Cloacked Ursa
· Published 21/12/2025 00:52 · Modified 21/12/2025 00:52
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 00:52
- Modified
- 21/12/2025 00:52
- Updated at
- 21/12/2025 00:52
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 8 attack patterns (mitre), 2 sectors, 1 countries, 10 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (8)
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1102 usesWeb Service MITRE
-
T1547 usesBoot or Logon Autostart Execution MITRE
-
T1566 usesPhishing MITRE
-
T1113 usesScreen Capture MITRE
-
T1055 usesProcess Injection MITRE
-
T1106 usesNative API MITRE
-
T1027 usesObfuscated Files or Information MITRE
Sectors (2)
-
Embassy targets
-
Market infrastructures targets
Countries (1)
-
Ukraine targets
Indicators (10)
-
47e8f705febc94c832307dbf3e6d9c65164099230f4d438f7fe4851d701b580bindicates -
79a1402bc77aa2702dc5dca660ca0d1bf08a2923e0a1018da70e7d7c31d9417findicates -
cd4956e4c1a3f7c8c008c4658bb9eba7169aa874c55c12fc748b0ccfe0f4a59aindicates -
0dd55a234be8e3e07b0eb19f47abe594295889564ce6a9f6e8cc4d3997018839indicates -
60d96d8d3a09f822ded0a3c84194a5d88ed62a979cbb6378545b45b04353bb37indicates -
c62199ef9c2736d15255f5deaa663158a7bb3615ba9262eb67e3f4adada14111indicates -
resetlocations.comindicates -
www.willyminiatures.comindicates -
38f8b8036ed2a0b5abb8fbf264ee6fd2b82dcd917f60d9f1d8f18d07c26b1534indicates -
311e9c8cf6d0b295074ffefaa9f277cb1f806343be262c59f88fbdf6fe242517indicates