Roaming Mantis uses DNS hijacking to infect Android smartphones
Common Information
Type Value
UUID 5ed3ace2-cac4-4f08-ad4f-95e46391986d
Fingerprint 9d25090f8db336c1
Analysis status DONE
Considered CTI value 2
Text language
Published April 16, 2018, 8:30 a.m.
Added to db Sept. 26, 2022, 9:30 a.m.
Last updated Nov. 17, 2024, 6:50 p.m.
Headline Roaming Mantis uses DNS hijacking to infect Android smartphones
Title Roaming Mantis uses DNS hijacking to infect Android smartphones
Detected Hints/Tags/Attributes 75/2/67
Attributes
Details Type #Events CTI Value
Details Domain 403
securelist.com
Details Domain 1
wooribank.pib.smart
Details Domain 1
hanabank.ebk.channel.android
Details Domain 1
webzen.muorigin.google
Details Domain 1
co.happymoney.android
Details Domain 1
atsolution.android
Details Domain 2
my.tv.sohu.com
Details Domain 18
sohu.com
Details Domain 46
www.baidu.com
Details Domain 48
baidu.com
Details Domain 54
re.search
Details Domain 18
match.group
Details Domain 1
my.tv.sohu
Details Domain 1
www.baidu
Details Domain 3
haoxingfu01.ddns.net
Details Domain 2
shaoye11.hopto.org
Details File 4
facebook.apk
Details File 8
chrome.apk
Details File 172
androidmanifest.xml
Details File 1
epost.ps
Details File 3
data.sql
Details File 1
dec_facebook_apk.py
Details File 1
com_329505338.html
Details File 1
com_p_wokaixin158998_detail.html
Details md5 2
f3ca571b2d1f0ecff371fb82119d1afe
Details md5 2
4d9a7e425f8c8b02d598ef0a0a776a58
Details md5 2
03108e7f426416b0eaca9132f082d568
Details md5 2
1cc88a79424091121a83d58b6886ea7a
Details md5 2
2a1da7e17edaefc0468dbf25a0f60390
Details md5 2
31e61e52d38f19cf3958df2239fba1a7
Details md5 2
34efc3ebf51a6511c0d12cce7592db73
Details md5 2
808b186ddfa5e62ee882d5bdb94cc6e2
Details md5 2
904b4d615c05952bcf58f35acadee5c1
Details md5 2
a21322b2416fce17a1877542d16929d5
Details md5 2
b84b0d5f128a8e0621733a6f3b412e19
Details md5 2
bd90279ad5c5a813bc34c06093665e55
Details md5 2
ff163a92f2622f2b8330a5730d3d636c
Details md5 2
19e3daf40460aea22962d98de4bc32d2
Details md5 2
36b2609a98aa39c730c2f5b49097d0ad
Details md5 2
3ba4882dbf2dd6bd4fc0f54ec1373f4c
Details md5 2
6cac4c9eda750a69e435c801a7ca7b8d
Details md5 2
8a4ed9c4a66d7ccb3d155f85383ea3b3
Details md5 2
b43335b043212355619fd827b01be9a0
Details md5 2
b7afa4b2dafb57886fc47a1355824199
Details md5 2
f89214bfa4b4ac9000087e4253e7f754
Details md5 2
1bd7815bece1b54b7728b8dd16f1d3a9
Details md5 2
307d2780185ba2b8c5ad4c9256407504
Details md5 2
3e4bff0e8ed962f3c420692a35d2e503
Details md5 2
57abbe642b85fa00b1f76f62acad4d3b
Details md5 2
6e1926d548ffac0f6cedfb4a4f49196e
Details md5 2
7714321baf6a54b09baa6a777b9742ef
Details md5 2
7aa46b4d67c3ab07caa53e8d8df3005c
Details md5 2
a0f88c77b183da227b9902968862c2b9
Details IPv4 1441
127.0.0.1
Details IPv4 2
220.136.76.200
Details IPv4 2
220.136.179.5
Details IPv4 1
114.44.37.112
Details IPv4 1
118.166.1.124
Details IPv4 1
118.168.193.123
Details IPv4 1
128.14.50.146
Details IPv4 2
128.14.50.147
Details IPv4 2
220.136.111.66
Details IPv4 3
43.240.14.44
Details Url 37
http://127.0.0.1
Details Url 2
http://my.tv.sohu.com/user/%s
Details Url 1
http://my.tv.sohu.com/user/329505338.
Details Url 2
https://www.baidu.com/p/%s/detail