Summary: 2025/04/17 10:43

First reported date: 2010/05/28
Inquiry period : 2025/04/16 10:43 ~ 2025/04/17 10:43 (1 days), 3 search results

지난 7일 기간대비 100% 높은 트렌드를 보이고 있습니다.
지난 7일 기간대비 상승한 Top5 연관 키워드는
keylogger Windows Malware target Update 입니다.
악성코드 유형 TONESHELL Trojan GameoverP2P PlugX 도 새롭게 확인됩니다.
공격기술 Backdoor hijack 도 새롭게 확인됩니다.
기관 및 기업 Zscaler Microsoft Kaspersky Europe 도 새롭게 확인됩니다.
기타 EDR MUSTANG PANDA Cobalt Strike Victim GitHub 등 신규 키워드도 확인됩니다.

 * 최근 뉴스기사 Top3:
    ㆍ 2025/04/17 Latest Mustang Panda Arsenal: PAKLOG, CorKLOG, and SplatCloak | P2
    ㆍ 2025/04/17 Latest Mustang Panda Arsenal: ToneShell and StarProxy | P1

Trend graph by period


Related keyword cloud
Top 100

# Trend Count Comparison
1keylogger 3 ▲ 3 (100%)
2Zscaler 3 ▲ new
3EDR 3 ▲ new
4MUSTANG PANDA 3 ▲ new
5Cobalt Strike 3 ▲ new
6Victim 2 ▲ new
7GitHub 2 ▲ new
8Windows 2 ▲ 2 (100%)
9TONESHELL 2 ▲ new
10Backdoor 2 ▲ new
11hijack 2 ▲ new
12Malware 2 ▲ 2 (100%)
13c&c 2 ▲ new
14IoC 2 ▲ new
15Advertising 2 ▲ new
16Trojan 2 ▲ new
17target 2 ▲ 2 (100%)
18Operation 2 ▲ new
19Update 2 ▲ 2 (100%)
20Microsoft 1 ▲ new
21schtasks 1 ▲ new
22GameoverP2P 1 ▲ new
23PlugX 1 ▲ new
24server 1 ▲ new
25Exploit 1 ▲ 1 (100%)
26attack 1 ▲ 1 (100%)
27Dropper 1 ▲ 1 (100%)
28SplatCloak 1 ▲ new
29driver 1 ▲ new
30Kaspersky 1 ▲ new
31Government 1 ▲ 1 (100%)
32StarProxy 1 ▲ new
33file 1 ▲ new
34C2 1 ▲ new
35Europe 1 ▲ new
36ThreatLabz 1 ▲ new
37UNIX 1 ▲ new
38China 1 ▲ 1 (100%)
39Campaign 1 ▲ 1 (100%)
40Panda 1 ▲ new
41Mustang 1 ▲ new
42exploration 1 ▲ new
43Mustan 1 ▲ new
Special keyword group
Top 5

Malware Type
Malware Type

This is the type of malware that is becoming an issue.


Keyword Average Label
TONESHELL
2 (33.3%)
Trojan
2 (33.3%)
GameoverP2P
1 (16.7%)
PlugX
1 (16.7%)
Attacker & Actors
Attacker & Actors

The status of the attacker or attack group being issued.


Keyword Average Label
Attack technique
Technique

This is an attack technique that is becoming an issue.


Keyword Average Label
Backdoor
2 (28.6%)
hijack
2 (28.6%)
Exploit
1 (14.3%)
Dropper
1 (14.3%)
Campaign
1 (14.3%)
Country & Company
Country & Company

This is a country or company that is an issue.


Keyword Average Label
Zscaler
3 (37.5%)
Microsoft
1 (12.5%)
Kaspersky
1 (12.5%)
Government
1 (12.5%)
Europe
1 (12.5%)

Additional information

Level Description
watch Resumed a suspended thread in a remote process potentially indicative of process injection
notice Allocates read-write-execute memory (usually to unpack itself)
notice Changes read-write memory protection to read-execute (probably to avoid detection when setting all RWX flags at the same time)
notice Potentially malicious URLs were found in the process memory dump
notice Uses Windows utilities for basic Windows functionality
notice Yara rule detected in process memory
Network SSLBL: Malicious JA3 SSL-Client Fingerprint detected (Tofsee)
No data
No URL CC ASN Co Reporter Date
1https://tinyfilemanagerdemo.alwaysdata.net/user/files/b.exe
alwaysdata exe keylogger
FR FRAlwaysdata Sarluser12222025.02.23
2http://141.147.43.219:3000/ftp/EmmetPROD.exe
exe keylogger lazy
SE SERiordz2025.01.31
3http://107.172.148.212/260/cvss.exe
exe keylogger snake
US USAS-COLOCROSSINGRiordz2025.01.30
4http://caca.vercel.app/file.exe
keylogger
US USabus3reports2024.12.06
5https://raw.githubusercontent.com/cheetz/nishang/master/Gather/Keylogger.ps1
keylogger
US USFASTLYabus3reports2024.12.06
View only the last 5
Beta Service, If you select keyword, you can check detailed information.