Lizar
Essential information
- Confidence
- 100/100
- Is family
- Yes
- Published
- 02/02/2022 22:05
- Modified
- 27/03/2026 01:07
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Related entities
- 44 attack patterns (mitre), 2 intrusion sets (apt), 1 sectors, 36 indicators, 3 vulnerabilities (cve)
Aliases
Tirion Icebot DiceLoader
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (44)
-
T1053.005 usesScheduled Task MITRE
-
T1059.006 usesPython MITRE
-
T1059.001 usesPowerShell MITRE
-
T1105 usesIngress Tool Transfer MITRE
-
T1090 usesProxy MITRE
-
T1497.001 usesSystem Checks MITRE
-
T1055.001 usesDynamic-link Library Injection MITRE
-
T1033 usesSystem Owner/User Discovery MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1087.003 usesEmail Account MITRE
-
T1132.002 usesNon-Standard Encoding MITRE
-
T1531 usesAccount Access Removal MITRE
Intrusion sets (APT) (2)
-
The MITRE Corporation Confidence 100
[FIN7](https://attack.mitre.org/groups/G0046) is a financially-motivated threat group that has been active since 2013. [FIN7](https://attack.mitre.org/groups/G0046) has targeted the retail, restaurant, hospitality, software, consulting, financial services, medical equipment, cloud services, media,…
First seen 01/01/1970 · Last seen 16/11/5138 · -
Bl00dy usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (1)
-
Education targets
Indicators (36)
-
194.87.82.7indicatesstix 100/100 RevokedCC=NL ASN=AS41745 Baykov Ilya Sergeevich
· Valid until 28/06/2023 · Source: AlienVault -
http://45.87.154.208/work_53m8.ps1indicatesstix 100/100 Revoked· Valid until 02/09/2024 · Source: AlienVault -
stix 100/100 Revoked· Valid until 14/08/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 20/10/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 20/10/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 20/10/2025 · Source: AlienVault
-
stix 100/100 Revoked
SHA256 of c9a705395fab442261c174021caa9348ebff6b19
· Valid until 20/10/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 02/09/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 20/10/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 20/10/2025 · Source: AlienVault
-
stix 100/100 Revoked
Win.Trojan.ChaChi-9910803-0
· Valid until 14/08/2024 · Source: AlienVault
Vulnerabilities (CVE) (3)
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 03/11/2021
- Modified
- 20/12/2025