Roaming Mantis uses DNS hijacking to infect Android smartphones
Tags
Common Information
Type | Value |
---|---|
UUID | 5ed3ace2-cac4-4f08-ad4f-95e46391986d |
Fingerprint | 9d25090f8db336c1 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | April 16, 2018, 8:30 a.m. |
Added to db | Sept. 26, 2022, 9:30 a.m. |
Last updated | Nov. 17, 2024, 6:50 p.m. |
Headline | Roaming Mantis uses DNS hijacking to infect Android smartphones |
Title | Roaming Mantis uses DNS hijacking to infect Android smartphones |
Detected Hints/Tags/Attributes | 75/2/67 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 403 | securelist.com |
|
Details | Domain | 1 | wooribank.pib.smart |
|
Details | Domain | 1 | hanabank.ebk.channel.android |
|
Details | Domain | 1 | webzen.muorigin.google |
|
Details | Domain | 1 | co.happymoney.android |
|
Details | Domain | 1 | atsolution.android |
|
Details | Domain | 2 | my.tv.sohu.com |
|
Details | Domain | 18 | sohu.com |
|
Details | Domain | 46 | www.baidu.com |
|
Details | Domain | 48 | baidu.com |
|
Details | Domain | 54 | re.search |
|
Details | Domain | 18 | match.group |
|
Details | Domain | 1 | my.tv.sohu |
|
Details | Domain | 1 | www.baidu |
|
Details | Domain | 3 | haoxingfu01.ddns.net |
|
Details | Domain | 2 | shaoye11.hopto.org |
|
Details | File | 4 | facebook.apk |
|
Details | File | 8 | chrome.apk |
|
Details | File | 172 | androidmanifest.xml |
|
Details | File | 1 | epost.ps |
|
Details | File | 3 | data.sql |
|
Details | File | 1 | dec_facebook_apk.py |
|
Details | File | 1 | com_329505338.html |
|
Details | File | 1 | com_p_wokaixin158998_detail.html |
|
Details | md5 | 2 | f3ca571b2d1f0ecff371fb82119d1afe |
|
Details | md5 | 2 | 4d9a7e425f8c8b02d598ef0a0a776a58 |
|
Details | md5 | 2 | 03108e7f426416b0eaca9132f082d568 |
|
Details | md5 | 2 | 1cc88a79424091121a83d58b6886ea7a |
|
Details | md5 | 2 | 2a1da7e17edaefc0468dbf25a0f60390 |
|
Details | md5 | 2 | 31e61e52d38f19cf3958df2239fba1a7 |
|
Details | md5 | 2 | 34efc3ebf51a6511c0d12cce7592db73 |
|
Details | md5 | 2 | 808b186ddfa5e62ee882d5bdb94cc6e2 |
|
Details | md5 | 2 | 904b4d615c05952bcf58f35acadee5c1 |
|
Details | md5 | 2 | a21322b2416fce17a1877542d16929d5 |
|
Details | md5 | 2 | b84b0d5f128a8e0621733a6f3b412e19 |
|
Details | md5 | 2 | bd90279ad5c5a813bc34c06093665e55 |
|
Details | md5 | 2 | ff163a92f2622f2b8330a5730d3d636c |
|
Details | md5 | 2 | 19e3daf40460aea22962d98de4bc32d2 |
|
Details | md5 | 2 | 36b2609a98aa39c730c2f5b49097d0ad |
|
Details | md5 | 2 | 3ba4882dbf2dd6bd4fc0f54ec1373f4c |
|
Details | md5 | 2 | 6cac4c9eda750a69e435c801a7ca7b8d |
|
Details | md5 | 2 | 8a4ed9c4a66d7ccb3d155f85383ea3b3 |
|
Details | md5 | 2 | b43335b043212355619fd827b01be9a0 |
|
Details | md5 | 2 | b7afa4b2dafb57886fc47a1355824199 |
|
Details | md5 | 2 | f89214bfa4b4ac9000087e4253e7f754 |
|
Details | md5 | 2 | 1bd7815bece1b54b7728b8dd16f1d3a9 |
|
Details | md5 | 2 | 307d2780185ba2b8c5ad4c9256407504 |
|
Details | md5 | 2 | 3e4bff0e8ed962f3c420692a35d2e503 |
|
Details | md5 | 2 | 57abbe642b85fa00b1f76f62acad4d3b |
|
Details | md5 | 2 | 6e1926d548ffac0f6cedfb4a4f49196e |
|
Details | md5 | 2 | 7714321baf6a54b09baa6a777b9742ef |
|
Details | md5 | 2 | 7aa46b4d67c3ab07caa53e8d8df3005c |
|
Details | md5 | 2 | a0f88c77b183da227b9902968862c2b9 |
|
Details | IPv4 | 1441 | 127.0.0.1 |
|
Details | IPv4 | 2 | 220.136.76.200 |
|
Details | IPv4 | 2 | 220.136.179.5 |
|
Details | IPv4 | 1 | 114.44.37.112 |
|
Details | IPv4 | 1 | 118.166.1.124 |
|
Details | IPv4 | 1 | 118.168.193.123 |
|
Details | IPv4 | 1 | 128.14.50.146 |
|
Details | IPv4 | 2 | 128.14.50.147 |
|
Details | IPv4 | 2 | 220.136.111.66 |
|
Details | IPv4 | 3 | 43.240.14.44 |
|
Details | Url | 37 | http://127.0.0.1 |
|
Details | Url | 2 | http://my.tv.sohu.com/user/%s |
|
Details | Url | 1 | http://my.tv.sohu.com/user/329505338. |
|
Details | Url | 2 | https://www.baidu.com/p/%s/detail |