Kaspersky recently released a detailed report on a group known for some time as "Naikon" ( https://securelist.com/analysis/publications/69953/the-naikon-apt/ ), and likely shares some correlations with the more recently described APT30 ( https://blog.kaspersky.com/naikon-apt-south-china-sea/ ).
You can browse some of the infrastructure within ThreatCrowd below:
https://www.threatcrowd.org/domain.php?domain=linda.googlenow.in
https://www.threatcrowd.org/domain.php?domain=admin0805.gnway.net
https://www.threatcrowd.org/domain.php?domain=free.googlenow.in
https://www.threatcrowd.org/domain.php?domain=frankhere.oicp.net
https://www.threatcrowd.org/domain.php?domain=frankhere.oicp.net
https://www.threatcrowd.org/domain.php?domain=telcom.dhtu.info
https://www.threatcrowd.org/domain.php?domain=laotel08.vicp.net
https://www.threatcrowd.org/domain.php?domain=greensky27.vicp.net
https://www.threatcrowd.org/domain.php?domain=googlemm.vicp.net
https://www.threatcrowd.org/domain.php?domain=googlemm.vicp.net
https://www.threatcrowd.org/domain.php?domain=peacesyou.imwork.net
https://www.threatcrowd.org/domain.php?domain=sayakyaw.xicp.net
https://www.threatcrowd.org/domain.php?domain=ubaoyouxiang.gicp.net
https://www.threatcrowd.org/domain.php?domain=htkg009.gicp.net
https://www.threatcrowd.org/domain.php?domain=kyawthumyin.xicp.net
https://www.threatcrowd.org/domain.php?domain=myanmartech.vicp.net
https://www.threatcrowd.org/domain.php?domain=test-user123.vicp.cc
https://www.threatcrowd.org/domain.php?domain=us.googlereader.pw
https://www.threatcrowd.org/domain.php?domain=net.googlereader.pw
https://www.threatcrowd.org/domain.php?domain=lovethai.vicp.net
https://www.threatcrowd.org/domain.php?domain=yahoo.goodns.in
https://www.threatcrowd.org/domain.php?domain=xl.findmy.pw
https://www.threatcrowd.org/domain.php?domain=xl.kevins.pw
https://www.threatcrowd.org/domain.php?domain=oraydns.googlesec.pw
https://www.threatcrowd.org/domain.php?domain=gov.yahoomail.pw
https://www.threatcrowd.org/domain.php?domain=pp.googledata.pw
https://www.threatcrowd.org/domain.php?domain=xl.findmy.pw
https://www.threatcrowd.org/domain.php?domain=mlfjcjssl.gicp.net
https://www.threatcrowd.org/domain.php?domain=o.wm.ggpw.pw
https://www.threatcrowd.org/domain.php?domain=oooppp.findmy.pw
https://www.threatcrowd.org/domain.php?domain=cipta.kevins.pw
https://www.threatcrowd.org/domain.php?domain=phi.yahoomail.pw
https://www.threatcrowd.org/domain.php?domain=xl.findmy.pw
https://www.threatcrowd.org/domain.php?domain=dd.googleoffice.in
https://www.threatcrowd.org/domain.php?domain=moziliafirefox.wicp.net
https://www.threatcrowd.org/domain.php?domain=bkav.imshop.in
https://www.threatcrowd.org/domain.php?domain=baomoi.coyo.eu
https://www.threatcrowd.org/domain.php?domain=macstore.vicp.cc
https://www.threatcrowd.org/domain.php?domain=downloadwindows.imwork.net
https://www.threatcrowd.org/domain.php?domain=vietkey.xicp.net
https://www.threatcrowd.org/domain.php?domain=baomoi.vicp.cc
https://www.threatcrowd.org/domain.php?domain=downloadwindow.imwork.net
https://www.threatcrowd.org/domain.php?domain=www.ttxvn.net
https://www.threatcrowd.org/domain.php?domain=vietlex.gnway.net
https://www.threatcrowd.org/domain.php?domain=www.ttxvn.net
https://www.threatcrowd.org/domain.php?domain=us.googlereader.pw
https://www.threatcrowd.org/domain.php?domain=yahoo.goodns.in
https://www.threatcrowd.org/domain.php?domain=lovethai.vicp.net
https://www.threatcrowd.org/domain.php?domain=vietlex.gnway.net
Tuesday, 19 May 2015
Example Threat: Cmstar
PaloAlto recently published an article (http://researchcenter.paloaltonetworks.com/2015/05/cmstar-downloader-lurid-and-enfals-new-cousin/ ) detailing a downloader they name "Cmstar" used to download the well known Enfal malware.
Below are links to browse some of this infrastructure within ThreatCrowd:
Below are links to browse some of this infrastructure within ThreatCrowd:
- https://www.threatcrowd.org/domain.php?domain=links.dogsforhelp.com
- https://www.threatcrowd.org/domain.php?domain=three.earewq.com
- https://www.threatcrowd.org/domain.php?domain=question.eboregi.com
- https://www.threatcrowd.org/domain.php?domain=here.pechooin.com
- https://www.threatcrowd.org/domain.php?domain=sarey.phdreport.com
- https://www.threatcrowd.org/domain.php?domain=bakler.featurvoice.com
- https://www.threatcrowd.org/domain.php?domain=forever.cowforhelp.com
- https://www.threatcrowd.org/domain.php?domain=question.shiesiido.com
- https://www.threatcrowd.org/domain.php?domain=help.ubxpi0s.com
- https://www.threatcrowd.org/domain.php?domain=endline.biortherm.com
- https://www.threatcrowd.org/domain.php?domain=baby.brabbq.com
- https://www.threatcrowd.org/domain.php?domain=lind.kruptcy.com
- https://www.threatcrowd.org/domain.php?domain=under.suttgte.com
- https://www.threatcrowd.org/domain.php?domain=help.ubxpi0s.com
- https://www.threatcrowd.org/domain.php?domain=finally.basiccompare.com
- https://www.threatcrowd.org/domain.php?domain=crystal.diskfunc.com
- https://www.threatcrowd.org/domain.php?domain=queenfansclub.com
- https://www.threatcrowd.org/domain.php?domain=novnitie.com
- https://www.threatcrowd.org/domain.php?domain=flash-vip.com
- https://www.threatcrowd.org/domain.php?domain=replyfunt.com
- https://www.threatcrowd.org/domain.php?domain=natcongress.com
- https://www.threatcrowd.org/domain.php?domain=keep.regebky.com
- https://www.threatcrowd.org/domain.php?domain=love.regebky.com
- https://www.threatcrowd.org/domain.php?domain=xphome.mailru-vip.com
- https://www.threatcrowd.org/domain.php?domain=error.yandex-pro.com
- https://www.threatcrowd.org/domain.php?domain=dns.thinkttun.com
- https://www.threatcrowd.org/domain.php?domain=help.redhag.com
- https://www.threatcrowd.org/domain.php?domain=mssage.hotoicq.com
- https://www.threatcrowd.org/domain.php?domain=new.hoticq.com
Subscribe to:
Posts (Atom)