WEBJACK
· Published 21/12/2025 18:50 · Modified 21/12/2025 18:50
· Source: AlienVault
Essential information
- Confidence
- 100/100
- Published
- 21/12/2025 18:50
- Modified
- 21/12/2025 18:50
- Updated at
- 21/12/2025 18:50
- Revoked
- No
- Author / Source
- AlienVault
- Resource level
- —
- Primary motivation
- —
- Related entities
- 1 reports, 11 attack patterns (mitre), 4 malware, 3 sectors, 1 countries, 25 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators and other entities linked to this intrusion set.
Reports (1)
-
11 MITREs 4 Malwares 34 Observables 1 APTPublished 19/11/2025 09:01 · Modified 19/11/2025 09:34
Attack patterns (MITRE) (11)
-
T1574 usesHijack Execution Flow
-
T1564.001 usesHidden Files and Directories
-
T1027.002 usesSoftware Packing
-
T1055 usesProcess Injection
-
T1572 usesProtocol Tunneling
-
T1071.001 usesWeb Protocols
-
T1046 usesNetwork Service Discovery
-
T1190 usesExploit Public-Facing Application
-
T1505 usesServer Software Component
-
T1003 usesOS Credential Dumping
-
T1070.001 usesClear Windows Event Logs
Malware (4)
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 19:39 · Modified 27/05/2026 21:40
-
m0yv usesFamilyPublished 19/11/2025 09:01 · Modified 19/11/2025 09:01
-
BadIIS usesFamilyPublished 05/06/2026 18:07 · Modified 05/06/2026 18:07
-
XlAnyLoader usesFamilyPublished 19/11/2025 09:01 · Modified 19/11/2025 09:01
Sectors (3)
- Education targets
- Technology targets
- Government targets
Countries (1)
- France targets
Indicators (25 / 34)
-
86b8605b4870be8c3e83e51b4e3ee80e781a7c5a0104ffa656da651a03579c5aindicates -
e51ea911a281097be040ac2871134e6c7d5c3b37c8b46d2267ad40a18a05d2ecindicates -
jiankong.sneaws.comindicates -
48ec6530470b295db455bf2c72dc4fbd18672725f45821304f966d436b428865indicates -
767576a2b67a3a53883b174a50c83192d0930a4ce213af5f5093e6ee26910d2bindicates -
seo.667759.comindicates -
bab9a644aff24cf313210cc6632f71d935a428ea0efb3823c0dbe6dccabe4b73indicates -
jk.667759.comindicates -
c17d1bb654bfa9ff9f612d37c1204585cfc76d663818a23aac78ba43e35e3df0indicates -
tdk.jmfwy.comindicates -
6b60b6df8a1a95f51ffe57255c05d26eb9e113857efac3b29d6ef080b8d414f3indicates -
72cf397738724b1f555c147005c61c058619405846460a60b02a2af75b57a81eindicates -
mail.tttseo.comindicates -
c9b4657b6aea927bb0f601f2063e743f8702408c98d01ca3332692b29c4d90caindicates -
00c7efe65ab90c03678359f5ba6b24d9f938a28205652dd61f15d7a31323cf1bindicates -
561fcf1a2d6cc2170d2b538f416e95d981663984e384da51b36ffe97d2653dcdindicates -
ttseo66.comindicates -
ffa835cd05558fa52a12e91136c4e8a3e7393b3155a6be7877812c6e7d1ff811indicates -
w5c.sneaws.comindicates -
ffbad7beab3e0888d6957637f2ec80156402ad540e9c92ebb243fe27bea1f598indicates -
d8c0ef6dbf7d4572f92d3a492f32061ab8f3dd46beb9ff5a0bf9bf550935458cindicates -
kaifa.sneaws.comindicates -
b0842c9916449de6d4b4159d6c5af747d6fb40609510d6a8d2eb669932c1f661indicates -
9a2fd34e22c5f3d3d5fb96e3cd514dad7b03ed7bf53a87e7d8d9b73987d02eceindicates -
11265422e79f2cd057ee1ae38a16e5db54039711ae8cdb9e177aebfde5666f32indicates