Advertisement
Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Appendix B: TG-3279 indicators
- The threat indicators in Table 3 are associated with TG-3279 activity. The domains and IP addresses listed in the indicators table may contain malicious content, so consider the risks before opening them in a browser.
- Indicator Type Context
- statics.mozillor.org Domain name Known C2 domain
- 192.69.198.6 IP address IP resolution for statics.mozillor.org, ad.7zbiz.com, and get.7zbiz.com
- First seen September 2013
- Last seen November 2013
- tactics.mozillor.org Domain name Known C2 domain
- update.mozillor.org Domain name Known C2 domain
- 110.45.158.78 IP address IP resolution for update.mozillor.org, *.mozillor.org, news.7zbiz.com, ad.7zbiz.com, and update.7zbiz.com
- First seen September 2013
- Last seen November 2013
- 108.166.215.94 IP address IP resolution for update.7zbiz.com and *.mozillor.org
- First and last seen February 2014
- 108.166.215.93 IP address IP resolution for news.7zbiz.com and ad.7zbiz.com
- First and last seen February 2014
- kr.Clientpg@yahoo.co.kr Email address Email address used to register mozillor.org and 7unzip.org
- login.7zbiz.com Domain name Known C2 domain
- news.7zbiz.com Domain name Related subdomain of known C2 domain
- update.7zbiz.com Domain name Related subdomain of known C2 domain
- get.7zbiz.com Domain name Related subdomain of known C2 domain; shares IP address with a second known C2 domain
- First seen 2013
- 108.166.215.89 IP address IP resolution for get.7zbiz.com
- First and last seen February 2014
- ad.7zbiz.com Domain name Related subdomain of known C2 domain
- downloads.7zbiz.com Domain name Related subdomain of known C2 domain
- 144.214.176.139 IP address Resolving IP address for downloads.7zbiz.com
- 7zbiz.com Domain name Second level of known C2 domain
- 184.168.221.57 IP address IP resolution for 7zbiz.com
- e59e@qq.com Email address Email address used to register 7zbiz.com
- First seen February 2, 2012
- Last seen December 1, 2013
- Wen Ben Zhou Name Presumed fake name used to register 7zbiz.com
- First seen February 2, 2012
- Last seen February 4, 2014
- www3.micorsofts.com Domain name Known C2 domain
- www6.micorsofts.com Domain name Known C2 domain
- www7.micorsofts.com Domain name Known C2 domain
- 82.100.37.191 IP address IP resolution for www7.micorsofts.com, used for IP calculation (IP address is not known to be malicious)
- Last seen January 1, 2014
- 230.165.22.199 IP address Observed IP resolution for www7.micorsofts.com and www8.micorsofts.com, used for IP calculation (IP address is not known to be malicious)
- First seen January 4, 2014
- 110.45.158.79 IP address Observed IP resolution for update.micorsofts.com, www.update.micorsofts.com, www3.micorsofts.com, and www2.micorsofts.com; IP address of www7.micorsofts.com and www8.micorsofts.com after IP calculation
- www2.micorsofts.com Domain name Related subdomain of known C2 domain
- test1.micorsofts.com Domain name Related subdomain of known C2 domain
- support.micorsofts.com Domain name Related subdomain of known C2 domain
- www.update.micorsofts.com Domain name CNAME for wwwN.micorsofts.com, where N is replaced with the numbers 3, 6, or 7.
- 218.236.173.55 IP address Observed IP resolution for www.update.micorsofts.com
- 173.193.227.143 IP address Observed IP resolution for www.update.micorsofts.com
- Last seen November 2013
- dyhan@outlook.com Email address Email address in registration data for micorsofts.com
- First seen June 21, 2013
- wvwugff@21cn.com Email address Original email address used to register micorsofts.com
- Last seen June 21, 2013
- 7unzip.org Domain name Domain registered with the same email address as mozillor.org
- First seen December 3, 2011
- login.7unzip.org Domain name Related sub domain of known C2 domain
- 108.166.215.94 IP address IP resolution for login.7unzip.org
- First seen January 3, 2014
- www.sincoder.com Domain name Domain name that uses the Sincoder persona's handle and points to IP addresses used to host the C2 server
- First seen May 27, 2011
- 60.173.12.20 IP address IP resolution for test1.micorsofts.com, possibly not malicious
- 60.173.12.16 IP address IP resolution for test1.micorsofts.com,possibly not malicious
- 1.25.36.108 IP address IP resolution for test1.micorsofts.com, possibly not malicious
- 60.5.240.93 IP address IP resolution for test1.micorsofts.com, possibly not malicious
- 122.143.24.131 IP address IP resolution for test1.micorsofts.com, possibly not malicious
- 125.78.248.31 IP address IP resolution for test1.micorsofts.com, possibly not malicious
- 218.26.233.114 IP address IP resolution for test1.micorsofts.com, possibly not malicious
- 119.97.168.173 IP address IP resolution for test1.micorsofts.com, possibly not malicious
- 119.97.168.174 IP address IP resolution for test1.micorsofts.com, possibly not malicious
- Table 3. Threat indicators for TG-3279.
- Appendix C: TG-2633 indicators
- The threat indicators in Table 4 are associated with TG-2633 activity. The domains and IP addresses listed in the indicators table may contain malicious content, so consider the risks before opening them in a browser.
- Indicator Type Context
- dl0.7zbiz.org Domain name TG-2633-related domain
- update.7zbiz.org Domain name TG-2633-related domain
- login.7zbiz.org Domain name TG-2633-related domain
- 7zbiz.org Domain name TG-2633-related domain
- sexndomain@gmail.com Email address Email address used to register 7zbiz.org
- 112.175.41.73 IP address IP resolution for club.cjinternet.us, coderprojcet.com, as.cjinternet.us, ru.cjinternet.us, db.jcrsoft.com, nx.cjinternet.us, cc.nexoncorp.us, dl0.7zbiz.org, and update.7zbiz.org
- club.cjinternet.us Domain name TG-2633-related domain
- as.cjinternet.us Domain name TG-2633-related domain
- ru.cjinternet.us Domain name TG-2633-related domain
- nx.cjinternet.us Domain name TG-2633-related domain
- evilsex@gmail.com Email address Email address used to register cjinternet.us and nexoncorp.us
- cc.nexoncorp.us Domain name TG-2633-related domain
- First seen April 12, 2012
- coderprojcet.com Domain name TG-2633-related domain
- First seen August 22, 2012
- db.jcrsoft.com Domain name TG-2633-related domain
- First seen July 14, 2013
- Last seen July 24, 2013
- www.jjjtv.com Domain name TG-2633-related domain
- First seen June 6, 2012
- soft.socksys.net Domain name TG-2633-related domain
- First seen October 9, 2010
- Last seen September 9, 2013
- www.socksys.net Domain name TG-2633-related domain
- www.hichf.com Domain name TG-2633-related domain
- First seen May 6, 2008
- Last seen May 13, 2013
- 68.178.232.100 IP address IP resolution for www.hichf.com
- First seen January 3, 2014
- Donnepar-godaddy@yahoo.fr Email address Contact email address for hichf.com
- First seen May 13, 2013
- dcaccarpowerinverter.com Domain name TG-2633-related domain
- pdmadden@ruggedsystems.com Email address Contact email address for dcaccarpowerinverer.com
- www.pigszone.com Domain name TG-2633 related domain
- 122.10.87.231 IP address IP resolution for www.pigszone.com
- www.pigzone.info Domain name TG-2633 related domain
- 198.74.101.239 IP address IP resolution for www.pigszone.info
- wwww961h@qq.com Email address Email address used to register pigszone.com and pigszone.info
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement