TA571
· Published 21/12/2025 01:30 · Modified 21/12/2025 01:30
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 01:30
- Modified
- 21/12/2025 01:30
- Updated at
- 21/12/2025 01:30
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 17 attack patterns (mitre), 8 malware, 25 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
9 MITREs 8 Malwares 14 Observables 1 APTPublished 17/06/2024 11:23 · Modified 17/06/2024 11:38
Attack patterns (MITRE) (17)
-
T1547 usesBoot or Logon Autostart Execution
-
T1028 uses
-
T1105 usesIngress Tool Transfer
-
T1218 usesSystem Binary Proxy Execution
-
T1027 usesObfuscated Files or Information
-
T1087 usesAccount Discovery
-
T1053.005 usesScheduled Task
-
T1557.002 usesARP Cache Poisoning
-
T1059.001 usesPowerShell
-
T1185 usesBrowser Session Hijacking
-
T1204 usesUser Execution
-
T1059 usesCommand and Scripting Interpreter
-
T1193 uses
-
T1486 usesData Encrypted for Impact
-
T1055 usesProcess Injection
-
T1106 usesNative API
-
T1071 usesApplication Layer Protocol
Malware (8)
-
JaskaGO usesFamilyPublished 17/06/2024 11:23 · Modified 17/06/2024 11:23
-
Amadey Loader usesFamilyPublished 17/06/2024 11:23 · Modified 17/06/2024 11:23
-
Lumma Stealer usesFamilyPublished 08/06/2026 19:36 · Modified 08/06/2026 19:36
-
XMRig usesFamilyPublished 28/05/2026 10:56 · Modified 28/05/2026 10:56
-
Matanbuchus usesFamilyPublished 09/12/2025 05:39 · Modified 09/12/2025 05:39
-
DarkGate usesFamilyPublished 21/08/2025 21:03 · Modified 21/08/2025 21:03
-
Vidar Stealer usesFamilyPublished 07/04/2025 19:41 · Modified 07/04/2025 19:41
-
NetSupport usesFamilyPublished 03/11/2025 14:28 · Modified 03/11/2025 14:28
Indicators (25 / 32)
-
http://mylittlecabbage.net/xcdttafqindicates -
liguys.comindicates -
6c6a68da31204cfe93ee86cd85cf668a20259220ad44341b3915396e263e4f86indicates -
modalefastnow.comindicates -
brandworks.com.auindicates -
compacta.comindicates -
07e0c15adc6fcf6096dd5b0b03c20145171c00afe14100468f18f01876457c80indicates -
a12045a6177dd32af8b39dea93fa92962ff1716381d0d137dede1fc75ecd2c0cindicates -
https://cdn3535.shop/1.zipindicates -
https://rtattack.baqebei1.online/df/ttindicates -
jonanna.comindicates -
57897b750473215a2ea6a15070ad5334465019ea4847a2c3c92dae8e5845b2c4indicates -
jerryposter.comindicates -
https://lashakhazhalia86dancer.com/c.txtindicates -
gestionhqse.comindicates -
https://jenniferwelsh.com/header.pngindicates -
http://mylittlecabbage.net/qhsddxnaindicates -
naughtycharlotte.comindicates -
11909c0262563f29d28312baffb7ff027f113512c5a76bab7c5870f348ff778findicates -
0a61d734db49fdf92f018532b2d5e512e90ae0b1657c277634aa06e7b71833c4indicates -
ekaraj.irindicates -
roatancruiseship.comindicates -
karo.caindicates -
gilaniultrasound.comindicates -
https://kostumn1.ilabserver.com/1.zipindicates