Greedy Sponge
· Published 21/12/2025 15:47 · Modified 21/12/2025 15:47
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 15:47
- Modified
- 21/12/2025 15:47
- Updated at
- 21/12/2025 15:47
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 16 attack patterns (mitre), 2 malware, 7 sectors, 1 countries, 68 indicators, 2 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
2 Malwares 1 APTPublished 21/08/2025 16:16 · Modified 21/08/2025 20:25
Attack patterns (MITRE) (16)
-
T1105 usesIngress Tool Transfer
-
T1218.007 usesMsiexec
-
T1547.001 usesRegistry Run Keys / Startup Folder
-
T1113 usesScreen Capture
-
T1204.002 usesMalicious File
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1071.001 usesWeb Protocols
-
T1218.003 usesCMSTP
-
T1132.001 usesStandard Encoding
-
T1548.002 usesBypass User Account Control
-
T1591.001
-
T1059.005 usesVisual Basic
-
T1555 usesCredentials from Password Stores
-
T1041 usesExfiltration Over C2 Channel
-
T1056.001 usesKeylogging
-
T1070.004 usesFile Deletion
Malware (2)
-
SystemBC usesFamilyPublished 12/06/2026 21:29 · Modified 12/06/2026 21:29
-
AllaKore RAT usesFamilyPublished 21/08/2025 16:16 · Modified 21/08/2025 16:16
Sectors (7)
- Culture and entertainment targets
- Manufacturing targets
- Agriculture targets
- Retail targets
- Government targets
- Transportation targets
- Finance targets
Countries (1)
- Mexico targets
Indicators (68)
-
3729396b11c69c60f9d096ce726f4cc5b4ed2054d89f7d195e998456de7fb229indicates -
50e5cd438024b34ba638e170f6e4595b0361dedb0ea925d06d06f68988468ddfindicates -
siperasul.comindicates -
masamadreartesanal.comindicates -
pachisuave.comindicates -
capitolioeventos.comindicates -
e9b9cdb713bfea40e13acffbe90faa536df206675819035835ce9218365cd118indicates -
fed1c094280d1361e8a9aafdb4c1b3e63e0f2e5bb549d5d737d0a33f2b63b4b8indicates -
dc409e9fa8b8c031c347d9c36f5732ea03e246c29d73e3425e4e8aaa1da6ff7cindicates -
5b51d1682cbd40cc6eca23333554ab16b7ed4bbd727712b3a00b07c24e629863indicates -
e4a6be2fb70603f1545641240680b44e21b5601e8016c0d144711423eef9778eindicates -
elitesubmissions.comindicates -
9170503615e4d2cf1d67f0935ded3ce36a984247ae7f9ab406d81ebe1daf3604indicates -
cleanmades.comindicates -
e9cd7c4db074c8e7c6b488a724be1cd05c8536dae28674ce3aa48ebb258e3c31indicates -
8bf0d693033a761843ae20c7e118c05f851230cb95058f836ffe2b51770f788aindicates -
b9bb43b725a454e826ab64fdd6256af809c60119dab2876d081b3721d226c672indicates -
cupertujo.comindicates -
73a46441a7135296d1070f5905a5cb6453ea8511a99a3b9c76060069aa7abcefindicates -
trenipono.comindicates -
flapawer.comindicates -
53b85d1b7127c365a4ebae5f22ed479cd5d7e9efc716fb9df68ebdd18551834aindicates -
34e347d1c9ce80b4e2b77f2de5aa7b4d98084704896bd169338c6d4b440e16c3indicates -
21614973732d4012889da2e1538b20fd1c0aefdb1d1452d79fd9a1bc06d569daindicates -
https://manzisuape.com/ao/190.exeindicates -
idaculipa.comindicates -
5d16547900119112c12a755e099bed1fafe1890869df4db297a6a21ec40185b0indicates -
manzisuape.comindicates -
barrosuon.comindicates -
logisticasmata.comindicates -
f5adef8c202e62125be49f748ed3b30b34e0fb2c9539c805dd96a75a26c7ddc4indicates -
12557dcf9c9a609521d7a2cc84a7e6fb95a93957aed6bda0f9644e96dfbbc180indicates -
681b15a43925e02d7f4f0c9e554e8d73e230931ce6634f49dd5b204afd03d20cindicates -
pasaaportes-citas-srre-gob.comindicates -
mx-terrasabvia.comindicates -
544091acb5807aaac32ca4843bb85c4aa7ce0ab0acda296efa1a23fe3c181b7eindicates -
glossovers.comindicates -
a83f218d9dbb05c1808a71c75f3535551b67d41da6bb027ac0972597a1fc49feindicates -
https://manzisuape.com/amw/indicates -
bb3f433799c30a8aad5257abc2df479ecad058f6099fd89fb8e7c278dfe3be45indicates -
8634988a90e69d8e657f72cf5f599176be5854448e0544abc42eb49b0c245f0cindicates -
e848a0f1900e2f0be9ed1ea8e947ae3bae14e78f3ff81c02d8e5a54353cdbac8indicates -
4f08865b1bdcc0e27e34bbd722279de661c92ce9aafb9fced1b5de1275887486indicates -
f76b456cf2af1382325c704bf70b5168d28d30da0f3d0a5207901277e01db395indicates -
metritono.comindicates -
3b0772608844821555bb90e0218972f89f421dad9b1f7bd1918de26a929e998findicates -
79a5ac15d0de66df3dd00a4148aa76dc183ebf47553fbcc5355f4902dc981267indicates -
bd299b5e3d7645b10286410f98f6ec79d803ce2b977c61e49f2dc26285823c99indicates -
0dbaf8970c0620e1b5902fd87c1cd0e72e917c45add84a024338c0481b5e161cindicates -
https://masamadreartesanal.com/tag/ss.exeindicates -
chuacheneguer.comindicates -
inmobiliariaarte.comindicates -
a8abffa5d7259a94951d96ad3d60e8910927b5d0697f8edece2e295154e00832indicates -
mepunico.comindicates -
c33723a6c0ece4f790396f5fd5133cf384143736e6acd06e1d7642c04757bbaeindicates -
65fc84ffd9be05720b700292b7dbc0ac8afa7faaadf6fcd4485ce34785ba0932indicates -
32ef3a0da762bc88afb876537809350a885bbbc3ec59b1838e9e9ccc0a04b081indicates -
84b046a4dbfcd9d4b2d62b4bc8faaf4c6395696f1e688f464bc9e0b760885263indicates -
c3e7089e47e5c9fc896214bc44d35608854cd5fa70ae5c19aadb0748c6b353d6indicates -
d8343068669d8fbb52b0af87bd3d4f3579d76192d021b37b6fd236b0973e4a5dindicates -
20fe630a63dd1741ec4ade9fe05b2e7e57208f776d5e20bbf0a012fea96ad0c0indicates -
kalichepa.comindicates -
dcfa26a38a5af8a072104854fba1b7c0aa9ec99875d35dbd623c12932df44969indicates -
974c221c75c35d03dd2158d1d1a0a72a7ae85a6f7c1c729977f3676f946758eeindicates -
tlelmeuas.comindicates -
http://masamadreartesanal.com/tag/ss.exeindicates -
arimateas.comindicates -
4bf4bcf1cc45d9e50efbd184aad827e2c81f900a53961cf4fbea90fa31ca7549indicates
Vulnerabilities (CVE) (2)
10.0
Critical
A vulnerability in the RADIUS subsystem implementation of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to …
- Attack vector
- Network
- Published
- 14/08/2025
- Modified
- 27/05/2026
9.8
Critical
An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] in Fortinet FortiSIEM version 7.3.0 through …
- Attack vector
- Network
- Published
- 12/08/2025
- Modified
- 27/05/2026