Mallory pivots from this family to the IOCs, detections, and named campaigns that touch your stack, and pages you when something new lands.
1 distinct threat actor attributed by public researchers. Open in Mallory to see the full evidence chain and overlapping campaigns.
28 distinct techniques documented for this family, organized by ATT&CK tactic.
レジストリ操作に失敗した場合は、下記PowerShellのコマンドレットを用いて追加を試みます。 「powershell.exe -NoP -NonI -W Hidden -C "Add-MpPreference -ExclusionPath ..."」
このデバイスインタフェースを利用する主な目的は、セキュリティ製品の無効化(0x22E010 IOCTL)と、自分自身のプロセスおよびネットワーク通信の隠蔽(0x22E008 IOCTL)です。
スキャン除外パスの登録... HKLM¥SOFTWARE¥Microsoft¥Windows Defender¥Exclusions¥Paths ... リアルタイム保護と振る舞い監視の無効化 ... HKLM¥SOFTWARE¥Policies¥Microsoft¥Windows Defender¥Real-Time Protection ... クラウド連携およびサンプル自動送信のブロック ... HKLM¥SOFTWARE¥Policies¥Microsoft¥Windows Defender¥Spynet
マルウェア内部にハードコードされている暗号化された10FXRAT関連ファイル...を、Incremental XORを用いて復号します。
本マルウェアはAPI Hashingテクニックを用いており、必要なWindows APIのアドレスを実行時にハッシュ値から動的解決します。
これを受け取ったドライバは、WindowsのカーネルAPIや、正規のネットワーク監視ドライバ(¥Driver¥nsiproxy、¥Device¥Tcpなど)をフックし、指定されたPIDのプロセス情報と通信記録をシステムから除外します。これにより、OSのプロセス一覧から自身の存在を消し去り、タスクマネージャーやEDR等の各種システム監視ツールから、プロセスおよびC2サーバとの不正な通信活動を隠蔽することが可能となります。
64 indicators attributed across vendor reports, sandbox runs, and researcher write-ups. Full values are available in Mallory.
IPs, domains, and DNS infrastructure linked to this family.
File hashes (MD5, SHA-1, SHA-256) from samples and reports.
Other indicator types observed in public reporting.
3 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A modular HTTP/S remote access tool delivered with PoisonX that establishes encrypted C2, sets up an internal SOCKS5 proxy, and supports file exfiltration, lateral movement, keylogging, and credential theft.
モジュール型RATで、システム情報収集、任意コマンド実行、SOCKS5トンネリング、プラグインの動的取得に対応する。追加機能としてキーロガー、クリップボード監視、暗号資産ウォレット窃取、Telegram情報窃取、hVNC、権限昇格などが想定される。
Match every observed IP, domain, and hash against your live telemetry.
Named campaigns wielding this family, with evidence pinned to each claim.
CVEs this family uses for access and lateral movement.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Every documented technique, ranked by evidence weight.
Reddit, Mastodon, and CTI community discussion around this family.