Movatterモバイル変換


[0]ホーム

URL:


  1. Home
  2. Software
  3. QuietSieve

QuietSieve

QuietSieve is an information stealer that has been used byGamaredon Group since at least 2021.[1]

ID: S0686
Type: MALWARE
Platforms: Windows
Version: 1.0
Created: 18 February 2022
Last Modified: 16 April 2025
Enterprise Layer
downloadview

Techniques Used

DomainIDNameUse
EnterpriseT1071.001Application Layer Protocol:Web Protocols

QuietSieve can use HTTPS in C2 communications.[1]

EnterpriseT1005Data from Local System

QuietSieve can collect files from a compromised host.[1]

EnterpriseT1083File and Directory Discovery

QuietSieve can search files on the target host by extension, including doc, docx, xls, rtf, odt, txt, jpg, pdf, rar, zip, and 7z.[1]

EnterpriseT1564.003Hide Artifacts:Hidden Window

QuietSieve has the ability to execute payloads in a hidden window.[1]

EnterpriseT1105Ingress Tool Transfer

QuietSieve can download and execute payloads on a target host.[1]

EnterpriseT1135Network Share Discovery

QuietSieve can identify and search networked drives for specific file name extensions.[1]

EnterpriseT1120Peripheral Device Discovery

QuietSieve can identify and search removable drives for specific file name extensions.[1]

EnterpriseT1113Screen Capture

QuietSieve has taken screenshots every five minutes and saved them to the user's local Application Data folder underTemp\SymbolSourceSymbols\icons orTemp\ModeAuto\icons.[1]

EnterpriseT1016.001System Network Configuration Discovery:Internet Connection Discovery

QuietSieve can check C2 connectivity with aping to 8.8.8.8 (Google public DNS).[1]

Groups That Use This Software

IDNameReferences
G0047Gamaredon Group

[1]

References

×

[8]ページ先頭

©2009-2026 Movatter.jp