8Base
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:40
- Modified
- 21/12/2025 01:04
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 42 attack patterns (mitre), 7 sectors, 3 countries, 10 indicators, 17 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (42)
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1564 usesHide Artifacts MITRE
-
T1074 usesData Staged MITRE
-
T1566 usesPhishing MITRE
-
T1005 usesData from Local System MITRE
-
T1003 usesOS Credential Dumping MITRE
-
T1129 usesShared Modules MITRE
-
T1548 usesAbuse Elevation Control Mechanism MITRE
-
T1490 usesInhibit System Recovery MITRE
-
T1574 usesHijack Execution Flow MITRE
-
T1598 usesPhishing for Information MITRE
-
T1485 usesData Destruction MITRE
Sectors (7)
-
Information Technologies Consulting targets
-
Accounting targets
-
Legal consulting targets
-
Healthcare targets
-
Construction targets
-
Manufacturing targets
-
Finance targets
Countries (3)
-
United States of America targets
-
Brazil targets
-
United Kingdom of Great Britain and Northern Ireland targets
Indicators (10)
-
stix 100/100 Revoked
Trojan:Win32/Phoenix SHA256 of b092a6bf7fb6755e095ed9f35147d1c6710cf2c4
· Valid until 03/06/2025 · Source: AlienVault -
stix 100/100 Revoked
Ransom:Win32/Phobos.PC!MTB SHA256 of cb37b10b209ab38477d2e17f21cae12a1cb2adf0
· Valid until 03/06/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 03/06/2025 · Source: AlienVault
-
stix 100/100 Revoked
Win.Packer.pkr_ce1a-9980177-0 SHA256 of 4a8f0331abaf8f629b3c8220f0d55339cfa30223
· Valid until 03/06/2025 · Source: AlienVault -
stix 100/100 Revoked
Ransom:Win32/Phobos.PC!MTB SHA256 of 43683751209e85571072d953c0bdd44c883045ee
· Valid until 03/06/2025 · Source: AlienVault -
stix 100/100 Revoked
Win.Ransomware.Ulise-7594403-0 SHA256 of aed68cfa282ec2b0f8a681153beaebe3a17d04ee
· Valid until 03/06/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 30/10/2024 · Source: AlienVault
-
stix 100/100 Revoked
Win.Malware.Phobos-6981135-0 SHA256 of c88fad293256bfead6962124394de4f8b97765aa
· Valid until 03/06/2025 · Source: AlienVault
Vulnerabilities (CVE) (17)
The VMware Tanzu Application Service for VMs and Isolation Segment contain an information disclosure vulnerability due to the logging of credentials in …
- Attack vector
- NETWORK
- Published
- 26/07/2023
- Modified
- 21/12/2025
Out of bounds memory access in Mojo in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who had compromised the renderer …
- Attack vector
- NETWORK
- Published
- 02/08/2023
- Modified
- 21/12/2025
Privilege Escalation to root administrator (nsroot)
- Attack vector
- ADJACENT_NETWORK
- Published
- 19/07/2023
- Modified
- 21/12/2025
Use after free in WebRTC in Google Chrome prior to 115.0.5790.98 allowed a remote attacker to potentially exploit heap corruption via a …
- Attack vector
- NETWORK
- Published
- 02/08/2023
- Modified
- 21/12/2025
Ivanti Endpoint Manager Mobile (EPMM, previously branded MobileIron Core) contains an authentication bypass vulnerability that allows unauthenticated access to specific API paths. …
- Attack vector
- Network
- Published
- 25/07/2023
- Modified
- 21/12/2025
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.46 and …
- Attack vector
- NETWORK
- Published
- 18/07/2023
- Modified
- 21/12/2025
Atera Agent through 1.8.3.6 on Windows Creates a Temporary File in a Directory with Insecure Permissions.
- Attack vector
- LOCAL
- Published
- 24/07/2023
- Modified
- 21/12/2025
Apple iOS, iPadOS, macOS, tvOS, and watchOS contain an unspecified vulnerability allowing an app to modify a sensitive kernel state.
- Attack vector
- Local
- Published
- 26/07/2023
- Modified
- 21/12/2025
Use after free in Tab Groups in Google Chrome prior to 115.0.5790.98 allowed a remote attacker who convinced a user to engage …
- Attack vector
- NETWORK
- Published
- 02/08/2023
- Modified
- 21/12/2025
The PKCS#11 feature in ssh-agent in OpenSSH before 9.3p2 has an insufficiently trustworthy search path, leading to remote code execution if an …
- Attack vector
- NETWORK
- Published
- 20/07/2023
- Modified
- 21/12/2025
Citrix NetScaler ADC and NetScaler Gateway contains a code injection vulnerability that allows for unauthenticated remote code execution.
- Attack vector
- Network
- Published
- 19/07/2023
- Modified
- 27/05/2026
A CWE-754: Improper Check for Unusual or Exceptional Conditions vulnerability exists that could cause arbitrary code execution, denial of service and loss …
- Attack vector
- NETWORK
- Published
- 30/01/2023
- Modified
- 21/12/2025