Trinper
AlienVault
· Published 21/12/2025 08:39 · Modified 21/12/2025 08:39
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 21/12/2025 08:39
- Modified
- 21/12/2025 08:39
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 33 attack patterns (mitre), 2 intrusion sets (apt), 2 sectors, 1 countries, 18 indicators, 2 vulnerabilities (cve), 3 reports
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (33)
-
T1041 usesExfiltration Over C2 Channel
-
T1218.011 usesRundll32
-
T1588.002 usesTool
-
T1036.004 usesMasquerade Task or Service
-
T1113 usesScreen Capture
-
T1547.009 usesShortcut Modification
-
T1059.001 usesPowerShell
-
T1553.002 usesCode Signing
-
T1218 usesSystem Binary Proxy Execution
-
T1055.012 usesProcess Hollowing
-
T1055 usesProcess Injection
-
T1132.001 usesStandard Encoding
-
T1082 usesSystem Information Discovery
-
T1115 usesClipboard Data
-
T1140 usesDeobfuscate/Decode Files or Information
-
T1090.004 usesDomain Fronting
-
T1020 usesAutomated Exfiltration
-
T1568 usesDynamic Resolution
-
T1056.001 usesKeylogging
-
T1566 usesPhishing
-
T1573.001 usesSymmetric Cryptography
-
T1566.002 usesSpearphishing Link
-
T1070.004 usesFile Deletion
-
T1204.002 usesMalicious File
-
T1574.002 uses
-
T1057 usesProcess Discovery
-
T1012 usesQuery Registry
-
T1083 usesFile and Directory Discovery
-
T1071 usesApplication Layer Protocol
-
T1187 usesForced Authentication
-
T1573 usesEncrypted Channel
-
T1573.002 usesAsymmetric Cryptography
-
T1027 usesObfuscated Files or Information
Intrusion sets (APT) (2)
Sectors (2)
- Government targets
- Telecommunications targets
Countries (1)
- Russian Federation targets
Indicators (18)
-
2a0c6a66774cc535f51e1a12d81ba6aa346934aa542291cee0c57f3bc9373a8eindicates -
https://infosecteam.info/other.php?id=jdcz7vyqdoadr31gejeivo6g30cx7kguindicates -
7e82b3f1be69d34684a4aa4823ef0d5ae864db3501fae5a0c3697bcd28df5cefindicates -
dd3a609b7beb35fb2527e7ca1450ad40569b3ffbf67d84811fcf8ff09096d823indicates -
https://srv480138.hstgr.cloud/uploads/scan_3824.pdf'indicates -
infosecteam.infoindicates -
https://mil-by.info/#/i?id=[REDACTED]indicates -
srv480138.hstgr.cloudindicates -
00f433c593204eaa1facb18d1a0dec4caee06915bbc8a51ad6bf47bf9e865fe8indicates -
f699c309f0d2547a85f6623dc74cc452a1471cd77af2360116447244043ee0ddindicates -
https://srv510786.hstgr.cloud/ordinary.php?id=9826fbb409f65dc6b068b085551bf4f3indicates -
https://srv480138.hstgr.cloud/report.php?query=$env:COMPUTERNAME'indicates -
server.1cscan.netindicates -
6d4fac9e4c36face9e0d0a7fdec1cc1403b3188ecf5c24f1ac6c32981f9c72b2indicates -
mil-by.infoindicates -
srv510786.hstgr.cloudindicates -
93b07ba651fb6dbebaaadb39cf45ddfea7af9d3943458a5630aa588080dcf335indicates -
e93c1a0696b59a58e2444eb69ddf165eed71ad159624674a7fe6c91e9852443aindicates
Vulnerabilities (CVE) (2)
7.8
High
Yandex Browser for Desktop before 24.7.1.380 has a DLL Hijacking Vulnerability because an untrusted search path is used.
- Attack vector
- LOCAL
- Published
- 03/09/2024
- Modified
- 21/12/2025
CVE-2025-2783
KEV
8.3
High
Google Chromium Mojo on Windows contains a sandbox escape vulnerability caused by a logic error, which results from an incorrect handle being …
- Attack vector
- Network
- Published
- 27/03/2025
- Modified
- 21/12/2025
Reports (3)
-
2 CVEs 14 MITREs 3 Malwares 9 Observables 1 APTPublished 29/10/2025 10:49 · Modified 29/10/2025 18:23
-
12 MITREs 3 Malwares 1 APTPublished 18/04/2025 21:45 · Modified 21/04/2025 12:45
-
14 MITREs 1 Malware 11 Observables 1 APTPublished 03/12/2024 16:26 · Modified 03/12/2024 16:50