SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia
概要
Infrastructure analysis reveals a cluster of SpiceRAT command and control servers active from late 2025 through August 2026, linked through shared TLS certificates, domain registrations, and a cloned RTX Corporation webpage. The infrastructure connects to multiple threat families including SpiceRAT, NodeEdgeRAT, NomadRAT, and BloodAlchemy, suggesting either a single operator managing multiple toolsets or shared support infrastructure. A TLS certificate impersonating Uzbekistan's railway authority was issued by TLC, a Chinese state-affiliated certificate authority. Domains spoof Central Asian government entities including Türkmengaz, the Galkynysh gas field, Tojiktelecom, and Turkmenistan's Ministry of Foreign Affairs. Passive DNS analysis reveals subdomain infrastructure dating to mid-2022, indicating at least four years of ongoing operations. The infrastructure shares characteristics with previously documented China-nexus actors FamousSparrow and IndigoZebra, both known for targeting Central Asian governm...
Created: 2026-09-17
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 35.83
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1099 - Timestomp
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1040 - Network Sniffing
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1036.002 - Right-to-Left Override
- T1608.005 - Link Target
- T1554 - Compromise Host Software Binary
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1553.004 - Install Root Certificate
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 20.37
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1588.001 - Malware
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1553.004 - Install Root Certificate
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 7.08
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1027.014 - Polymorphic Code
- T1553.004 - Install Root Certificate
MITREへのリンク →
Score: 60.51
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1134.002 - Create Process with Token
- T1546.008 - Accessibility Features
- T1588.001 - Malware
- T1609 - Container Administration Command
- T1608.005 - Link Target
- T1654 - Log Enumeration
- T1597 - Search Closed Sources
- T1027.014 - Polymorphic Code
- T1553.004 - Install Root Certificate
- T1027.004 - Compile After Delivery
- T1656 - Impersonation
- T1126 - Network Share Connection Removal
- T1027.018 - Invisible Unicode
- T1003.003 - NTDS
MITREへのリンク →
Score: 21.64
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1596.001 - DNS/Passive DNS
- T1556.002 - Password Filter DLL
- T1009 - Binary Padding
- T1588.001 - Malware
- T1597 - Search Closed Sources
- T1488 - Disk Content Wipe
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.37
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1009 - Binary Padding
- T1588.001 - Malware
MITREへのリンク →
Score: 10.17
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
- T1553.004 - Install Root Certificate
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 43.17
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1099 - Timestomp
- T1587.003 - Digital Certificates
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1547.005 - Security Support Provider
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1134.002 - Create Process with Token
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1187 - Forced Authentication
- T1553.004 - Install Root Certificate
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 7.20
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1134.002 - Create Process with Token
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 4.68
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 20.83
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1584.008 - Network Devices
- T1007 - System Service Discovery
- T1183 - Image File Execution Options Injection
- T1588.001 - Malware
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1027.018 - Invisible Unicode
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 38.18
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1546.013 - PowerShell Profile
- T1608.004 - Drive-by Target
- T1007 - System Service Discovery
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1134.002 - Create Process with Token
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
- T1553.004 - Install Root Certificate
- T1027.018 - Invisible Unicode
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 33.42
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1596.001 - DNS/Passive DNS
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1547.011 - Plist Modification
- T1134.002 - Create Process with Token
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 18.39
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1546.013 - PowerShell Profile
- T1527 - Application Access Token
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 4.33
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1553.004 - Install Root Certificate
MITREへのリンク →
Score: 27.44
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1584.008 - Network Devices
- T1007 - System Service Discovery
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1097 - Pass the Ticket
- T1208 - Kerberoasting
- T1027 - Obfuscated Files or Information
- T1574.009 - Path Interception by Unquoted Path
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 35.38
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1098.007 - Additional Local or Domain Groups
- T1016.002 - Wi-Fi Discovery
- T1183 - Image File Execution Options Injection
- T1134.002 - Create Process with Token
- T1546.008 - Accessibility Features
- T1055.004 - Asynchronous Procedure Call
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1187 - Forced Authentication
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 39.54
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1222.002 - Linux and Mac Permissions
- T1487 - Disk Structure Wipe
- T1040 - Network Sniffing
- T1098.007 - Additional Local or Domain Groups
- T1139 - Bash History
- T1131 - Authentication Package
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1097 - Pass the Ticket
- T1574.009 - Path Interception by Unquoted Path
- T1553.004 - Install Root Certificate
- T1585 - Establish Accounts
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 11.40
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1099 - Timestomp
- T1487 - Disk Structure Wipe
- T1134.002 - Create Process with Token
- T1608.005 - Link Target
MITREへのリンク →
Score: 31.56
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1007 - System Service Discovery
- T1098.007 - Additional Local or Domain Groups
- T1503 - Credentials from Web Browsers
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1590 - Gather Victim Network Information
- T1097 - Pass the Ticket
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1493 - Transmitted Data Manipulation
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 5.89
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1584.008 - Network Devices
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 24.89
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1587.003 - Digital Certificates
- T1487 - Disk Structure Wipe
- T1608.004 - Drive-by Target
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1128 - Netsh Helper DLL
- T1027.004 - Compile After Delivery
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 8.80
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 8.35
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1003.007 - Proc Filesystem
- T1588.001 - Malware
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 23.75
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1588.001 - Malware
- T1027.012 - LNK Icon Smuggling
- T1097 - Pass the Ticket
- T1027 - Obfuscated Files or Information
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 15.90
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 38.27
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1202 - Indirect Command Execution
- T1547.011 - Plist Modification
- T1036.002 - Right-to-Left Override
- T1568 - Dynamic Resolution
- T1608.005 - Link Target
- T1027.012 - LNK Icon Smuggling
- T1556.008 - Network Provider DLL
- T1027.004 - Compile After Delivery
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 36.47
Matched TTPs:
- T1044 - File System Permissions Weakness
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
- T1656 - Impersonation
- T1126 - Network Share Connection Removal
- T1027.018 - Invisible Unicode
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 25.22
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1099 - Timestomp
- T1003.007 - Proc Filesystem
- T1040 - Network Sniffing
- T1131 - Authentication Package
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1097 - Pass the Ticket
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 9.67
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1134.002 - Create Process with Token
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 13.54
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1588.001 - Malware
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 8.80
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1090 - Proxy
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1055.003 - Thread Execution Hijacking
MITREへのリンク →
Score: 13.46
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1098.007 - Additional Local or Domain Groups
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1027.004 - Compile After Delivery
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 3.33
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 15.70
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1587.003 - Digital Certificates
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1090 - Proxy
- T1588.001 - Malware
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 7.12
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 13.36
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1598.004 - Spearphishing Voice
- T1027.014 - Polymorphic Code
- T1128 - Netsh Helper DLL
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 6.47
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1588.001 - Malware
- T1553.004 - Install Root Certificate
MITREへのリンク →
Score: 10.92
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1183 - Image File Execution Options Injection
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 3.33
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 6.51
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1101 - Security Support Provider
MITREへのリンク →
Score: 27.23
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1596.001 - DNS/Passive DNS
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1136.003 - Cloud Account
- T1055.005 - Thread Local Storage
- T1027.018 - Invisible Unicode
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 5.35
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 3.33
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 12.15
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1609 - Container Administration Command
MITREへのリンク →
Score: 16.26
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1134.002 - Create Process with Token
- T1055.004 - Asynchronous Procedure Call
- T1097 - Pass the Ticket
MITREへのリンク →
Score: 15.46
Matched TTPs:
- T1099 - Timestomp
- T1098.007 - Additional Local or Domain Groups
- T1036.002 - Right-to-Left Override
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 4.48
Matched TTPs:
- T1099 - Timestomp
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 18.63
Matched TTPs:
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1007 - System Service Discovery
- T1547.005 - Security Support Provider
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
- T1134.001 - Token Impersonation/Theft
MITREへのリンク →
Score: 34.96
Matched TTPs:
- T1099 - Timestomp
- T1686.003 - Windows Host Firewall
- T1003.007 - Proc Filesystem
- T1040 - Network Sniffing
- T1556.002 - Password Filter DLL
- T1547.005 - Security Support Provider
- T1134.002 - Create Process with Token
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1488 - Disk Content Wipe
- T1584.002 - DNS Server
MITREへのリンク →
Score: 11.94
Matched TTPs:
- T1099 - Timestomp
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
- T1027.018 - Invisible Unicode
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 5.90
Matched TTPs:
- T1682 - Query Public AI Services
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 7.07
Matched TTPs:
- T1584.008 - Network Devices
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 17.84
Matched TTPs:
- T1584.008 - Network Devices
- T1007 - System Service Discovery
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1654 - Log Enumeration
- T1097 - Pass the Ticket
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 12.32
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 9.10
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1097 - Pass the Ticket
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 4.33
Matched TTPs:
- T1584.008 - Network Devices
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 14.62
Matched TTPs:
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1547.011 - Plist Modification
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 11.47
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1098.007 - Additional Local or Domain Groups
- T1055.004 - Asynchronous Procedure Call
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 19.07
Matched TTPs:
- T1584.008 - Network Devices
- T1487 - Disk Structure Wipe
- T1097 - Pass the Ticket
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1656 - Impersonation
- T1003.003 - NTDS
MITREへのリンク →
Score: 16.76
Matched TTPs:
- T1596.001 - DNS/Passive DNS
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1134.002 - Create Process with Token
- T1546.008 - Accessibility Features
- T1609 - Container Administration Command
MITREへのリンク →
Score: 7.95
Matched TTPs:
- T1596.001 - DNS/Passive DNS
- T1587.003 - Digital Certificates
- T1098.007 - Additional Local or Domain Groups
MITREへのリンク →
Score: 7.95
Matched TTPs:
- T1596.001 - DNS/Passive DNS
- T1574.009 - Path Interception by Unquoted Path
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 4.51
Matched TTPs:
- T1596.001 - DNS/Passive DNS
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 21.92
Matched TTPs:
- T1588.004 - Digital Certificates
- T1003.007 - Proc Filesystem
- T1040 - Network Sniffing
- T1098.007 - Additional Local or Domain Groups
- T1153 - Source
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 15.93
Matched TTPs:
- T1587.003 - Digital Certificates
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1007 - System Service Discovery
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 16.67
Matched TTPs:
- T1587.003 - Digital Certificates
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1007 - System Service Discovery
- T1055.004 - Asynchronous Procedure Call
- T1574 - Hijack Execution Flow
MITREへのリンク →
Score: 27.47
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1098.007 - Additional Local or Domain Groups
- T1547.005 - Security Support Provider
- T1609 - Container Administration Command
- T1083 - File and Directory Discovery
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 20.02
Matched TTPs:
- T1484.002 - Trust Modification
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1554 - Compromise Host Software Binary
- T1027.014 - Polymorphic Code
- T1488 - Disk Content Wipe
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 7.46
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
- T1097 - Pass the Ticket
MITREへのリンク →
Score: 5.56
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1608.005 - Link Target
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 22.61
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1040 - Network Sniffing
- T1098.007 - Additional Local or Domain Groups
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1097 - Pass the Ticket
- T1128 - Netsh Helper DLL
- T1027.018 - Invisible Unicode
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 3.55
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 16.48
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1007 - System Service Discovery
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
- T1136.003 - Cloud Account
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 6.66
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.26
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 4.26
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 7.48
Matched TTPs:
- T1007 - System Service Discovery
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 11.37
Matched TTPs:
- T1007 - System Service Discovery
- T1547.011 - Plist Modification
- T1097 - Pass the Ticket
- T1027.004 - Compile After Delivery
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 11.86
Matched TTPs:
- T1007 - System Service Discovery
- T1097 - Pass the Ticket
- T1562.001 - Disable or Modify Tools
- T1213.003 - Code Repositories
MITREへのリンク →
Score: 18.32
Matched TTPs:
- T1007 - System Service Discovery
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
- T1553.004 - Install Root Certificate
MITREへのリンク →
Score: 13.01
Matched TTPs:
- T1007 - System Service Discovery
- T1009 - Binary Padding
- T1134.001 - Token Impersonation/Theft
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 11.89
Matched TTPs:
- T1007 - System Service Discovery
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 7.06
Matched TTPs:
- T1040 - Network Sniffing
- T1130 - Install Root Certificate
MITREへのリンク →
Score: 5.27
Matched TTPs:
- T1040 - Network Sniffing
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.76
Matched TTPs:
- T1040 - Network Sniffing
- T1588.001 - Malware
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 8.40
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1027 - Obfuscated Files or Information
- T1486 - Data Encrypted for Impact
MITREへのリンク →
Score: 6.55
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 3.53
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1608.005 - Link Target
MITREへのリンク →
Score: 6.16
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1036.002 - Right-to-Left Override
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 9.33
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1588.001 - Malware
- T1608.005 - Link Target
- T1027.004 - Compile After Delivery
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 9.95
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1036.002 - Right-to-Left Override
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 7.69
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1134.002 - Create Process with Token
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 12.51
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
- T1134.002 - Create Process with Token
- T1027 - Obfuscated Files or Information
- T1126 - Network Share Connection Removal
MITREへのリンク →
Score: 6.90
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1036.002 - Right-to-Left Override
- T1588.001 - Malware
MITREへのリンク →
Score: 3.80
Matched TTPs:
- T1098.007 - Additional Local or Domain Groups
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 16.58
Matched TTPs:
- T1547.005 - Security Support Provider
- T1134.002 - Create Process with Token
- T1609 - Container Administration Command
- T1556.008 - Network Provider DLL
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1009 - Binary Padding
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 8.88
Matched TTPs:
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 6.47
Matched TTPs:
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1553.004 - Install Root Certificate
MITREへのリンク →
Score: 11.02
Matched TTPs:
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 4.49
Matched TTPs:
- T1588.001 - Malware
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 8.06
Matched TTPs:
- T1588.001 - Malware
- T1097 - Pass the Ticket
- T1656 - Impersonation
MITREへのリンク →
Score: 5.58
Matched TTPs:
- T1055.004 - Asynchronous Procedure Call
- T1187 - Forced Authentication
MITREへのリンク →
Score: 5.45
Matched TTPs:
- T1608.005 - Link Target
- T1656 - Impersonation
MITREへのリンク →
Score: 5.24
Matched TTPs:
- T1597 - Search Closed Sources
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 4.14
Matched TTPs:
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 4.20
Matched TTPs:
- T1597 - Search Closed Sources
- T1553.004 - Install Root Certificate
MITREへのリンク →
Score: 5.14
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 6.50
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1027.018 - Invisible Unicode
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 5.14
Matched TTPs:
- T1027.014 - Polymorphic Code
- T1553.004 - Install Root Certificate
MITREへのリンク →
Score: 3.70
Matched TTPs:
- T1027.004 - Compile After Delivery
- T1027.018 - Invisible Unicode
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1130 - Install Root Certificate
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1583 - Acquire Infrastructure
- T1134.002 - Create Process with Token
- T1546.008 - Accessibility Features
- T1656 - Impersonation
- T1131 - Authentication Package
- T1003.007 - Proc Filesystem
- T1003.003 - NTDS
- T1654 - Log Enumeration
- T1027.004 - Compile After Delivery
- T1126 - Network Share Connection Removal
- T1027.014 - Polymorphic Code
- T1546.013 - PowerShell Profile
- T1183 - Image File Execution Options Injection
- T1213.006 - Databases
- T1608.005 - Link Target
- T1553.004 - Install Root Certificate
- T1588.001 - Malware
- T1098.007 - Additional Local or Domain Groups
- T1609 - Container Administration Command
- T1027.018 - Invisible Unicode
- T1009 - Binary Padding
- T1597 - Search Closed Sources
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る