Earth Baxia
· Published 21/12/2025 07:15 · Modified 21/12/2025 07:15
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 07:15
- Modified
- 21/12/2025 07:15
- Updated at
- 21/12/2025 07:15
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 2 reports, 31 attack patterns (mitre), 5 malware, 4 sectors, 4 countries, 25 indicators, 1 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (2)
-
11 MITREs 1 Malware 1 APT
-
19 MITREs 4 Malwares 29 Observables 1 APT
Attack patterns (MITRE) (31)
-
T1570 usesLateral Tool Transfer MITRE
-
T1566 usesPhishing MITRE
-
Digital Certificates usesT1587.003 MITRE
-
T1573.001 usesSymmetric Cryptography MITRE
-
T1562.001 usesDisable or Modify Tools MITRE
-
T1036.004 usesMasquerade Task or Service MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1055 usesProcess Injection MITRE
-
T1566.001 usesSpearphishing Attachment MITRE
-
T1584.006 usesWeb Services MITRE
-
T1588.002 usesTool MITRE
-
T1543.003 usesWindows Service MITRE
Malware (5)
Sectors (4)
-
Aerospace targets
-
Energy targets
-
Government targets
-
Telecommunications targets
Countries (4)
-
Taiwan targets
-
China targets
-
Philippines targets
-
Thailand targets
Indicators (25)
-
static.trendmicrotech.comindicates -
b3b8efcaf6b9491c00049292cdff8f53772438fde968073e73d767d51218d189indicates -
ms1.hinet.latindicates -
status.s3cloud-azure.comindicates -
061bcd5b34c7412c46a3acd100167336685a467d2cbcd1c67d183b90d0bf8de7indicates -
c78a02fa928ed8f83bda56d4b269152074f512c2cb73d59b2029bfc50ac2b8bcindicates -
6be4dd9af27712f5ef6dc7d684e5ea07fa675b8cbed3094612a6696a40c664ceindicates -
api.s2cloud-amazon.comindicates -
rocean.oca.picsindicates -
d23dd576f7a44df0d44fca6652897e4de751fdb0becc6b14b754ac9aafc9081cindicates -
visualstudio-microsoft.comindicates -
cef0d2834613a3da4befa2f56ef91afc9ab82b1e6c510d2a619ed0c1364032b8indicates
Vulnerabilities (CVE) (1)
9.8
Critical
OSGeo GeoServer GeoTools contains an improper neutralization of directives in dynamically evaluated code vulnerability due to unsafely evaluating property names as XPath …
- Attack vector
- Network
- Published
- 15/07/2024
- Modified
- 21/12/2025