timb-machine / timb-machine/linux-malware
[Intel]: https://blog.aquasec.com/threat-alert-anatomy-of-silentbobs-cloud-attack
@timb-machine is already working on this.
Since Jul 10, 2023.
- Dominant language
- HTML
- Stars
- 1.2k
- Forks
- 95
- PR merge metrics
- No merged PRs in 30d
Description
Area
Malware reports
Parent threat
Reconnaissance, Initial Access, Execution, Persistence, Defense Evasion, Credential Access, Discovery, Command and Control, Impact
Finding
https://blog.aquasec.com/threat-alert-anatomy-of-silentbobs-cloud-attack
Industry reference
attack:T1525:Implant Internal Image
attack:T1595:Active Scanning
attack:T1496:Resource Hijacking
attack:T1613:Container and Resource Discovery
attack:T1190:Exploit Public-Facing Application
attack:T1059:Command and Scripting Interpreter
attack:T1610:Deploy Container
attack:T1222:File and Directory Permissions Modification
attack:T1036:Masquerading
attack:T1132:Data Encoding
attack:T1552.005:Cloud Instance Metadata API
attack:T1082:System Information Discovery
attack:T1071.001:Web Protocols
attack:T1090.003:Multi-hop Proxy
Malware reference
Tsunami
Actor reference
TeamTNT
Component
Linux
Scenario
No response
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Assessment
This issue has not been assessed yet.