Going Eagle
AlienVault
· Published 20/12/2025 19:34 · Modified 20/12/2025 21:15
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:34
- Modified
- 20/12/2025 21:15
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 14 attack patterns (mitre), 8 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (14)
-
T1568 usesDynamic Resolution MITRE
-
T1021 usesRemote Services MITRE
-
T1046 usesNetwork Service Discovery MITRE
-
T1038 uses
-
T1090 usesProxy MITRE
-
T1087 usesAccount Discovery MITRE
-
T1195 usesSupply Chain Compromise MITRE
-
T1574 usesHijack Execution Flow MITRE
-
T1016 usesSystem Network Configuration Discovery MITRE
-
T1070 usesIndicator Removal MITRE
-
T1218 usesSystem Binary Proxy Execution MITRE
-
T1003 usesOS Credential Dumping MITRE
Indicators (8)
-
stix 100/100 Revoked· Valid until 06/09/2023 · Source: AlienVault
-
general_win_faked_dlls_export_popoindicatesyara 100/100 Revokedgeneral_win_faked_dlls_export_popo Detects DLL files with an export function named 'popo'
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/09/2023 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 06/09/2023 · Source: AlienVault
-
4c9f59bafba49c8dda245fb992418c66a9427691indicatesyara 100/100 Revokedpotentially unwanted GO application with proxy communication capabilities
· Valid until 06/09/2023 · Source: AlienVault -
stix 100/100 Revoked· Valid until 06/09/2023 · Source: AlienVault