Androxgh0st
· Published 21/12/2025 05:24 · Modified 21/12/2025 08:21
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 05:24
- Modified
- 21/12/2025 08:21
- Updated at
- 21/12/2025 08:21
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 3 reports, 26 attack patterns (mitre), 2 malware, 4 countries, 13 indicators, 13 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (3)
-
13 CVEs 20 MITREs 2 Malwares 10 Observables 1 APT
-
8 MITREs 2 Malwares 1 Observable 1 APT
-
3 CVEs 9 MITREs 1 Malware 7 Observables 1 APT
Attack patterns (MITRE) (26)
-
T1110 usesBrute Force MITRE
-
T1071 usesApplication Layer Protocol MITRE
-
T1587 usesDevelop Capabilities MITRE
-
T1562 usesImpair Defenses MITRE
-
T1593 MITRE
-
T1046 usesNetwork Service Discovery MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1016 usesSystem Network Configuration Discovery MITRE
-
T1595 usesActive Scanning MITRE
-
T1583 usesAcquire Infrastructure MITRE
-
T1537 usesTransfer Data to Cloud Account MITRE
Malware (2)
-
Androxgh0st usesFamily
-
Mozi usesFamily
Countries (4)
-
British Indian Ocean Territory targets
-
India targets
-
China targets
-
Albania targets
Indicators (13)
-
6b5846f32d8009e6b54743d6f817f0c3519be6f370a0917bf455d3d114820bbcindicates
Vulnerabilities (CVE) (13)
9.8
Critical
PHPUnit allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by …
- Attack vector
- NETWORK
- Complexity
- LOW
- Published
- 27/06/2017
- Modified
- 22/04/2026