LookBack
Essential information
- Confidence
- 100/100
- Is family
- Yes
- Published
- 01/03/2021 15:07
- Modified
- 27/03/2026 01:06
- Revoked
- No
- Author / Source
- The MITRE Corporation
- Related entities
- 22 attack patterns (mitre), 1 intrusion sets (apt), 3 sectors, 53 indicators, 5 vulnerabilities (cve)
Description
Marking (TLP)
TLP:CLEAR Copyright 2015-2025, The MITRE Corporation. MITRE ATT&CK and ATT&CK are registered trademarks of The MITRE Corporation.
External references
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (22)
-
T1112 usesModify Registry MITRE
-
T1007 usesSystem Service Discovery MITRE
-
T1573.001 usesSymmetric Cryptography MITRE
-
T1218 usesSystem Binary Proxy Execution MITRE
-
T1036.005 usesMatch Legitimate Resource Name or Location MITRE
-
T1489 usesService Stop MITRE
-
T1095 usesNon-Application Layer Protocol MITRE
-
T1057 usesProcess Discovery MITRE
-
T1059.005 usesVisual Basic MITRE
-
T1113 usesScreen Capture MITRE
-
T1027 usesObfuscated Files or Information MITRE
-
T1529 usesSystem Shutdown/Reboot MITRE
Intrusion sets (APT) (1)
-
Witchetty usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Sectors (3)
-
Government targets
-
Manufacturing targets
-
Diplomacy targets
Indicators (53)
-
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
stix 100/100 Revoked
Backdoor:ASP/Ace.T SHA256 of e3af60f483774014c43a7617c44d05e7
· Valid until 20/05/2024 · Source: AlienVault -
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
http://185.225.19.55:8080/111'indicatesstix 100/100 Revoked· Valid until 16/11/2022 · Source: AlienVault -
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 03/01/2024 · Source: AlienVault
-
http://194.180.174.254/111'indicatesstix 100/100 Revoked· Valid until 16/11/2022 · Source: AlienVault
Vulnerabilities (CVE) (5)
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution.
- Published
- 03/11/2021
- Modified
- 29/05/2026
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for security feature bypass.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for privilege escalation.
- Published
- 03/11/2021
- Modified
- 20/12/2025
Microsoft Exchange Server contains an unspecified vulnerability that allows for remote code execution. This vulnerability is part of the ProxyLogon exploit chain.
- Published
- 03/11/2021
- Modified
- 20/12/2025