Vexday analysis
TA578 é um agente de ameaça que utiliza formulários de contato e e-mail para iniciar comunicações com vítimas e distribuir malware, incluindo Latrodectus, IcedID e Bumblebee. O grupo é rastreado pelo MITRE ATT&CK sob o identificador G1038, com 4 técnicas documentadas em sua matriz.
Techniques (MITRE ATT&CK) 4
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Known infrastructure 45
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
gitenter.digitalLatrodectusthreatfoxmaialimentosreales.comLatrodectusthreatfoxngb.roLatrodectusthreatfoxnwachambersfamily.comLatrodectusthreatfoxpcl.hamburgLatrodectusthreatfoxquaideazamcollege.comLatrodectusthreatfoxpetx.vetLatrodectusthreatfoxplumbinggurus.comLatrodectusthreatfoxracingoperations.com.auLatrodectusthreatfoxracquetclubofgastonia.comLatrodectusthreatfoxsealaunchservices.comLatrodectusthreatfoxsarahcole.com.auLatrodectusthreatfoxstudio-minx.comLatrodectusthreatfoxsoftsystems.proLatrodectusthreatfoxsurf7seas.comLatrodectusthreatfoxtanahabangmini.netLatrodectusthreatfoxthebookoninvesting.comLatrodectusthreatfoxtscd.vnLatrodectusthreatfoxvin2.roLatrodectusthreatfoxwaltonsoftware.comLatrodectusthreatfoxzeribsglobal.comLatrodectusthreatfoxfocusspo.comLatrodectusthreatfoxmarebnb.comLatrodectusthreatfoxpyebrook.comLatrodectusthreatfoxsamarkegypt.comLatrodectusthreatfoxcaramdistribuciones.com.arLatrodectusthreatfoxcmla.blogLatrodectusthreatfoxcursohenfil.com.brLatrodectusthreatfoxcydesys.comLatrodectusthreatfoxdokonalebydleni.czLatrodectusthreatfox+45 indicators in total. See them all on the IOCs page.
References
TA578 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →