TA829
· Published 21/12/2025 14:36 · Modified 21/12/2025 14:36
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 14:36
- Modified
- 21/12/2025 14:36
- Updated at
- 21/12/2025 14:36
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 19 attack patterns (mitre), 9 malware, 1 sectors, 2 countries, 107 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
19 MITREs 9 Malwares 103 Observables 1 APTPublished 01/07/2025 08:07 · Modified 01/07/2025 08:36
Attack patterns (MITRE) (19)
-
T1012 usesQuery Registry
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1588.002 usesTool
-
T1587.001 usesMalware
-
T1059 usesCommand and Scripting Interpreter
-
T1583.001 usesDomains
-
T1105 usesIngress Tool Transfer
-
T1547.001 usesRegistry Run Keys / Startup Folder
-
T1102.001 usesDead Drop Resolver
-
T1071.001 usesWeb Protocols
-
T1588.001 usesMalware
-
T1112 usesModify Registry
-
T1016 usesSystem Network Configuration Discovery
-
T1218.011 usesRundll32
-
T1057 usesProcess Discovery
-
T1082 usesSystem Information Discovery
-
T1027.002 usesSoftware Packing
-
T1102.002 usesBidirectional Communication
-
T1027 usesObfuscated Files or Information
Malware (9)
-
SlipScreen usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
TransferLoader usesFamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
-
HellCat usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
MeltingClaw usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
ShadyHammock usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
DustyHammock usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
RustyClaw usesFamilyPublished 15/09/2025 18:00 · Modified 15/09/2025 18:00
-
SingleCamper usesFamilyPublished 01/07/2025 08:07 · Modified 01/07/2025 08:07
-
Morpheus usesFamilyPublished 25/09/2025 09:21 · Modified 25/09/2025 09:21
Sectors (1)
- Defense targets
Countries (2)
- Ukraine targets
- United States of America targets
Indicators (107)
-
share-doc.liveindicates -
drivedefend.comindicates -
1drive.worksindicates -
file-share.worksindicates -
1drv.bizindicates -
onedrivecloud.clickindicates -
1dcloud.liveindicates -
1drivems.expertindicates -
ondv.liveindicates -
my1drv.liveindicates -
msvhost.comindicates -
mngersrv.comindicates -
livestorage.clickindicates -
workspace-doc.liveindicates -
cloud1dv.comindicates -
1drvcloud.onlineindicates -
1drive-work.onlineindicates -
supportcausems.comindicates -
drivehost.liveindicates -
cdngateway.usindicates -
drsync.clickindicates -
share-pdf.liveindicates -
opendnsapi.netindicates -
lauradream.comindicates -
onedrivecloud.liveindicates -
onefile.socialindicates -
diskstorage.clickindicates -
7fc65b23e0a85f548e4268b77b66a3c9f3d08b9c1817c99bc1336d51d36e1ec6indicates -
8f3b065e6aa6bc220867cdcb1c250c69b2d46422c51f66f25091f6cab5d043deindicates -
onedr.expertindicates -
site-staff.saleindicates -
e7917ff12114be5c79ca9bd0082eb628192c2ebfbee7aad2ae626ea208ee37cfindicates -
healthfy.bioindicates -
my1drv.onlineindicates -
1drvfiles.onlineindicates -
1drv.worldindicates -
f5f2761278163a1a813356666cb305fe37806f5f633b2a5475997f10d24fb3d4indicates -
d1rv.socialindicates -
cd526475391c375e8e40f0146146672928db9bbf210acb41e0fd41381cd5eb9aindicates -
data-dv.liveindicates -
1drv365.onlineindicates -
onedrivems.cloudindicates -
consvcprivacy.comindicates -
1drivecloud.clickindicates -
1drive.bioindicates -
pdfshare.clickindicates -
onestorelink.liveindicates -
sharepdf.limitedindicates -
drivestorage.onlineindicates -
myonedrive365.liveindicates -
onedrivecloud.expertindicates -
deliverycitylife.comindicates -
1drv365.liveindicates -
gdrvdocs.onlineindicates -
1c6a5476d485d311be1e07c2e0d2ae322214caa5d4f84398d4169d499105b01aindicates -
1drv-team.worksindicates -
54a94c7ec259104478b40fd0e6325d1f5364351e6ce1adfd79369d6438ed6ed9indicates -
gdl-cloud.worksindicates -
clouderive.comindicates -
1drvms.spaceindicates -
fba9f2c351e898bfc61c8b1181020212ccb9e55041c4dd433ca2867dbf796469indicates -
1drivems.worksindicates -
temptransfer.liveindicates -
journalctl.websiteindicates -
onlinedrive.clickindicates -
365msdrv.liveindicates -
drivepublic.liveindicates -
3a234b49b834849689da477f77ca6363b40ee83e58213ee51b1ec248da90a543indicates -
7e51eb44cfd945f4a155707f773fae3207ebfb59d45ea866ba69bd9bc28dfc32indicates -
my-356drv.onlineindicates -
mydrv1.liveindicates -
1dvstorage.comindicates -
file-acess.liveindicates -
drshare.onlineindicates -
1dv365.liveindicates -
dvcloud.liveindicates -
1drive.socialindicates -
datadrv1.comindicates -
1drive.expertindicates -
1day.liveindicates -
1share.limitedindicates -
onedrivecloud.netindicates -
365drv.liveindicates -
drivehub.liveindicates -
33971df8f5c34c3c79f64e2e28e300260499285bd37f77295ba88897728ace4bindicates -
dr365.liveindicates -
onedrweb.liveindicates -
onedrivems.worksindicates -
ms.share-onedr.comindicates -
gworkspace.socialindicates -
onelivedrv.comindicates -
00385cae3630694eb70e2b82d5baa6130c503126c17db3fc63376c7d28c04145indicates -
mspdf.liveindicates -
365work.chatindicates -
1drivecloud.liveindicates -
1drw.liveindicates -
6d5226cba687d99ce14eda8de290edd470e79436625618559c8db1458a53666cindicates -
ondrve.liveindicates -
1drv.siteindicates -
gdrive-share.onlineindicates -
documentapproved.clickindicates -
1drv.meindicates -
file-cloud.companyindicates -
cloudly.liveindicates -
1drv.zoneindicates -
07b9e353239c4c057115e8871adc3cfb42467998c6b737b28435ecc9405001c9indicates -
cloud-pdf.onlineindicates