Silver Fox
· Published 21/12/2025 00:22 · Modified 21/12/2025 00:22
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 00:22
- Modified
- 21/12/2025 00:22
- Updated at
- 21/12/2025 00:22
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 10 reports, 68 attack patterns (mitre), 9 malware, 7 sectors, 11 countries, 105 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (10)
-
19 MITREs 4 Malwares 46 Observables 1 APTPublished 30/04/2026 09:42 · Modified 04/05/2026 11:00
-
13 MITREs 7 Observables 1 APTPublished 23/02/2026 15:00 · Modified 23/02/2026 22:51
-
18 MITREs 2 Malwares 11 Observables 1 APTPublished 22/02/2026 02:50 · Modified 23/02/2026 09:49
-
19 MITREs 1 Malware 8 Observables 1 APTPublished 24/12/2025 21:10 · Modified 26/12/2025 10:05
-
9 MITREs 1 Malware 37 Observables 1 APTPublished 10/12/2025 17:22 · Modified 21/12/2025 18:58
-
6 MITREs 1 Malware 16 Observables 1 APTPublished 28/08/2025 13:26 · Modified 28/08/2025 13:45
-
5 MITREs 1 Malware 53 Observables 1 APTPublished 25/02/2025 09:52 · Modified 25/02/2025 10:12
-
11 MITREs 3 Malwares 52 Observables 1 APTPublished 20/01/2025 11:09 · Modified 20/01/2025 11:49
-
18 MITREs 1 Malware 34 Observables 1 APTPublished 16/08/2024 14:26 · Modified 16/08/2024 14:51
-
9 MITREs 2 Malwares 7 Observables 1 APTPublished 10/07/2024 10:19 · Modified 10/07/2024 10:31
Attack patterns (MITRE) (68)
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1036.004 usesMasquerade Task or Service
-
T1003 usesOS Credential Dumping
-
T1574.002 uses
-
T1543 usesCreate or Modify System Process
-
T1059.001 usesPowerShell
-
T1562 usesImpair Defenses
-
T1070.004 usesFile Deletion
-
T1021 usesRemote Services
-
T1189 usesDrive-by Compromise
-
T1115 usesClipboard Data
-
T1572 usesProtocol Tunneling
-
T1106 usesNative API
-
T1027.005 usesIndicator Removal from Tools
-
T1218 usesSystem Binary Proxy Execution
-
T1137 usesOffice Application Startup
-
T1095 usesNon-Application Layer Protocol
-
T1036 usesMasquerading
-
T1059 usesCommand and Scripting Interpreter
-
T1078.001 usesDefault Accounts
-
T1219 usesRemote Access Tools
-
T1038 uses
-
T1105 usesIngress Tool Transfer
-
T1566.002 usesSpearphishing Link
-
T1543.003 usesWindows Service
-
T1102 usesWeb Service
-
T1071.001 usesWeb Protocols
-
T1012 usesQuery Registry
-
T1056.001 usesKeylogging
-
T1112 usesModify Registry
-
T1107 uses
-
T1568 usesDynamic Resolution
-
T1573 usesEncrypted Channel
-
T1588.001 usesMalware
-
T1129 usesShared Modules
-
T1083 usesFile and Directory Discovery
-
T1555 usesCredentials from Password Stores
-
T1132 usesData Encoding
-
T1574.006 usesDynamic Linker Hijacking
-
T1071 usesApplication Layer Protocol
-
T1218.011 usesRundll32
-
T1204 usesUser Execution
-
T1057 usesProcess Discovery
-
T1053.005 usesScheduled Task
-
T1497 usesVirtualization/Sandbox Evasion
-
T1008 usesFallback Channels
-
T1574.001 usesDLL
-
T1078 usesValid Accounts
-
T1547.001 usesRegistry Run Keys / Startup Folder
-
T1566 usesPhishing
-
T1553.006 usesCode Signing Policy Modification
-
T1566.001 usesSpearphishing Attachment
-
T1014 usesRootkit
-
T1562.002 usesDisable Windows Event Logging
-
T1562.001 usesDisable or Modify Tools
-
T1574 usesHijack Execution Flow
-
T1113 usesScreen Capture
-
T1027 usesObfuscated Files or Information
-
T1033 usesSystem Owner/User Discovery
-
T1053 usesScheduled Task/Job
-
T1036.005 usesMatch Legitimate Resource Name or Location
-
T1068 usesExploitation for Privilege Escalation
-
T1082 usesSystem Information Discovery
-
T1548 usesAbuse Elevation Control Mechanism
-
T1547 usesBoot or Logon Autostart Execution
-
T1204.002 usesMalicious File
-
T1055 usesProcess Injection
-
T1064 usesScripting
Malware (9)
-
ABCDoor usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
-
Valley RAT usesFamilyPublished 15/01/2026 12:03 · Modified 15/01/2026 12:03
-
UpdateDll usesFamilyPublished 10/07/2024 10:19 · Modified 10/07/2024 10:19
-
gh0st RAT - S0032 usesFamilyPublished 17/04/2026 23:18 · Modified 17/04/2026 23:18
-
Winos 4.0 usesFamilyPublished 30/04/2026 09:42 · Modified 30/04/2026 09:42
-
RustSL usesFamilyPublished 30/04/2026 09:42 · Modified 30/04/2026 09:42
-
PNGPlug usesFamilyPublished 20/01/2025 11:09 · Modified 20/01/2025 11:09
-
Winos usesFamilyPublished 10/07/2024 10:19 · Modified 10/07/2024 10:19
-
ValleyRAT usesFamilyPublished 08/06/2026 10:30 · Modified 08/06/2026 10:30
Sectors (7)
- Government targets
- Retail targets
- Transportation targets
- Healthcare targets
- Finance targets
- Education targets
- Manufacturing targets
Countries (11)
- Canada targets
- Taiwan targets
- India targets
- China targets
- Japan targets
- South Africa targets
- Russian Federation targets
- Indonesia targets
- British Indian Ocean Territory targets
- Hong Kong targets
- United States of America targets
Indicators (105)
-
7545ac54f4bdfe8a9a271d30a233f8717ca692a6797ca775de1b7d3eaab1e066indicates -
31adb4043339320c360d43686ace3736bac87df27dc309c7c544820acdb34a93indicates -
0cffb8b8fd11f300b5477ff23ec576f66ab65c021d995fa5495827237e679d93indicates -
75f9256201b12fb9d83a2d64c50a61166d50de98f9cda9e8e82f448f732a7fd8indicates -
gov-a.clubindicates -
9c394dcab9f711e2bf585edf0d22d2210843885917d409ee56f22a4c24ad225eindicates -
gvo-b.clubindicates -
6014.anonymousrat5.comindicates -
df1c6479002495d8d5b9cce0b0c333f4b653c78ac803ec4abd5031f920b3f1faindicates -
teamscn.comindicates -
http://6014.anonymousrat6.com:8888indicates -
2da901c7e1441286d7e90d6a9f114ebb020e56d6f2200ea68111a691f29ff71bindicates -
twswsb.cnindicates -
48f258037be0ffe663da3bcd47dba22094cc31940083d9e18a71882bdc1ecdb8indicates -
12b3d8bc5cc1ea6e2acd741d8a80f56cf2a0a7ebfa0998e3f0743fcf83fabb9eindicates -
dingtalki.cnindicates -
45.207.231.107indicates -
http://154.82.81.205/YD20251001143052.zipindicates -
huorongcn.comindicates -
3fc35cab1272f769af309cb46375e21680f13d629181c7646cb0cf2c9b2e72e7indicates -
94ff4679dd5aec7874354c14132701ecdfbbb558c6011e4952d13bf843255529indicates -
76fc76dc651c3cc9d766a6ad8a90f605326463bc4cb2f8f053d44dfbc913beeeindicates -
6d2a4d9e2fc6e4dac2c426851b4bdf86dd63a5515d8d853e622a0bc01d250ce9indicates -
http://teamszv.comindicates -
4556d5d106adbd9e1c5627940bd2314ca59b2cc8c01359680ca70928b6bafc50indicates -
b.yuxuanow.topindicates -
https://roldco.com/api/download/c51bbd17-ef08-4d6c-ab4c-d7bf49483dd6indicates -
hhiioo.workindicates -
d51db234d0236cd0dbfcf13adc33387f10920011537815d188eff012872e30beindicates -
http://6014.anonymousrat7.com:80indicates -
517b43bf057877727387316d8538dc07599856eb428d43f512e89964a5dfb331indicates -
http://154.82.81.205/YD20251001143052.zip'indicates -
https://abc.fetish-friends.com/uploads/appclient.zipindicates -
43.226.125.124indicates -
108.187.41.221indicates -
8378960ee2bfc32930e19f762f561f4a6448160de2bde6ce330309326d745f89indicates -
1ec74968e59e18b32f6b68c38c3a72e09a3a9160d8c3e58a5f8f90c0a14223d6indicates -
c5d5054047a12efc68a67abd8f15069a853dd09800cd39d68df5a27702b45334indicates -
gov-a.workindicates -
949b0bea5bd7feab58e280dde49310521920b655714c5f1b7d9de8719373dcd7indicates -
192.238.205.47indicates -
twmoi2002.tos-cn-shanghai.volces.comindicates -
de8a0da702a491f610b9e85050d8641cadf4ed84edf4d151f94335b0d78d6636indicates -
b26aecc21da159c0073ecde31cc292d87c8674af8c312776d2cc9827e5c1ad6aindicates -
d8f9f8bc811f428dd9605000470c5f496f46145e2d3d8b7e750bca901e55fcddindicates -
obfuscate.ioindicates -
vnc.kcii2.comindicates -
itdd.clubindicates -
160.124.9.103indicates -
6e71e6b3a56db2c349c19cb20e5bc1eb87f98bd61af27887e73935bed3c5e2acindicates -
e26d5e23bee9695b05323928f66cec4d969178ebfc00e9930b71c356c5d37167indicates -
7eaed6fa867875119c3ebb40aa24716d91fdbccb2106fa4708ff0637920a920cindicates -
https://sudsmama.com/api/download/50e24b3a-8662-4d2f-9837-8cc62aa8f697indicates -
teams.kkkgenieyesl.cnindicates -
http://zbyq.cn/Set^up^64.e^x^eindicates -
image.tuchuang.coindicates -
http://teams.kkkgenieyesl.cnindicates -
5f9a5ad43a9f79976cd7014ce072429ef2edbae872b4226372cfb07d8a86b8a5indicates -
d0ac4eb544bc848c6eed4ef4617b13f9ef259054fe9e35d9df02267d5a1c26b2indicates -
huorongh.comindicates -
99fb7a40dbf6a042bcb77f67a5a76fe03ec3c6820ac5e15cb009795d545152eaindicates -
207.56.138.28indicates -
30147b6691e5bc1a15c76cebf81b2de77d9099e8200b6ed9742c6e3b36505f34indicates -
http://teams.telegramzwxz.comindicates -
d92850cc929423eab1da0022a4d8cc8394d44f1b3efd581ff9473cd38e81d4c5indicates -
6ebe9d4cffadf2566a960067fc226739dd74f361dca0b0809df66f1c7bb8049dindicates -
192.229.115.229indicates -
0e66d7ec29ad8b088971d337db79bc916c219e523bd538f5a9dc7e0179c2547aindicates -
http://binancegames.sbindicates -
5207b0111dc5cc23da549559a8968ee36e39b5d8776e6f5b1e6bdc367937e7dfindicates -
xzghjec.comindicates -
9aea0fdfead2e956bc0b4574c2b4cb2855dd9df6a5fd61d350f3285d249adfcaindicates -
192.163.167.14indicates -
ce8224de916a5eb0c76c9ba7acc3833f8cdc7f7d31a72dfbe69d2be1f8b7cc48indicates -
213ed93b19f0130313933a700cafbaa27bef8e1a60157b225959624a4c875068indicates -
ggwk.ccindicates -
f919634ac7e0877663fff06ea9e430b530073d6e79eee543d02331f4dff64375indicates -
fa26722e99763a29af160fae64183a47a57362b666753624b78e954c8cde0525indicates -
a92b2727de7c14b63c50b7062b2fcf61098a5d4d8bf3f749444e72b0cfc45f2bindicates -
7c31c4d0308fb1d67f6af48a76138a9db19f494c1e9a12debdcca7382ad5418cindicates -
ad753becec205160b78de45c11ed42f3da707c9cee0688fa4190233a9b4f1379indicates -
46af73560cafff5c8bbc16980d01641af0de3b689bc248dfb52afcf3a8a76a55indicates -
9aa51d1c82fdbc8f0f27340180bd40faa7e76b8ac6d204b2d3548cfd0897d805indicates -
2074ec1d3f58b19bd398b45af71b9853d6c3a0fa7c7145d76208601cfb05d1d6indicates -
a47423b59d75e228198450f7a9a2e051eeca6388028a6deb8e9843951bf21575indicates -
84f7ca5e09b2b3a4da145b1d43f23e0d3e93c208cd0f22b8b08efe5d4c45f38bindicates -
e54ce9939679c691dc5719e309a8d541183b6672269fd61013109ef0d8509b1eindicates -
17ff585fadcf40e25ad9d09cf007d20f6691ccf31d93a5d48d25f7e811cb0ca4indicates -
e96091fd784eca3c56ce4a703b22f5e5941464aec32a6f356ad0f99ea4422f04indicates -
207.56.119.216indicates -
http://teams.hardepc.comindicates -
25b6f65c07b83293958c6f1e36d053b1d39c5dde864fde5cfc1834ecca591139indicates -
http://6esygx.spaceindicates -
f06bd6e7a237c90800c09a584bd55ea5feaba92c29449c2bdfb8b93d0b830a78indicates -
ae6d88ea99e530f778ee6088862b50dfb6e8bb45857211e9105428c57c2a7b4aindicates -
db8cbf938da72be4d1a774836b2b5eb107c6b54defe0ae631ddc43de0bda8a7eindicates -
77ea62ff74a66f61a511eb6b6edac20be9822fa9cc1e7354a8cd6379c7b9d2d2indicates -
0b33f08bc2917c4825c053754fc88e16b35d1a8fff4135595b265a4c6f850250indicates -
kkyui.clubindicates -
c070749f95aeeefcd1c3a875c1b8e77b57cad0c8338436af9a3c9e1323fd4e11indicates -
http://teamscn.comindicates -
5af1dae21425dda8311a2044209c308525135e1733eeff5dd20649946c6e054cindicates -
134.122.207.20indicates -
tkooyvff.cnindicates -
33bc111238a0c6f10f6fe3288b5d4efe246c20efd8d85b4fe88f7d602d70738eindicates