TA413
· Published 20/12/2025 21:15 · Modified 20/12/2025 21:15
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 21:15
- Modified
- 20/12/2025 21:15
- Updated at
- 20/12/2025 21:15
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 4 attack patterns (mitre), 1 malware, 4 countries, 17 indicators, 2 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (4)
Malware (1)
-
Turian uses
Countries (4)
-
India targets
-
Russian Federation targets
-
Philippines targets
-
Nepal targets
Indicators (17)
-
248296cf75065c7db51a793816d388ad589127c40fddef276e622a160727ca29indicates -
xmlformats.comindicates -
coolrat.xyzindicates -
710370f6142d945e142890eb427a368bfc6c5fe13a963f952fb884c38ef06bfaindicates -
3db60df73a92b8b15d7885bdcc1cbcf9c740ce29c654375a5c1ce8c2b31488a1indicates
Vulnerabilities (CVE) (2)
CVE-2022-21907
targets
9.8
Critical
HTTP Protocol Stack Remote Code Execution Vulnerability
- Attack vector
- NETWORK
- Published
- 11/01/2022
- Modified
- 20/12/2025
A remote code execution vulnerability exists when MSDT is called using the URL protocol from a calling application such as Word. An …
- Published
- 14/06/2022
- Modified
- 27/05/2026