Stealerium
AlienVault
· Published 20/12/2025 19:38 · Modified 20/12/2025 23:34
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:38
- Modified
- 20/12/2025 23:34
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 32 attack patterns (mitre), 1 intrusion sets (apt), 4 sectors, 2 countries, 26 indicators, 1 vulnerabilities (cve), 2 reports
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (32)
-
T1552 usesUnsecured Credentials
-
T1056.001 usesKeylogging
-
T1218 usesSystem Binary Proxy Execution
-
T1555.003 usesCredentials from Web Browsers
-
T1106 usesNative API
-
T1574 usesHijack Execution Flow
-
T1056 usesInput Capture
-
T1555 usesCredentials from Password Stores
-
T1040 usesNetwork Sniffing
-
T1102.002 usesBidirectional Communication
-
T1134 usesAccess Token Manipulation
-
T1497 usesVirtualization/Sandbox Evasion
Intrusion sets (APT) (1)
-
TA2715 usesAlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 21/12/2025 15:59 · Modified 21/12/2025 15:59
Sectors (4)
- Government targets
- Finance targets
- Education targets
- Hospitality targets
Countries (2)
- United States of America targets
- Canada targets
Indicators (26)
-
d5b4c2c95d9610623e681301869b1643e4e2bf0adca42eac5d4d773b024fa442indicates -
31705d906058e7324027e65ce7f4f7a30bcf6c30571aa3f020e91678a22a835aindicates -
6b0cc6d044bb19076eb7aef5047d68bd90565eb8502aa01893b2ad0cc50f149dindicates -
e590552eea3ad225cfb6a33fd9a71f12f1861c8332a6f3a8e2050fffce93f45eindicates -
41700c8fe273e088932cc57d15ee86c281fd8d2e771f4e4bf77b0e2c387b8b23indicates -
48328ce3a4b2c2413acb87a4d1f8c3b7238db826f313a25173ad5ad34632d9d7indicates -
d4d36f5aae7fdb6b88b5aae888947d7e6e3bfaab67b584ee71bd316cedc80f00indicates -
b06f938b3823443406c499ff1995722b56e83d0c8b4d9ac646d4d29b4d59082dindicates -
https://phantomsoftwares.site/home/.indicates -
03b9d7296b01e8f3fb3d12c4d80fe8a1bb0ab2fd76f33c5ce11b40729b75fb23indicates -
658725fb5e75ebbcb03bc46d44f048a0f145367eff66c8a1a9dc84eef777a9ccindicates -
50927b350c108e730dc4098bbda4d9d8e7c7833f43ab9704f819e631b1d981e3indicates
Vulnerabilities (CVE) (1)
CVE-2015-2291
KEV
7.8
High
Intel ethernet diagnostics driver for Windows IQVW32.sys and IQVW64.sys contain an unspecified vulnerability that allows for a denial-of-service (DoS).
- Attack vector
- LOCAL
- Complexity
- LOW
- Published
- 09/08/2017
- Modified
- 22/04/2026
Reports (2)
-
14 MITREs 4 Malwares 8 Observables 1 APTPublished 04/09/2025 00:59 · Modified 04/09/2025 08:16
-
1 MalwarePublished 30/04/2025 17:22 · Modified 30/04/2025 21:54