Trusted Design

Romanian Shellshock Backdoor

概要

This backdoor was discovered while digging through apache logs for shellshock exploitation attempts and inspecting the malicious payloads associated with them. This attack initially exploits CVE-2014-6271 (shellshock) to download a tar file on the system after which the contents of the tar file are extracted to the file system in the /tmp directory. After extracting the files to the file system xcron.sh is run, which looks for /lib/libpcprofile.so on the system and attempts to further exploit CVE-2013-2094 in order to elevate privileges to root. Upon successful exploitation of CVE-2013-2094 the software will install a root account on the system in addition to SSH keys which allows the attacker to remotely log in to the system as root. The attack originated out of an IP in Germany, however strings contained within the backdoor scripts suggest the software is of Romanian origin.

Created: 2026-02-23

Indicators

Indicatorsは見つかっていない。

類似Pulses

このPulseに関連する脅威アクター (事実ベース)

Gamaredon Group

Score: 6.77
Matched TTPs:
  • T1021.005 - VNC
  • T1546.017 - Udev Rules
MITREへのリンク →

FIN7

Score: 10.68
Matched TTPs:
  • T1021.005 - VNC
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
  • T1490 - Inhibit System Recovery
MITREへのリンク →

GCMAN

Score: 3.62
Matched TTPs:
  • T1021.005 - VNC
MITREへのリンク →

Fox Kitten

Score: 12.12
Matched TTPs:
  • T1021.005 - VNC
  • T1555.003 - Credentials from Web Browsers
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT41

Score: 11.60
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1686.002 - Network Device Firewall
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Scattered Spider

Score: 14.24
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1686.002 - Network Device Firewall
  • T1557.002 - ARP Cache Poisoning
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

TA505

Score: 3.29
Matched TTPs:
  • T1560.003 - Archive via Custom Method
MITREへのリンク →

Volt Typhoon

Score: 16.00
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1555.003 - Credentials from Web Browsers
  • T1686.002 - Network Device Firewall
  • T1584.002 - DNS Server
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT3

Score: 10.05
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1218.010 - Regsvr32
  • T1578.002 - Create Cloud Instance
  • T1622 - Debugger Evasion
MITREへのリンク →

FIN13

Score: 9.04
Matched TTPs:
  • T1560.003 - Archive via Custom Method
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

CURIUM

Score: 5.61
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1205.001 - Port Knocking
MITREへのリンク →

Dragonfly

Score: 13.62
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1578.002 - Create Cloud Instance
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT28

Score: 16.32
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1205.001 - Port Knocking
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1548.006 - TCC Manipulation
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

OilRig

Score: 4.91
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

Agrius

Score: 3.41
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
MITREへのリンク →

APT39

Score: 3.41
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
MITREへのリンク →

Mustang Panda

Score: 5.60
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.010 - Regsvr32
  • T1548.006 - TCC Manipulation
MITREへのリンク →

GALLIUM

Score: 5.05
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1174 - Password Filter DLL
MITREへのリンク →

Threat Group-3390

Score: 9.16
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1546.017 - Udev Rules
MITREへのリンク →

Tropic Trooper

Score: 5.92
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.010 - Regsvr32
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Ember Bear

Score: 10.14
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
  • T1003.003 - NTDS
MITREへのリンク →

HAFNIUM

Score: 6.77
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1548.006 - TCC Manipulation
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Sandworm Team

Score: 5.60
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.010 - Regsvr32
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Tonto Team

Score: 6.01
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
MITREへのリンク →

APT38

Score: 13.21
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1174 - Password Filter DLL
  • T1059.005 - Visual Basic
  • T1216 - System Script Proxy Execution
MITREへのリンク →

APT29

Score: 5.92
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.010 - Regsvr32
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Magic Hound

Score: 7.03
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1578.002 - Create Cloud Instance
  • T1622 - Debugger Evasion
MITREへのリンク →

BlackByte

Score: 3.41
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
MITREへのリンク →

APT5

Score: 3.41
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
MITREへのリンク →

APT32

Score: 9.21
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1174 - Password Filter DLL
  • T1218.010 - Regsvr32
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Medusa Group

Score: 13.91
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1216 - System Script Proxy Execution
  • T1094 - Custom Command and Control Protocol
MITREへのリンク →

Leviathan

Score: 8.06
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1546.017 - Udev Rules
MITREへのリンク →

Sea Turtle

Score: 8.76
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1686.002 - Network Device Firewall
  • T1218.010 - Regsvr32
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Kimsuky

Score: 10.21
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
  • T1003.003 - NTDS
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Storm-1811

Score: 7.47
Matched TTPs:
  • T1205.001 - Port Knocking
  • T1578.002 - Create Cloud Instance
MITREへのリンク →

Wizard Spider

Score: 6.73
Matched TTPs:
  • T1059.001 - PowerShell
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

menuPass

Score: 10.02
Matched TTPs:
  • T1059.001 - PowerShell
  • T1174 - Password Filter DLL
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

MuddyWater

Score: 4.24
Matched TTPs:
  • T1059.001 - PowerShell
  • T1218.010 - Regsvr32
MITREへのリンク →

Aquatic Panda

Score: 4.48
Matched TTPs:
  • T1686.002 - Network Device Firewall
  • T1622 - Debugger Evasion
MITREへのリンク →

Velvet Ant

Score: 9.63
Matched TTPs:
  • T1686.002 - Network Device Firewall
  • T1490 - Inhibit System Recovery
  • T1566.003 - Spearphishing via Service
MITREへのリンク →

UNC3886

Score: 4.33
Matched TTPs:
  • T1686.002 - Network Device Firewall
  • T1218.010 - Regsvr32
MITREへのリンク →

Lazarus Group

Score: 10.05
Matched TTPs:
  • T1174 - Password Filter DLL
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
  • T1216 - System Script Proxy Execution
MITREへのリンク →

Daggerfly

Score: 3.29
Matched TTPs:
  • T1174 - Password Filter DLL
MITREへのリンク →

Patchwork

Score: 3.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

Axiom

Score: 3.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

Higaisa

Score: 4.65
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1546.017 - Udev Rules
MITREへのリンク →

Cobalt Group

Score: 3.14
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1622 - Debugger Evasion
MITREへのリンク →

APT37

Score: 5.12
Matched TTPs:
  • T1218.010 - Regsvr32
  • T1216 - System Script Proxy Execution
MITREへのリンク →

SideCopy

Score: 4.13
Matched TTPs:
  • T1584.002 - DNS Server
MITREへのリンク →

LAPSUS$

Score: 6.47
Matched TTPs:
  • T1557.002 - ARP Cache Poisoning
  • T1548.006 - TCC Manipulation
MITREへのリンク →

FIN6

Score: 3.99
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

FIN10

Score: 4.31
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1490 - Inhibit System Recovery
MITREへのリンク →

Chimera

Score: 3.99
Matched TTPs:
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Molerats

Score: 3.15
Matched TTPs:
  • T1546.017 - Udev Rules
MITREへのリンク →

TA2541

Score: 3.15
Matched TTPs:
  • T1546.017 - Udev Rules
MITREへのリンク →

Mofang

Score: 3.15
Matched TTPs:
  • T1546.017 - Udev Rules
MITREへのリンク →

このPulseに関連する脅威アクター (推論ベース)

APT28

Score: 0.81
Matched TTPs:
  • T1205.001 - Port Knocking
  • T1555.003 - Credentials from Web Browsers
  • T1059.001 - PowerShell
  • T1566.003 - Spearphishing via Service
  • T1548.006 - TCC Manipulation
  • T1218.010 - Regsvr32
MITREへのリンク →

Volt Typhoon

Score: 0.77
Matched TTPs:
  • T1686.002 - Network Device Firewall
  • T1555.003 - Credentials from Web Browsers
  • T1560.003 - Archive via Custom Method
  • T1622 - Debugger Evasion
  • T1584.002 - DNS Server
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Medusa Group

Score: 0.69
Matched TTPs:
  • T1094 - Custom Command and Control Protocol
  • T1555.003 - Credentials from Web Browsers
  • T1622 - Debugger Evasion
  • T1216 - System Script Proxy Execution
  • T1548.006 - TCC Manipulation
MITREへのリンク →

Scattered Spider

Score: 0.68
Matched TTPs:
  • T1686.002 - Network Device Firewall
  • T1560.003 - Archive via Custom Method
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1557.002 - ARP Cache Poisoning
MITREへのリンク →

Dragonfly

Score: 0.67
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1578.002 - Create Cloud Instance
  • T1622 - Debugger Evasion
  • T1059.001 - PowerShell
  • T1548.006 - TCC Manipulation
  • T1218.010 - Regsvr32
MITREへのリンク →

APT38

Score: 0.66
Matched TTPs:
  • T1174 - Password Filter DLL
  • T1216 - System Script Proxy Execution
  • T1059.005 - Visual Basic
  • T1555.003 - Credentials from Web Browsers
MITREへのリンク →

Fox Kitten

Score: 0.62
Matched TTPs:
  • T1555.003 - Credentials from Web Browsers
  • T1059.001 - PowerShell
  • T1021.005 - VNC
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
MITREへのリンク →

APT41

Score: 0.60
Matched TTPs:
  • T1686.002 - Network Device Firewall
  • T1560.003 - Archive via Custom Method
  • T1622 - Debugger Evasion
  • T1548.006 - TCC Manipulation
  • T1218.010 - Regsvr32
MITREへのリンク →

FIN7

Score: 0.57
Matched TTPs:
  • T1021.005 - VNC
  • T1622 - Debugger Evasion
  • T1490 - Inhibit System Recovery
  • T1059.001 - PowerShell
MITREへのリンク →

Related CVEs

Pulse – 脅威アクター グラフ


← Pulse一覧に戻る