Rewterz Threat Alert – North Korean APT Targets Security Researchers - Rewterz
Tags
country: | North Korea |
attack-pattern: | Domains - T1583.001 Domains - T1584.001 Exploits - T1587.004 Exploits - T1588.005 Malware - T1587.001 Malware - T1588.001 Server - T1583.004 Server - T1584.004 |
Common Information
Type | Value |
---|---|
UUID | 1d27dc3c-eef8-4822-9bc6-990197f8e50f |
Fingerprint | dbb509f16c1587cb |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Jan. 26, 2021, 5:52 p.m. |
Added to db | Dec. 19, 2024, 2:29 a.m. |
Last updated | Dec. 22, 2024, 5:34 p.m. |
Headline | Rewterz Threat Alert – North Korean APT Targets Security Researchers |
Title | Rewterz Threat Alert – North Korean APT Targets Security Researchers - Rewterz |
Detected Hints/Tags/Attributes | 43/2/71 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 4 | cve-2021-23965 |
|
Details | CVE | 18 | cve-2021-1647 |
|
Details | Domain | 4 | blog.br0vvnn.io |
|
Details | Domain | 8 | www.fabioluciani.com |
|
Details | Domain | 5 | www.edujikim.com |
|
Details | Domain | 9 | www.dronerc.it |
|
Details | Domain | 1 | www.de.transferwiser.io |
|
Details | Domain | 6 | www.colasprint.com |
|
Details | Domain | 2 | br0vvnn.io |
|
Details | Domain | 3 | trophylab.com |
|
Details | Domain | 4 | transplugin.io |
|
Details | Domain | 3 | transferwiser.io |
|
Details | Domain | 3 | opsonew3org.sg |
|
Details | Domain | 3 | krakenfolio.com |
|
Details | Domain | 3 | investbooking.de |
|
Details | Domain | 5 | codevexillium.org |
|
Details | Domain | 3 | angeldonationblog.com |
|
Details | Domain | 1 | aston-martin-interiors.as |
|
Details | Domain | 1 | www.trophylab.com |
|
Details | File | 2329 | cmd.exe |
|
Details | md5 | 2 | 7fc2af97b004836c5452922d4491baaa |
|
Details | md5 | 3 | f5475608c0126582081e29927424f338 |
|
Details | md5 | 2 | b52e05683b15c6ad56cebea4a5a54990 |
|
Details | md5 | 3 | 56018500f73e3f6cf179d3b853c27912 |
|
Details | md5 | 2 | 9e9f69ed56482fff18933c5ec8612063 |
|
Details | sha1 | 1 | 631adb4cb6433330f3e6dfec4f6c1ea3bfff983c |
|
Details | sha1 | 2 | 8e88fd82378794a17a4211fbf2ee2506b9636b02 |
|
Details | sha1 | 1 | baf97d3b9095911fb7c9c8d7152fdc32ca7b33aa |
|
Details | sha1 | 2 | a3060a3efb9ac3da444ef8abc99143293076fe32 |
|
Details | sha1 | 1 | 4ff6c02140ab1daf217b6e01ec042460389e2e92 |
|
Details | sha256 | 1 | 284df008aa2459fd1e69b1b1c54fb64c534fce86d2704c4d4cc95d72e8c11d6f |
|
Details | sha256 | 3 | a75886b016d84c3eaacaf01a3c61e04953a7a3adf38acf77a4a2e3a8f544f855 |
|
Details | sha256 | 3 | a4fb20b15efd72f983f0fb3325c0352d8a266a69bb5f6ca2eba0556c3e00bd15 |
|
Details | sha256 | 2 | 68e6b9d71c727545095ea6376940027b61734af5c710b2985a628131e47c6af7 |
|
Details | sha256 | 3 | 4c3499f3cc4a4fdc7e67417e055891c78540282dccc57e37a01167dfe351b244 |
|
Details | sha256 | 2 | 25d8ae4678c37251e7ffbaeddc252ae2530ef23f66e4c856d98ef60f399fa3dc |
|
Details | sha256 | 1 | c8a8d2caa429a8bbe885ef8d59d982b4bfd9c48f1255ff69e3b81c6bbd7b2925 |
|
Details | Url | 2 | https://blog.br0vvnn.io |
|
Details | Url | 1 | https://www.fabioluciani.com/uk/comunicati-stampa/graffio-e-gesto-lavabi-in-ceramilux.asp |
|
Details | Url | 1 | https://www.fabioluciani.com/uk/clienti/aston-martin-interiors.as |
|
Details | Url | 1 | https://www.fabioluciani.com/thumb/stthumb.asp?image= |
|
Details | Url | 1 | https://www.fabioluciani.com/it/index.asp?idnewletter=743&iduser=7677&mailing=mailinglist1523637408_20180413_doc_743_8 |
|
Details | Url | 1 | https://www.fabioluciani.com/it/index.asp?idnewletter=723&iduser=7677&mailing=mailinglist1523361543_20180403_doc_723_8 |
|
Details | Url | 1 | https://www.fabioluciani.com/it/index.asp |
|
Details | Url | 1 | https://www.fabioluciani.com/it/comunicati-stampa/ivv-un-viaggio-attraverso-gli-anni-60-e-la-natura-.asp?idnewletter=773&iduser=4537&mailing=mailinglist1527271710_20180525_doc_773_13 |
|
Details | Url | 1 | https://www.fabioluciani.com/it/comunicati-stampa/casalgrandeantiquewood.asp?idnewletter=568&iduser=3709&mailing=mailinglist1505380637_20170912_doc_568_ |
|
Details | Url | 3 | https://codevexillium.org/image/download/download.asp |
|
Details | Url | 1 | https://www.edujikim.com/web/download/현장체험학습 |
|
Details | Url | 1 | http://www.edujikim.com/fds/board/8/manual_5.pdf |
|
Details | Url | 1 | http://www.edujikim.com/fds/board/8/manual_2.pdf |
|
Details | Url | 3 | https://www.dronerc.it/shop_testbr/upload/upload.php |
|
Details | Url | 1 | https://www.dronerc.it/shop_testbr/localization/dir_photoes/logo.php?image=plogo_vp.png |
|
Details | Url | 1 | https://www.dronerc.it/shop_testbr/localization/dir_photoes |
|
Details | Url | 1 | https://www.dronerc.it/shop_testbr/localization |
|
Details | Url | 5 | https://www.dronerc.it/shop_testbr/adapter/adapter_config.php |
|
Details | Url | 1 | https://www.dronerc.it/shop_testbr |
|
Details | Url | 1 | https://www.dronerc.it/forum/forum/categoria-robotica-droni-fpv-e-multicotteri-ad-esclusivo-usoamatoriale/modelli-multirotori-costruzione-e-progettazione/10394-mode1-o-mode-2 |
|
Details | Url | 1 | https://www.dronerc.it/forum/forum/categoria-robotica-droni-fpv-e-multicotteri-ad-esclusivo-uso-amatoriale/fpv-eriprese-aeree/8700-regolamentazione-frequenze-433mhz-900mhz-1-2ghz-2-4ghz-5-8gh |
|
Details | Url | 1 | https://www.dronerc.it/forum/forum/categoria-robotica-droni-fpv-e-multicotteri-ad-esclusivo-uso-amatoriale/flightcontroller-schede-di-volo-motori-e-regolatori/846940-naza-v2-gps-zaggometry-coordinate-errate |
|
Details | Url | 1 | http://www.trophylab.com/tmember/membercheck.asp |
|
Details | Url | 1 | http://www.trophylab.com/shopimages/trophy/favicon.ico |
|
Details | Url | 1 | http://www.trophylab.com/shop/shopbrand2.asp?tcate=1040 |
|
Details | Url | 1 | http://www.trophylab.com/shop/shopbrand2.asp?tcate=10100 |
|
Details | Url | 1 | http://www.trophylab.com/favicon.ico |
|
Details | Url | 1 | http://www.trophylab.com/e |
|
Details | Url | 1 | http://www.trophylab.com |
|
Details | Url | 1 | http://trophylab.com/customerwebsian/dpage.asp?no=8iwcsuy9gy14 |
|
Details | Url | 1 | http://trophylab.com/customerwebsian/dpage.asp?no=12hris9l0914 |
|
Details | Url | 1 | https://blog.br0vvnn.io/pages/blogpoxxxxxxxxx |
|
Details | Url | 1 | https://blog.br0vvnn.io/pages/blogpost.aspx?id=2 |
|
Details | Url | 3 | https://transplugin.io/upload/upload.asp |