WeaselBiscuit Strips BeaverTail and OtterCookie Down to Essentials
概要
A new JavaScript infostealer dubbed WeaselBiscuit has been discovered hidden in 11 malicious npm packages. This lean malware shares operational similarities with DPRK-linked BeaverTail and OtterCookie families but features a stripped-down architecture. WeaselBiscuit deploys through npm imports, executes a detached Node process, retrieves its payload from Npoint URLs, and communicates with a C2 server at 103.170.217.184:8787. The malware profiles infected hosts, steals Chrome extension storage containing wallet signing states, captures clipboard contents, and logs Windows keystrokes when commanded. Unlike its predecessors, it lacks wallet-draining code, browser password decryption, Python second stages, screenshots, and remote shell capabilities. The operation uses numeric campaign identifiers embedded in package names for tracking. While technical overlap suggests DPRK attribution, particularly through Npoint dead-drop patterns and nested IP geolocation lookups, definitive attribution requires additional c...
Created: 2026-09-18
Indicators
類似Pulses
類似するPulseは見つかりませんでした。
このPulseに関連する脅威アクター (事実ベース)
Score: 23.11
Matched TTPs:
- T1560.001 - Archive via Utility
- T1171 - LLMNR/NBT-NS Poisoning and Relay
- T1099 - Timestomp
- T1487 - Disk Structure Wipe
- T1027.008 - Stripped Payloads
- T1590.006 - Network Security Appliances
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 21.10
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1558 - Steal or Forge Kerberos Tickets
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 25.96
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1176.001 - Browser Extensions
- T1007 - System Service Discovery
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1083 - File and Directory Discovery
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1556.009 - Conditional Access Policies
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 9.26
Matched TTPs:
- T1560.001 - Archive via Utility
- T1051 - Shared Webroot
- T1562.001 - Disable or Modify Tools
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 10.84
Matched TTPs:
- T1560.001 - Archive via Utility
- T1177 - LSASS Driver
- T1051 - Shared Webroot
- T1656 - Impersonation
MITREへのリンク →
Score: 27.52
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1686.003 - Windows Host Firewall
- T1003.007 - Proc Filesystem
- T1040 - Network Sniffing
- T1556.002 - Password Filter DLL
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 19.94
Matched TTPs:
- T1560.001 - Archive via Utility
- T1587.003 - Digital Certificates
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1007 - System Service Discovery
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1136.002 - Domain Account
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 24.27
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1136.003 - Cloud Account
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 12.86
Matched TTPs:
- T1560.001 - Archive via Utility
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
- T1574.009 - Path Interception by Unquoted Path
- T1506 - Web Session Cookie
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 28.84
Matched TTPs:
- T1560.001 - Archive via Utility
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1587.003 - Digital Certificates
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1007 - System Service Discovery
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1055.004 - Asynchronous Procedure Call
- T1574 - Hijack Execution Flow
- T1592.003 - Firmware
MITREへのリンク →
Score: 10.29
Matched TTPs:
- T1560.001 - Archive via Utility
- T1587.003 - Digital Certificates
- T1122 - Component Object Model Hijacking
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 11.82
Matched TTPs:
- T1560.001 - Archive via Utility
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1007 - System Service Discovery
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 28.17
Matched TTPs:
- T1560.001 - Archive via Utility
- T1587.003 - Digital Certificates
- T1487 - Disk Structure Wipe
- T1016.002 - Wi-Fi Discovery
- T1090 - Proxy
- T1051 - Shared Webroot
- T1122 - Component Object Model Hijacking
- T1128 - Netsh Helper DLL
- T1027.004 - Compile After Delivery
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 9.76
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1027.008 - Stripped Payloads
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 12.29
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1176.001 - Browser Extensions
- T1487 - Disk Structure Wipe
- T1558 - Steal or Forge Kerberos Tickets
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 10.14
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 29.97
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1176.001 - Browser Extensions
- T1007 - System Service Discovery
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
- T1027 - Obfuscated Files or Information
- T1574.009 - Path Interception by Unquoted Path
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 20.09
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 33.29
Matched TTPs:
- T1560.001 - Archive via Utility
- T1222.002 - Linux and Mac Permissions
- T1487 - Disk Structure Wipe
- T1040 - Network Sniffing
- T1558 - Steal or Forge Kerberos Tickets
- T1131 - Authentication Package
- T1562.004 - Disable or Modify System Firewall
- T1547.011 - Plist Modification
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
- T1592.003 - Firmware
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 42.80
Matched TTPs:
- T1560.001 - Archive via Utility
- T1113 - Screen Capture
- T1546.013 - PowerShell Profile
- T1099 - Timestomp
- T1003.007 - Proc Filesystem
- T1040 - Network Sniffing
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1136.002 - Domain Account
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1218.001 - Compiled HTML File
- T1506 - Web Session Cookie
- T1027.004 - Compile After Delivery
- T1556.009 - Conditional Access Policies
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1560.001 - Archive via Utility
- T1007 - System Service Discovery
MITREへのリンク →
Score: 14.29
Matched TTPs:
- T1560.001 - Archive via Utility
- T1003.007 - Proc Filesystem
- T1558 - Steal or Forge Kerberos Tickets
- T1592.004 - Client Configurations
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 18.80
Matched TTPs:
- T1560.001 - Archive via Utility
- T1556.002 - Password Filter DLL
- T1009 - Binary Padding
- T1021.006 - Windows Remote Management
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 49.06
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1213.006 - Databases
- T1176.001 - Browser Extensions
- T1003.007 - Proc Filesystem
- T1009 - Binary Padding
- T1131 - Authentication Package
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1546.008 - Accessibility Features
- T1051 - Shared Webroot
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027.014 - Polymorphic Code
- T1506 - Web Session Cookie
- T1027.004 - Compile After Delivery
- T1656 - Impersonation
- T1126 - Network Share Connection Removal
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 15.29
Matched TTPs:
- T1560.001 - Archive via Utility
- T1176.001 - Browser Extensions
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1177 - LSASS Driver
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
MITREへのリンク →
Score: 17.00
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1504 - PowerShell Profile
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
- T1506 - Web Session Cookie
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 23.91
Matched TTPs:
- T1560.001 - Archive via Utility
- T1584.008 - Network Devices
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1176.001 - Browser Extensions
- T1487 - Disk Structure Wipe
- T1027.008 - Stripped Payloads
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 12.41
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1176.001 - Browser Extensions
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 24.30
Matched TTPs:
- T1560.001 - Archive via Utility
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1007 - System Service Discovery
- T1558 - Steal or Forge Kerberos Tickets
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1134.001 - Token Impersonation/Theft
MITREへのリンク →
Score: 27.18
Matched TTPs:
- T1560.001 - Archive via Utility
- T1546.013 - PowerShell Profile
- T1176.001 - Browser Extensions
- T1003.007 - Proc Filesystem
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1136.002 - Domain Account
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1218.001 - Compiled HTML File
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 43.36
Matched TTPs:
- T1560.001 - Archive via Utility
- T1171 - LLMNR/NBT-NS Poisoning and Relay
- T1099 - Timestomp
- T1587.003 - Digital Certificates
- T1016.002 - Wi-Fi Discovery
- T1547.005 - Security Support Provider
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1592.003 - Firmware
MITREへのリンク →
Score: 14.80
Matched TTPs:
- T1560.001 - Archive via Utility
- T1176.001 - Browser Extensions
- T1003.007 - Proc Filesystem
- T1562.004 - Disable or Modify System Firewall
- T1136.002 - Domain Account
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 17.33
Matched TTPs:
- T1560.001 - Archive via Utility
- T1007 - System Service Discovery
- T1083 - File and Directory Discovery
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 17.33
Matched TTPs:
- T1560.001 - Archive via Utility
- T1137.005 - Outlook Rules
- T1504 - PowerShell Profile
- T1597 - Search Closed Sources
- T1601 - Modify System Image
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 7.57
Matched TTPs:
- T1560.001 - Archive via Utility
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 38.46
Matched TTPs:
- T1113 - Screen Capture
- T1546.013 - PowerShell Profile
- T1176.001 - Browser Extensions
- T1007 - System Service Discovery
- T1558 - Steal or Forge Kerberos Tickets
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1590.006 - Network Security Appliances
- T1592.004 - Client Configurations
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
- T1556 - Modify Authentication Process
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 48.76
Matched TTPs:
- T1222.002 - Linux and Mac Permissions
- T1099 - Timestomp
- T1584.008 - Network Devices
- T1202 - Indirect Command Execution
- T1562.004 - Disable or Modify System Firewall
- T1547.011 - Plist Modification
- T1177 - LSASS Driver
- T1592.004 - Client Configurations
- T1568 - Dynamic Resolution
- T1608.005 - Link Target
- T1027.012 - LNK Icon Smuggling
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1027.004 - Compile After Delivery
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 33.09
Matched TTPs:
- T1666 - Modify Cloud Resource Hierarchy
- T1685.004 - Disable or Modify Linux Audit System Log
- T1547.005 - Security Support Provider
- T1590.006 - Network Security Appliances
- T1136.002 - Domain Account
- T1083 - File and Directory Discovery
- T1051 - Shared Webroot
- T1556.008 - Network Provider DLL
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1666 - Modify Cloud Resource Hierarchy
MITREへのリンク →
Score: 8.04
Matched TTPs:
- T1171 - LLMNR/NBT-NS Poisoning and Relay
- T1136.002 - Domain Account
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 5.78
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
- T1597 - Search Closed Sources
MITREへのリンク →
Score: 11.45
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 10.81
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1487 - Disk Structure Wipe
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 19.13
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1587.003 - Digital Certificates
- T1487 - Disk Structure Wipe
- T1558 - Steal or Forge Kerberos Tickets
- T1562.004 - Disable or Modify System Firewall
- T1090 - Proxy
- T1218.001 - Compiled HTML File
MITREへのリンク →
Score: 7.12
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.011 - Plist Modification
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 35.37
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1558 - Steal or Forge Kerberos Tickets
- T1547.005 - Security Support Provider
- T1131 - Authentication Package
- T1021.006 - Windows Remote Management
- T1183 - Image File Execution Options Injection
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1027.004 - Compile After Delivery
- T1656 - Impersonation
- T1126 - Network Share Connection Removal
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 11.38
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1558 - Steal or Forge Kerberos Tickets
- T1136.002 - Domain Account
- T1608.005 - Link Target
MITREへのリンク →
Score: 18.56
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1527 - Application Access Token
- T1016.002 - Wi-Fi Discovery
- T1136.002 - Domain Account
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 18.41
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1176.001 - Browser Extensions
- T1009 - Binary Padding
- T1608.005 - Link Target
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 18.58
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1176.001 - Browser Extensions
- T1598.004 - Spearphishing Voice
- T1027.014 - Polymorphic Code
- T1128 - Netsh Helper DLL
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 3.44
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1590.006 - Network Security Appliances
MITREへのリンク →
Score: 13.44
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1003.007 - Proc Filesystem
- T1183 - Image File Execution Options Injection
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
MITREへのリンク →
Score: 4.50
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1051 - Shared Webroot
MITREへのリンク →
Score: 3.99
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1608.005 - Link Target
MITREへのリンク →
Score: 7.19
Matched TTPs:
- T1546.013 - PowerShell Profile
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 11.17
Matched TTPs:
- T1099 - Timestomp
- T1547.005 - Security Support Provider
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 23.10
Matched TTPs:
- T1099 - Timestomp
- T1527 - Application Access Token
- T1487 - Disk Structure Wipe
- T1040 - Network Sniffing
- T1090 - Proxy
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 13.66
Matched TTPs:
- T1099 - Timestomp
- T1136.002 - Domain Account
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1128 - Netsh Helper DLL
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 4.54
Matched TTPs:
- T1682 - Query Public AI Services
MITREへのリンク →
Score: 17.87
Matched TTPs:
- T1584.008 - Network Devices
- T1007 - System Service Discovery
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1531 - Account Access Removal
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 20.24
Matched TTPs:
- T1584.008 - Network Devices
- T1176.001 - Browser Extensions
- T1487 - Disk Structure Wipe
- T1218.003 - CMSTP
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1122 - Component Object Model Hijacking
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 24.92
Matched TTPs:
- T1584.008 - Network Devices
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1487 - Disk Structure Wipe
- T1558 - Steal or Forge Kerberos Tickets
- T1562.004 - Disable or Modify System Firewall
- T1136.002 - Domain Account
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1656 - Impersonation
MITREへのリンク →
Score: 31.69
Matched TTPs:
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1176.001 - Browser Extensions
- T1487 - Disk Structure Wipe
- T1003.007 - Proc Filesystem
- T1040 - Network Sniffing
- T1558 - Steal or Forge Kerberos Tickets
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1128 - Netsh Helper DLL
- T1556.009 - Conditional Access Policies
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 27.20
Matched TTPs:
- T1195.001 - Compromise Software Dependencies and Development Tools
- T1176.001 - Browser Extensions
- T1487 - Disk Structure Wipe
- T1007 - System Service Discovery
- T1590.006 - Network Security Appliances
- T1090 - Proxy
- T1055.004 - Asynchronous Procedure Call
- T1136.003 - Cloud Account
- T1128 - Netsh Helper DLL
- T1506 - Web Session Cookie
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 28.47
Matched TTPs:
- T1588.004 - Digital Certificates
- T1176.001 - Browser Extensions
- T1003.007 - Proc Filesystem
- T1040 - Network Sniffing
- T1558 - Steal or Forge Kerberos Tickets
- T1009 - Binary Padding
- T1562.004 - Disable or Modify System Firewall
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1051 - Shared Webroot
- T1597 - Search Closed Sources
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 25.87
Matched TTPs:
- T1685.004 - Disable or Modify Linux Audit System Log
- T1686.003 - Windows Host Firewall
- T1504 - PowerShell Profile
- T1027.012 - LNK Icon Smuggling
- T1027 - Obfuscated Files or Information
- T1027.014 - Polymorphic Code
- T1506 - Web Session Cookie
- T1055.009 - Proc Memory
MITREへのリンク →
Score: 36.27
Matched TTPs:
- T1484.002 - Trust Modification
- T1686.003 - Windows Host Firewall
- T1558 - Steal or Forge Kerberos Tickets
- T1016.002 - Wi-Fi Discovery
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
- T1055.004 - Asynchronous Procedure Call
- T1122 - Component Object Model Hijacking
- T1562.001 - Disable or Modify Tools
- T1027 - Obfuscated Files or Information
- T1075 - Pass the Hash
MITREへのリンク →
Score: 15.20
Matched TTPs:
- T1484.002 - Trust Modification
- T1562.004 - Disable or Modify System Firewall
- T1183 - Image File Execution Options Injection
- T1027.014 - Polymorphic Code
- T1592.003 - Firmware
MITREへのリンク →
Score: 25.36
Matched TTPs:
- T1176.001 - Browser Extensions
- T1007 - System Service Discovery
- T1218.003 - CMSTP
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1608.005 - Link Target
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1128 - Netsh Helper DLL
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 6.73
Matched TTPs:
- T1176.001 - Browser Extensions
- T1007 - System Service Discovery
- T1562.001 - Disable or Modify Tools
MITREへのリンク →
Score: 28.06
Matched TTPs:
- T1176.001 - Browser Extensions
- T1007 - System Service Discovery
- T1503 - Credentials from Web Browsers
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1590 - Gather Victim Network Information
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1506 - Web Session Cookie
- T1493 - Transmitted Data Manipulation
MITREへのリンク →
Score: 4.68
Matched TTPs:
- T1176.001 - Browser Extensions
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 21.24
Matched TTPs:
- T1176.001 - Browser Extensions
- T1007 - System Service Discovery
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
- T1504 - PowerShell Profile
- T1134.001 - Token Impersonation/Theft
- T1597 - Search Closed Sources
- T1027 - Obfuscated Files or Information
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 6.15
Matched TTPs:
- T1176.001 - Browser Extensions
- T1590.006 - Network Security Appliances
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 4.60
Matched TTPs:
- T1176.001 - Browser Extensions
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 4.28
Matched TTPs:
- T1176.001 - Browser Extensions
- T1009 - Binary Padding
MITREへのリンク →
Score: 30.14
Matched TTPs:
- T1176.001 - Browser Extensions
- T1009 - Binary Padding
- T1183 - Image File Execution Options Injection
- T1547.011 - Plist Modification
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
- T1608.005 - Link Target
- T1069.001 - Local Groups
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1055.005 - Thread Local Storage
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 4.28
Matched TTPs:
- T1176.001 - Browser Extensions
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.93
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1547.011 - Plist Modification
MITREへのリンク →
Score: 4.20
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1608.005 - Link Target
MITREへのリンク →
Score: 4.09
Matched TTPs:
- T1487 - Disk Structure Wipe
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 4.26
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 5.73
Matched TTPs:
- T1003.007 - Proc Filesystem
- T1590.006 - Network Security Appliances
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 7.48
Matched TTPs:
- T1007 - System Service Discovery
- T1547.011 - Plist Modification
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 5.27
Matched TTPs:
- T1040 - Network Sniffing
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 7.12
Matched TTPs:
- T1040 - Network Sniffing
- T1136.002 - Domain Account
- T1055.004 - Asynchronous Procedure Call
MITREへのリンク →
Score: 8.01
Matched TTPs:
- T1558 - Steal or Forge Kerberos Tickets
- T1590.006 - Network Security Appliances
- T1608.005 - Link Target
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 4.09
Matched TTPs:
- T1558 - Steal or Forge Kerberos Tickets
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 11.99
Matched TTPs:
- T1558 - Steal or Forge Kerberos Tickets
- T1504 - PowerShell Profile
- T1027 - Obfuscated Files or Information
- T1486 - Data Encrypted for Impact
MITREへのリンク →
Score: 4.93
Matched TTPs:
- T1558 - Steal or Forge Kerberos Tickets
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 23.39
Matched TTPs:
- T1547.005 - Security Support Provider
- T1136.002 - Domain Account
- T1556.008 - Network Provider DLL
- T1122 - Component Object Model Hijacking
- T1601 - Modify System Image
- T1592.003 - Firmware
- T1564.003 - Hidden Window
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1009 - Binary Padding
- T1556 - Modify Authentication Process
MITREへのリンク →
Score: 10.78
Matched TTPs:
- T1009 - Binary Padding
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1506 - Web Session Cookie
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 3.81
Matched TTPs:
- T1009 - Binary Padding
- T1590.006 - Network Security Appliances
MITREへのリンク →
Score: 13.68
Matched TTPs:
- T1009 - Binary Padding
- T1055.004 - Asynchronous Procedure Call
- T1597 - Search Closed Sources
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
- T1490 - Inhibit System Recovery
MITREへのリンク →
Score: 3.29
Matched TTPs:
- T1131 - Authentication Package
MITREへのリンク →
Score: 9.94
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1027 - Obfuscated Files or Information
- T1126 - Network Share Connection Removal
MITREへのリンク →
Score: 8.40
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1590.006 - Network Security Appliances
- T1128 - Netsh Helper DLL
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 5.91
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1218.001 - Compiled HTML File
MITREへのリンク →
Score: 6.13
Matched TTPs:
- T1183 - Image File Execution Options Injection
- T1546.008 - Accessibility Features
MITREへのリンク →
Score: 3.37
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 5.09
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Score: 3.37
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 3.37
Matched TTPs:
- T1590.006 - Network Security Appliances
- T1506 - Web Session Cookie
MITREへのリンク →
Score: 6.03
Matched TTPs:
- T1177 - LSASS Driver
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 5.90
Matched TTPs:
- T1136.002 - Domain Account
- T1574.009 - Path Interception by Unquoted Path
MITREへのリンク →
Score: 5.45
Matched TTPs:
- T1608.005 - Link Target
- T1656 - Impersonation
MITREへのリンク →
Score: 4.76
Matched TTPs:
- T1608.005 - Link Target
- T1122 - Component Object Model Hijacking
MITREへのリンク →
Score: 5.14
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1027.014 - Polymorphic Code
MITREへのリンク →
Score: 5.14
Matched TTPs:
- T1562.001 - Disable or Modify Tools
- T1128 - Netsh Helper DLL
MITREへのリンク →
Score: 4.13
Matched TTPs:
- T1531 - Account Access Removal
MITREへのリンク →
このPulseに関連する脅威アクター (推論ベース)
Score: 0.70
Matched TTPs:
- T1608.005 - Link Target
- T1656 - Impersonation
- T1051 - Shared Webroot
- T1027.014 - Polymorphic Code
- T1003.007 - Proc Filesystem
- T1560.001 - Archive via Utility
- T1131 - Authentication Package
- T1490 - Inhibit System Recovery
- T1126 - Network Share Connection Removal
- T1176.001 - Browser Extensions
- T1597 - Search Closed Sources
- T1183 - Image File Execution Options Injection
- T1506 - Web Session Cookie
- T1546.013 - PowerShell Profile
- T1546.008 - Accessibility Features
- T1590.006 - Network Security Appliances
- T1213.006 - Databases
- T1009 - Binary Padding
- T1027.004 - Compile After Delivery
MITREへのリンク →
Score: 0.70
Matched TTPs:
- T1608.005 - Link Target
- T1490 - Inhibit System Recovery
- T1562.004 - Disable or Modify System Firewall
- T1568 - Dynamic Resolution
- T1592.004 - Client Configurations
- T1027.012 - LNK Icon Smuggling
- T1202 - Indirect Command Execution
- T1027.004 - Compile After Delivery
- T1547.011 - Plist Modification
- T1122 - Component Object Model Hijacking
- T1099 - Timestomp
- T1222.002 - Linux and Mac Permissions
- T1584.008 - Network Devices
- T1556.008 - Network Provider DLL
- T1177 - LSASS Driver
MITREへのリンク →
Score: 0.62
Matched TTPs:
- T1016.002 - Wi-Fi Discovery
- T1009 - Binary Padding
- T1608.005 - Link Target
- T1171 - LLMNR/NBT-NS Poisoning and Relay
- T1547.005 - Security Support Provider
- T1562.004 - Disable or Modify System Firewall
- T1592.003 - Firmware
- T1504 - PowerShell Profile
- T1587.003 - Digital Certificates
- T1027 - Obfuscated Files or Information
- T1055.004 - Asynchronous Procedure Call
- T1562.001 - Disable or Modify Tools
- T1099 - Timestomp
- T1560.001 - Archive via Utility
- T1590.006 - Network Security Appliances
- T1597 - Search Closed Sources
- T1183 - Image File Execution Options Injection
MITREへのリンク →
Score: 0.61
Matched TTPs:
- T1136.002 - Domain Account
- T1608.005 - Link Target
- T1490 - Inhibit System Recovery
- T1506 - Web Session Cookie
- T1113 - Screen Capture
- T1027.004 - Compile After Delivery
- T1546.013 - PowerShell Profile
- T1040 - Network Sniffing
- T1055.004 - Asynchronous Procedure Call
- T1218.001 - Compiled HTML File
- T1003.007 - Proc Filesystem
- T1099 - Timestomp
- T1560.001 - Archive via Utility
- T1590.006 - Network Security Appliances
- T1131 - Authentication Package
- T1597 - Search Closed Sources
- T1556.009 - Conditional Access Policies
MITREへのリンク →
Related CVEs
このPulseに見つかったCVEはありません。
Pulse – 脅威アクター グラフ
← Pulse一覧に戻る