CosmicBeetle
AlienVault
· Published 20/12/2025 19:40 · Modified 21/12/2025 01:13
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:40
- Modified
- 21/12/2025 01:13
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 41 attack patterns (mitre), 3 sectors, 6 countries, 14 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (41)
-
T1595 usesActive Scanning MITRE
-
T1132 usesData Encoding MITRE
-
T1090 usesProxy MITRE
-
T1041 usesExfiltration Over C2 Channel MITRE
-
T1136 usesCreate Account MITRE
-
T1190 usesExploit Public-Facing Application MITRE
-
T1071 usesApplication Layer Protocol MITRE
-
T1036 usesMasquerading MITRE
-
T1105 usesIngress Tool Transfer MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1547 usesBoot or Logon Autostart Execution MITRE
-
T1124 usesSystem Time Discovery MITRE
Sectors (3)
-
Government targets
-
Hospitality targets
-
Culture and entertainment targets
Countries (6)
-
Thailand targets
-
Türkiye targets
-
Mexico targets
-
Israel targets
-
Poland targets
-
Brazil targets
Indicators (14)
-
1HtkNb73kvUTz4KcHzztasbZVonWTYRfVxindicatesstix 100/100 Revoked· Valid until 05/12/2024 · Source: AlienVault -
stix 100/100 Revoked
stack_string SHA256 of 40b8af12ea6f89db6ed635037f468aadee7f4ca6
· Valid until 25/11/2024 · Source: AlienVault -
stix 100/100 Revoked
Ransom:Win32/Pulobe.RB!MSR SHA256 of 8f1374d4d6cc2899da1251de0325a7095e719edc
· Valid until 25/11/2024 · Source: AlienVault