TEMP.Hermit
· Published 20/12/2025 23:34 · Modified 20/12/2025 23:34
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 20/12/2025 23:34
- Modified
- 20/12/2025 23:34
- Updated at
- 20/12/2025 23:34
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 20 attack patterns (mitre), 6 malware, 3 sectors, 2 countries, 25 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Attack patterns (MITRE) (20)
-
T1133 usesExternal Remote Services
-
T1574 usesHijack Execution Flow
-
T1547 usesBoot or Logon Autostart Execution
-
T1560 usesArchive Collected Data
-
T1036 usesMasquerading
-
T1566 usesPhishing
-
T1553 usesSubvert Trust Controls
-
T1027 usesObfuscated Files or Information
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1055 usesProcess Injection
-
T1056 usesInput Capture
-
T1102 usesWeb Service
-
T1059 usesCommand and Scripting Interpreter
-
T1105 usesIngress Tool Transfer
-
Multi-Stage Channels usesT1104
-
T1070 usesIndicator Removal
-
T1573 usesEncrypted Channel
-
T1115 usesClipboard Data
-
T1113 usesScreen Capture
-
T1562 usesImpair Defenses
Malware (6)
- TOUCHSHIFT
- LIDSHOT
- LIGHTSHIFT
- SIDESHOW
- PLANKWALK
- LIDSHIFT
Sectors (3)
- Media targets
- Defense targets
- Technology targets
Countries (2)
- United States of America targets
- Korea, Republic of targets
Indicators (25 / 40)
-
318ebae17599da88f559ecd2d16add02e4f608d9indicates -
www.fainstec.comindicates -
bee21f2ee8dc32ded744ae728fe499bbb0b23b07indicates -
olidhealth.comindicates -
7724cbae651cbd782aae247b4f91ef7982b34047indicates -
ee5057da3e38b934dae15644c6eb24507fb5a187630c75725075b24a70065452indicates -
https://sede.lamarinadevalencia.com/tablonEdictal/layout/contentLayout.jspindicates -
ce501fd5c96223fb17d3fed0da310ea121ad83c463849059418639d211933aa4indicates -
crickethighlights.todayindicates -
www.ruscheltelefonia.com.brindicates -
71d27fe64df4fdc82153f246f3f55c5ac0a16287indicates -
http://mantis.quick.net.pl/library/securimage/index.phpindicates -
mantis.quick.net.plindicates -
www.keewoom.co.krindicates -
https://crickethighlights.today/wp-content/plugins/contact.phpindicates -
https://leadsblue.com/wp-content/wp-utility/index.phpindicates -
955f1309d0c2b80fb3aace6943c32ca1c0557f81indicates -
leadsblue.comindicates -
5983dc3361dfb765c62119e0836c9b799c11a5ccindicates -
f6bae38338601d961248e43ffdae05bdf4336edeea9eaf806f481e5f24700249indicates -
http://webinternal.anyplex.com/images/query_image.jspindicates -
2733a8e3ab7de1f89fbf8412600b6ed837a2ea1findicates -
sede.lamarinadevalencia.comindicates -
https://olidhealth.com/wp-includes/php-compat/compat.phpindicates -
http://www.ruscheltelefonia.com.br/public/php/index.phpindicates