Summary: 2025/04/17 12:37

First reported date: 2012/01/05
Inquiry period : 2025/04/16 12:36 ~ 2025/04/17 12:36 (1 days), 9 search results

지난 7일 기간대비 동일한 트렌드를 보이고 있습니다.
지난 7일 기간대비 상승한 Top5 연관 키워드는
Malware Update target Victim Exploit 입니다.
악성코드 유형 njRAT XWorm AsyncRAT 도 새롭게 확인됩니다.
공격자 MuddyWater APT28 도 새롭게 확인됩니다.
공격기술 MalSpam 도 새롭게 확인됩니다.
기관 및 기업 Iran Türkiye 도 새롭게 확인됩니다.
기타 Android own WhatsApp Krebs Trump 등 신규 키워드도 확인됩니다.

 * 최근 뉴스기사 Top3:
    ㆍ 2025/04/17 Former cyber official Chris Krebs to leave SentinelOne in bid to fight Trump pressure
    ㆍ 2025/04/17 Hi, robot: Half of all internet traffic now automated
    ㆍ 2025/04/17 Exploiting SMS: Threat Actors Use Social Engineering to Target Companies

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1Email 9 - 0 (0%)
2Malware 6 ▲ 2 (33%)
3Update 5 ▲ 3 (60%)
4target 5 ▲ 3 (60%)
5Victim 5 ▲ 3 (60%)
6Exploit 4 ▲ 2 (50%)
7Phishing 4 ▲ 1 (25%)
8Browser 4 ▲ 3 (75%)
9Kaspersky 3 ▲ 2 (67%)
10Report 3 - 0 (0%)
11NetWireRC 3 ▲ 3 (100%)
12Campaign 3 ▲ 1 (33%)
13Russia 3 ▲ 3 (100%)
14United States 3 - 0 (0%)
15RCE 3 ▲ 2 (67%)
16attack 3 ▲ 1 (33%)
17intelligence 3 ▲ 2 (67%)
18payment 2 ▲ 2 (100%)
19account 2 ▲ 2 (100%)
20RAT 2 ▲ 2 (100%)
21Advertising 2 - 0 (0%)
22njRAT 2 ▲ new
23Education 2 ▲ 1 (50%)
24Windows 2 ▲ 1 (50%)
25Government 2 ▲ 1 (50%)
26Password 2 ▲ 2 (100%)
27ZeroDay 2 ▲ 2 (100%)
28IoC 2 ▲ 1 (50%)
29Vulnerability 2 ▲ 1 (50%)
30threat 2 ▲ 1 (50%)
31LinkedIn 1 ▲ 1 (100%)
32MFA 1 - 0 (0%)
33Android 1 ▲ new
34Social Engineering 1 ▲ 1 (100%)
35Tick 1 ▲ 1 (100%)
36own 1 ▲ new
37CISA 1 ▲ 1 (100%)
38WhatsApp 1 ▲ new
39Krebs 1 ▲ new
40address 1 ▲ 1 (100%)
41Trump 1 ▲ new
42ltpgt 1 ▲ new
43access 1 ▲ new
44Smishing 1 ▲ 1 (100%)
45Software 1 - 0 (0%)
46hijack 1 ▲ 1 (100%)
47application 1 ▲ new
48Router 1 ▲ new
49traffic 1 ▲ new
50web 1 ▲ new
51bot 1 ▲ 1 (100%)
52human 1 ▲ new
53Firefox 1 ▲ new
54Chrome 1 ▲ 1 (100%)
55Google 1 - 0 (0%)
56Criminal 1 - 0 (0%)
57sense 1 ▲ new
58Figure 1 ▲ 1 (100%)
59legitimate 1 ▲ new
60RATel 1 ▲ 1 (100%)
61SentinelOne 1 ▲ 1 (100%)
62Cofense 1 ▲ 1 (100%)
63actor 1 ▲ 1 (100%)
64GitHub 1 ▲ 1 (100%)
65Trojan 1 ▲ 1 (100%)
66Lumma 1 ▲ 1 (100%)
67Linux 1 ▲ 1 (100%)
68Stealer 1 ▲ 1 (100%)
69Vawtrak 1 ▲ 1 (100%)
70GameoverP2P 1 - 0 (0%)
71XWorm 1 ▲ new
72EDR 1 ▲ 1 (100%)
73Iran 1 ▲ new
74Portugal 1 ▲ new
75powershell 1 - 0 (0%)
76c&c 1 ▲ 1 (100%)
77MuddyWater 1 ▲ new
78Cobalt Strike 1 ▲ new
79AsyncRAT 1 ▲ new
80Russian 1 ▲ new
81case 1 ▲ new
82Backdoor 1 ▲ 1 (100%)
83store 1 ▲ new
84Cryptocurrency 1 ▲ 1 (100%)
85Check Point 1 ▲ 1 (100%)
86scam 1 ▲ 1 (100%)
87sextortion 1 ▲ new
88Operation 1 - 0 (0%)
89Europe 1 ▲ 1 (100%)
90MalSpam 1 ▲ new
91sherrodim 1 ▲ new
92Türkiye 1 ▲ new
93SQL 1 ▲ new
94Australia 1 ▲ 1 (100%)
95Microsoft 1 - 0 (0%)
96SMB 1 ▲ 1 (100%)
97Ucraina 1 ▲ 1 (100%)
98APT28 1 ▲ new
99Alleged 1 - 0 (0%)
100format 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
NetWireRC
3 (21.4%)
RAT
2 (14.3%)
njRAT
2 (14.3%)
RATel
1 (7.1%)
Trojan
1 (7.1%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


Keyword Average Label
Tick
1 (33.3%)
MuddyWater
1 (33.3%)
APT28
1 (33.3%)
Attack technique
Technique

This is an attack technique that is becoming an issue.


Keyword Average Label
Exploit
4 (20%)
Phishing
4 (20%)
Campaign
3 (15%)
RCE
3 (15%)
Social Engineering
1 (5%)
Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
Kaspersky
3 (14.3%)
Russia
3 (14.3%)
United States
3 (14.3%)
Government
2 (9.5%)
CISA
1 (4.8%)
Threat info
Last 5

Additional information

Level Description
danger File has been identified by 59 AntiVirus engines on VirusTotal as malicious
danger Connects to an IP address that is no longer responding to requests (legitimate services will remain up-and-running usually)
danger Executed a process and injected code into it
watch Allocates execute permission to another process indicative of possible code injection
watch Attempts to remove evidence of file being downloaded from the Internet
watch Communicates with host for which no DNS query was performed
watch Potential code injection by writing to the memory of another process
watch Resumed a suspended thread in a remote process potentially indicative of process injection
watch Used NtSetContextThread to modify a thread in a remote process indicative of process injection
notice Allocates read-write-execute memory (usually to unpack itself)
notice One or more potentially interesting buffers were extracted
notice Potentially malicious URLs were found in the process memory dump
notice The binary likely contains encrypted or compressed data indicative of a packer
notice Yara rule detected in process memory
info Checks amount of memory in system
info Checks if process is being debugged by a debugger
info This executable has a PDB path
No data
No data
Beta Service, If you select keyword, you can check detailed information.