EVALUSION
· Published 21/12/2025 20:39 · Modified 21/12/2025 20:39
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 20:39
- Modified
- 21/12/2025 20:39
- Updated at
- 21/12/2025 20:39
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 16 attack patterns (mitre), 3 malware, 18 indicators, 1 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
16 MITREs 3 Malwares 1 Observable 1 APTPublished 18/11/2025 22:17 · Modified 19/11/2025 09:00
Attack patterns (MITRE) (16)
-
T1020 usesAutomated Exfiltration
-
T1041 usesExfiltration Over C2 Channel
-
T1071.001 usesWeb Protocols
-
T1555 usesCredentials from Password Stores
-
T1005 usesData from Local System
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1218.005 usesMshta
-
T1059.003 usesWindows Command Shell
-
T1573.001 usesSymmetric Cryptography
-
T1119 usesAutomated Collection
-
T1132.001 usesStandard Encoding
-
T1027 usesObfuscated Files or Information
-
T1083 usesFile and Directory Discovery
-
T1056.001 usesKeylogging
-
T1059.001 usesPowerShell
-
T1553.002 usesCode Signing
Malware (3)
-
ACR Stealer usesFamilyPublished 19/02/2026 16:01 · Modified 19/02/2026 16:01
-
Amatera Stealer usesFamilyPublished 09/03/2026 09:42 · Modified 09/03/2026 09:42
-
NetSupport RAT usesFamilyPublished 22/05/2026 13:08 · Modified 22/05/2026 13:08
Indicators (18)
-
unpopularnational.comindicates -
c96d51f37b676b0fed0c5c512adfac703f397a0b695ad490cde0aa737aaa248eindicates -
https://h2.kuq5g.ru/pwuwa75bindicates -
df98ce80d4437d77f2c6c7fa58c82d8cd4da37f2a0cc4b5b1e0c7d48ca4c4dd8indicates -
26db2f20d3d84657af15509ba39f62690a06175c2d5671795e239bdbe3acbaefindicates -
h2.kuq5g.ruindicates -
http://87.120.219.26/P9m4H7S2FqDTofindicates -
a61a2efaad92e5888cf20cb2bf96b9874eac5d5aadf6456c76926ab90cbe74d7indicates -
congenialespresso.topindicates -
ea84d5dacc5cae7e57782678a0e9bba016e959580bb1c6b2c4a02c51c8288039indicates -
aad4b827858210d101ccd9f75b2caa7d207ff7dde9e7f8f8c587a0b11d198b2bindicates -
http://87.120.219.26/P9m4H7S2FqDTof'indicates -
ci6ef.ruindicates -
8d84596d648444e668ee40e3ee1467b5d9ca1f7bc346778ab6aa66bad84cb7afindicates -
c70ye.ruindicates -
kuq5g.ruindicates -
ha0m.ruindicates -
168f1b974b31df0889e6dbe75f0fe8486cf932d72f0d6ad8348c97a2e537a738indicates
Vulnerabilities (CVE) (1)
CVE-2025-59287
KEV
9.8
Critical
Microsoft Windows Server Update Service (WSUS) contains a deserialization of untrusted data vulnerability that allows for remote code execution.
- Attack vector
- Network
- Published
- 24/10/2025
- Modified
- 21/12/2025