THREAT OPS › Threat News › TerminalFix campaign deploys a reverse tunnel through multistage intrusion
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
<aside class="table-of-contents-block accordion wp-block-bloginabox-theme-table-of-contents" id="accordion-370d8b63-0266-4944-b0de-d35597edafcd"> <button class="btn btn-collapse" type="button"> <span class="table-of-contents-block__label">In this article</span> <span class="table-of-contents-block__current"></span>
<svg class="table-of-contents-block__arrow" fill="none" height="11" viewBox
MITRE ATT&CK techniques
- Scheduled TaskT1053.005
- JavaScriptT1059.007
- Permission Groups DiscoveryT1069
- Match Legitimate Resource Name or LocationT1036.005
- Boot or Logon Autostart ExecutionT1547
- Domain AccountT1087.002
- Hide ArtifactsT1564
- Malicious FileT1204.002
- Domain GroupsT1069.002
- DLLT1574.001
- Network TopologyT1590.004
- System Information DiscoveryT1082
- Application Layer ProtocolT1071
- Scheduled Task/JobT1053
- Social EngineeringT1684
- MasqueradingT1036
- Protocol TunnelingT1572
- Account DiscoveryT1087
- Command and Scripting InterpreterT1059
- Domain AccountT1136.002
- Domain Trust DiscoveryT1482
- PowerShellT1059.001
- Registry Run Keys / Startup FolderT1547.001
- Hijack Execution FlowT1574
- Obfuscated Files or InformationT1027
- Social MediaT1593.001
- CredentialsT1589.001
- SteganographyT1027.003
- Drive-by CompromiseT1189
- Web ProtocolsT1071.001
- Remote System DiscoveryT1018
- Ingress Tool TransferT1105
- Hidden Files and DirectoriesT1564.001
- SteganographyT1001.002
- Command and Scripting InterpreterAML.T0050
- MasqueradingAML.T0074
- Drive-by CompromiseAML.T0078
Indicators of compromise
- 18c2090e8a0ae0568af9b87e59eaf8270f23d2909600ed9db91a9444fd8b278fsha256
- b8d107800403b9197e5b7609ceacd8e4cac1b0f9a1d156e6dacd6c3f7794b36asha256
- ba77feed86bcda49308746421bdc684a432dd5d68c363975b2a3c6831bda3f07sha256
- 026478003fe354134c03acf6890e7d3b153ba08a836eca42350db48f213872absha256
- 032b529fac61e550f5dc9489686f519b82d64625fa05a8d9ecf8ba8be9b2ad22sha256
- df8221a933b38284ebdcb8bffc2df62123c9f5b5f421dd0b070e13e668b3eabfsha256
- eb1b4be34d05b394fb74efdeb95faecd1d1963be6ecc1b9db2b4757b491f01f0sha256
- 5d43abf5c36ea203176d3300ff14af27b4be81810ad2679b3a62b255e3d6e1c8sha256
- 9a7b4dcd51d9251c177d323d6aaecdfc86674f69bc1af048dc872926d22aaa24sha256
- 342df92235c9dec81203b837addaa38bb85b64b4a48fe71b5303ca86d991991esha256
- ededeacf30e493dd632d477fe770ba419aa2848f685ea049381a0a8d2cc3e84dsha256
- https://linked-log.com/url
- https://microsoft.github.io/zerotrustassessment/url
- python.orgdomain
- bestsocialmedianewspapper.comdomain
- offlineupdater.comdomain