Tomb
AlienVault
· Published 15/06/2026 20:15 · Modified 15/06/2026 20:15
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 15/06/2026 20:15
- Modified
- 15/06/2026 20:15
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 22 attack patterns (mitre), 18 sectors, 1 countries, 100 indicators, 2 vulnerabilities (cve), 1 reports
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (22)
-
T1059.003 usesWindows Command Shell MITRE
-
T1204 usesUser Execution MITRE
-
T1482 usesDomain Trust Discovery MITRE
-
T1055 usesProcess Injection MITRE
-
T1140 usesDeobfuscate/Decode Files or Information MITRE
-
T1059.001 usesPowerShell MITRE
-
T1190 usesExploit Public-Facing Application MITRE
-
T1486 usesData Encrypted for Impact MITRE
-
T1027.002 usesSoftware Packing MITRE
-
T1018 usesRemote System Discovery MITRE
-
T1053.005 usesScheduled Task MITRE
-
T1203 usesExploitation for Client Execution MITRE
Sectors (18)
-
Energy targets
-
Technology targets
-
NGO targets
-
Retail targets
-
Aerospace targets
-
Healthcare targets
-
Media targets
-
Manufacturing targets
-
Construction targets
-
Transportation targets
-
Defense targets
-
Education targets
Countries (1)
-
United States of America targets
Indicators (100)
-
stix 100/100· Valid until 09/06/2027 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 12/04/2026 · Source: AlienVault
-
stix 100/100· Valid until 09/06/2027 · Source: AlienVault
-
stix 100/100· Valid until 09/06/2027 · Source: AlienVault
-
stix 100/100· Valid until 09/06/2027 · Source: AlienVault
-
stix 100/100· Valid until 09/06/2027 · Source: AlienVault
-
stix 100/100· Valid until 19/02/2027 · Source: AlienVault
-
stix 100/100· Valid until 09/06/2027 · Source: AlienVault
Vulnerabilities (CVE) (2)
7.8
High
Microsoft Windows Cloud Files Mini Filter Driver contains a privilege escalation vulnerability that could allow an attacker to gain SYSTEM privileges.
- Attack vector
- Local
- Published
- 14/11/2023
- Modified
- 15/06/2026
10.0
Critical
A vulnerability in the web-based management interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to …
- Attack vector
- NETWORK
- Complexity
- Low
- Published
- 04/03/2026
- Modified
- 14/04/2026
Reports (1)
-
2 CVEs 22 MITREs 24 Malwares 102 Observables 1 APT