RotBot
AlienVault
· Published 20/12/2025 19:43 · Modified 21/12/2025 04:00
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:43
- Modified
- 21/12/2025 04:00
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 19 attack patterns (mitre), 1 intrusion sets (apt), 6 countries, 23 indicators
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (19)
-
T1592 usesGather Victim Host Information MITRE
-
T1584 usesCompromise Infrastructure MITRE
-
T1489 usesService Stop MITRE
-
T1185 usesBrowser Session Hijacking MITRE
-
T1569 usesSystem Services MITRE
-
T1071 usesApplication Layer Protocol MITRE
-
T1059 usesCommand and Scripting Interpreter MITRE
-
T1210 usesExploitation of Remote Services MITRE
-
T1008 usesFallback Channels MITRE
-
T1552 usesUnsecured Credentials MITRE
-
T1114 usesEmail Collection MITRE
-
T1588 usesObtain Capabilities MITRE
Intrusion sets (APT) (1)
-
CoralRaider usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 ·
Countries (6)
-
India targets
-
Indonesia targets
-
Pakistan targets
-
China targets
-
Bangladesh targets
-
British Indian Ocean Territory targets
Indicators (23)
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked
SHA256 of 60d5648d35bacf5c7aa713b2a0d267d3
· Valid until 20/01/2026 · Source: AlienVault -
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked
compromised_site_redirector_fromcharcode
· Valid until 08/07/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault