Alice
AlienVault
· Published 20/12/2025 19:36 · Modified 20/12/2025 22:24
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:36
- Modified
- 20/12/2025 22:24
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 16 attack patterns (mitre), 8 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (16)
-
T1528 usesSteal Application Access Token MITRE
-
T1082 usesSystem Information Discovery MITRE
-
T1020 usesAutomated Exfiltration MITRE
-
T1083 usesFile and Directory Discovery MITRE
-
T1053 usesScheduled Task/Job MITRE
-
T1566 usesPhishing MITRE
-
T1486 usesData Encrypted for Impact MITRE
-
T1087 usesAccount Discovery MITRE
-
T1134 usesAccess Token Manipulation MITRE
-
T1218 usesSystem Binary Proxy Execution MITRE
-
T1071 usesApplication Layer Protocol MITRE
-
T1497 usesVirtualization/Sandbox Evasion MITRE
Indicators (8)
-
stix 100/100 Revoked· Valid until 21/02/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 21/02/2024 · Source: AlienVault
-
stix 100/100 Revoked
Win32:RansomX-gen\ [Ransom] SHA256 of ca349c0ddd6cda3a53ada634c3c1e1d6f494da8a
· Valid until 21/02/2024 · Source: AlienVault -
stix 100/100 Revoked
ALF:HeraklezEval:Trojan:Win64/CoinMiner.DA!rfn SHA256 of c3d5c1f5ece8f0cf498d4812f981116ad7667286
· Valid until 21/02/2024 · Source: AlienVault -
stix 100/100 Revoked
Win32:RansomX-gen\ [Ransom] SHA256 of a5f53c9b0f7956790248607e4122db18ba2b8bd9
· Valid until 21/02/2024 · Source: AlienVault -
stix 100/100 Revoked
Win32:RansomX-gen\ [Ransom] SHA256 of 03d871509a7369f5622e9ba0e21a14a7e813536d
· Valid until 21/02/2024 · Source: AlienVault -
stix 100/100 Revoked· Valid until 21/02/2024 · Source: AlienVault
-
stix 100/100 Revoked
Win32:RansomX-gen\ [Ransom] SHA256 of 60a692c6eaf34a042717f54dbec4372848d7a3e3
· Valid until 21/02/2024 · Source: AlienVault