patch System Image
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 5.56
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1055.013 - Process Doppelgänging
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.36
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1098.007 - Additional Local or Domain Groups
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 11.32
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1547.011 - Plist Modification
- T1048 - Exfiltration Over Alternative Protocol
- T1562.001 - Disable or Modify Tools
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 7.78
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 3.27
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 11.74
Matched TTPs:
- T1598.003 - Spearphishing Link
- T1140 - Deobfuscate/Decode Files or Information
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
- T1087.004 - Cloud Account
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 7.27
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
- T1055.013 - Process Doppelgänging
MITREへのリンク →
Score: 16.60
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1087.004 - Cloud Account
- T1574 - Hijack Execution Flow
- T1601.001 - Patch System Image
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 16.33
Matched TTPs:
- T1689 - Downgrade Attack
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1488 - Disk Content Wipe
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1530 - Data from Cloud Storage
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 3.20
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 9.01
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1122 - Component Object Model Hijacking
- T1573 - Encrypted Channel
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 15.41
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1218.003 - CMSTP
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 8.40
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1122 - Component Object Model Hijacking
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 11.48
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
- T1055.013 - Process Doppelgänging
- T1051 - Shared Webroot
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 3.81
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 15.52
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1134.001 - Token Impersonation/Theft
- T1087.004 - Cloud Account
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 8.38
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 4.22
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 14.97
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1098.007 - Additional Local or Domain Groups
- T1562.004 - Disable or Modify System Firewall
- T1110.003 - Password Spraying
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.06
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1562.004 - Disable or Modify System Firewall
MITREへのリンク →
Score: 10.96
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 5.28
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
MITREへのリンク →
Score: 4.76
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1177 - LSASS Driver
MITREへのリンク →
Score: 12.71
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
- T1574.009 - Path Interception by Unquoted Path
- T1601.001 - Patch System Image
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 10.40
Matched TTPs:
- T1140 - Deobfuscate/Decode Files or Information
- T1009 - Binary Padding
- T1110.003 - Password Spraying
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 8.68
Matched TTPs:
- T1137.005 - Outlook Rules
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 8.40
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1027 - Obfuscated Files or Information
- T1486 - Data Encrypted for Impact
MITREへのリンク →
Score: 10.74
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1590.006 - Network Security Appliances
- T1087.004 - Cloud Account
- T1027.004 - Compile After Delivery
- T1197 - BITS Jobs
MITREへのリンク →
Score: 3.92
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 8.80
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 20.65
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1110.003 - Password Spraying
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1665 - Hide Infrastructure
MITREへのリンク →
Score: 10.94
Matched TTPs:
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 9.69
Matched TTPs:
- T1562.004 - Disable or Modify System Firewall
- T1102 - Web Service
- T1597 - Search Closed Sources
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 13.73
Matched TTPs:
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1087.004 - Cloud Account
MITREへのリンク →
Score: 9.41
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1055.013 - Process Doppelgänging
- T1087.004 - Cloud Account
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 6.03
Matched TTPs:
- T1177 - LSASS Driver
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 13.88
Matched TTPs:
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 6.66
Matched TTPs:
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 4.39
Matched TTPs:
- T1051 - Shared Webroot
- T1601.001 - Patch System Image
MITREへのリンク →
Score: 5.41
Matched TTPs:
- T1087.004 - Cloud Account
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1048 - Exfiltration Over Alternative Protocol
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1131 - Authentication Package
- T1027.014 - Polymorphic Code
- T1087.004 - Cloud Account
- T1490 - Inhibit System Recovery
- T1140 - Deobfuscate/Decode Files or Information
- T1051 - Shared Webroot
- T1027.004 - Compile After Delivery
- T1597 - Search Closed Sources
- T1197 - BITS Jobs
- T1665 - Hide Infrastructure
- T1601.001 - Patch System Image
- T1598.003 - Spearphishing Link
- T1213.006 - Databases
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1609 - Container Administration Command
- T1098.007 - Additional Local or Domain Groups
- T1546.008 - Accessibility Features
MITREへのリンク →
Score: 0.69
Matched TTPs:
- T1202 - Indirect Command Execution
- T1584.008 - Network Devices
- T1490 - Inhibit System Recovery
- T1562.004 - Disable or Modify System Firewall
- T1140 - Deobfuscate/Decode Files or Information
- T1104 - Multi-Stage Channels
- T1122 - Component Object Model Hijacking
- T1592.004 - Client Configurations
- T1027.004 - Compile After Delivery
- T1547.011 - Plist Modification
- T1556.008 - Network Provider DLL
- T1598.003 - Spearphishing Link
- T1177 - LSASS Driver
- T1099 - Timestomp
- T1027.012 - LNK Icon Smuggling
MITREへのリンク →
Score: 0.66
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1087.004 - Cloud Account
- T1562.004 - Disable or Modify System Firewall
- T1140 - Deobfuscate/Decode Files or Information
- T1122 - Component Object Model Hijacking
- T1055.004 - Asynchronous Procedure Call
- T1484.002 - Trust Modification
- T1075 - Pass the Hash
- T1686.003 - Windows Host Firewall
- T1573 - Encrypted Channel
- T1601.001 - Patch System Image
- T1598.003 - Spearphishing Link
- T1546.008 - Accessibility Features
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
MITREへのリンク →
Score: 0.65
Matched TTPs:
- T1131 - Authentication Package
- T1546.007 - Netsh Helper DLL
- T1562.004 - Disable or Modify System Firewall
- T1140 - Deobfuscate/Decode Files or Information
- T1104 - Multi-Stage Channels
- T1122 - Component Object Model Hijacking
- T1139 - Bash History
- T1547.011 - Plist Modification
- T1197 - BITS Jobs
- T1598.003 - Spearphishing Link
- T1487 - Disk Structure Wipe
- T1055.008 - Ptrace System Calls
- T1574.009 - Path Interception by Unquoted Path
- T1098.007 - Additional Local or Domain Groups
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る