Zardoor
AlienVault
· Published 20/12/2025 19:42 · Modified 21/12/2025 02:43
Essential information
- Confidence
- 100/100
- Is family
- No
- Published
- 20/12/2025 19:42
- Modified
- 21/12/2025 02:43
- Revoked
- No
- Author / Source
- AlienVault
- Related entities
- 22 attack patterns (mitre), 1 sectors, 1 countries, 25 indicators, 2 vulnerabilities (cve)
Description
No description.
Marking (TLP)
TLP:CLEAR
Related entities
Attack patterns, malware, vulnerabilities, indicators, intrusion sets and other entities linked to this malware.
Attack patterns (MITRE) (22)
-
T1059.003 usesWindows Command Shell MITRE
-
T1053.005 usesScheduled Task MITRE
-
T1090.003 usesMulti-hop Proxy MITRE
-
T1087.002 usesDomain Account MITRE
-
T1071 usesApplication Layer Protocol MITRE
-
T1055.001 usesDynamic-link Library Injection MITRE
-
T1568 usesDynamic Resolution MITRE
-
T1048 usesExfiltration Over Alternative Protocol MITRE
-
T1018 usesRemote System Discovery MITRE
-
T1057 usesProcess Discovery MITRE
-
T1574.002 uses
-
T1105 usesIngress Tool Transfer MITRE
Sectors (1)
-
Non-Governmental Organizations (NGOs) targets
Countries (1)
-
Saudi Arabia targets
Indicators (25)
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked
SHA256 of 60d5648d35bacf5c7aa713b2a0d267d3
· Valid until 20/01/2026 · Source: AlienVault -
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked
GoLandBuildPE SHA256 of e0f4afe374d75608d604fbf108eac64f
· Valid until 08/07/2025 · Source: AlienVault -
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
-
stix 100/100 Revoked· Valid until 08/07/2025 · Source: AlienVault
Vulnerabilities (CVE) (2)
8.8
High
Apple iOS, iPadOS, macOS, tvOS, and Safari WebKit contain a type confusion vulnerability that leads to code execution when processing maliciously crafted …
- Attack vector
- Network
- Complexity
- LOW
- Published
- 23/01/2024
- Modified
- 04/04/2026
8.2
High
Ivanti Connect Secure (ICS, formerly known as Pulse Connect Secure), Ivanti Policy Secure, and Ivanti Neurons contain a server-side request forgery (SSRF) …
- Attack vector
- Network
- Published
- 31/01/2024
- Modified
- 27/05/2026