Gopuram
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:38
- Modified
- 29/05/2026 12:20
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 22 attack patterns (mitre), 1 intrusion sets (apt), 5 sectors, 8 countries, 46 indicators, 2 vulnerabilities (cve), 1 reports
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (22)
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1115 usesClipboard Data MITRE
-
T1106 usesNative API MITRE
-
T1102 usesWeb Service MITRE
-
T1195 usesSupply Chain Compromise MITRE
-
T1003 usesOS Credential Dumping MITRE
-
T1546 usesEvent Triggered Execution MITRE
-
T1057 usesProcess Discovery MITRE
-
T1127 usesTrusted Developer Utilities Proxy Execution MITRE
-
T1495 usesFirmware Corruption MITRE
-
T1049 usesSystem Network Connections Discovery MITRE
-
TA0008 uses
Intrusion sets (APT) (1)
-
Lazarus usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (5)
-
Road transport targets
-
Technology targets
-
Universities targets
-
Defense targets
-
Government targets
Countries (8)
-
Hong Kong targets
-
Brazil targets
-
Germany targets
-
United States of America targets
-
Taiwan targets
-
France targets
-
Cyprus targets
-
Italy targets
Indicators (46)
-
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of e7aa0237fc3db67a96ebd877806a2c88
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked· Valid until 19/08/2024 · Source: AlienVault
-
stix 100/100 Revoked
Doc.Dropper.Agent-6960083-0 SHA256 of 7a73a2261e20bdb8d24a4fb252801db7
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
stack_string SHA256 of eb2dc282ad3ab29c1853d4f6d09bec4f SHA256 of eb2dc282ad3ab29c1853d4f6d09bec4f
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 11fdc0be9d85b4ff1faf5ca33cc272ed
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
LZMA SHA256 of d1c652b4192857cb08907f0ba1790976
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
TELPER:Trojan:Win32/ShortWick.B!dha SHA256 of 706e55af384e1d8483d2748107cbd57c
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
Other:Malware-gen\ [Trj] SHA256 of 9121f1c13955506e33894ffd780940cd
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SLF:SCPT:OffRelAttachedTemplateHttp.A SHA256 of 4c239a926676087e31d82e79e838ced1
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of 2efbe6901fc3f479bc32aaf13ce8cf12
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
LZMA SHA256 of 075fba0c098d86d9f22b8ea8c3033207
· Valid until 15/07/2024 · Source: AlienVault -
stix 100/100 Revoked
SHA256 of f6d6f3580160cd29b285edf7d0c647ce
· Valid until 15/07/2024 · Source: AlienVault
Vulnerabilities (CVE) (2)
Microsoft Win32k fails to properly handle objects in memory causing privilege escalation. Successful exploitation allows an attacker to run code in kernel …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Win32k contains a privilege escalation vulnerability when the Win32k component fails to properly handle objects in memory. Successful exploitation allows an …
- Published
- 03/11/2021
- Modified
- 29/05/2026
Reports (1)
-
Confidence 100 18 CVEs 200 MITREs 200 Malwares 20 APTs 26 Tools