Keitaro TDS Used to Redirect Hosts to Sundown EK and RIG-v EK.
Tags
maec-delivery-vectors: | Watering Hole |
attack-pattern: | Data Direct Exploits - T1587.004 Exploits - T1588.005 Malvertising - T1583.008 Malware - T1587.001 Malware - T1588.001 Server - T1583.004 Server - T1584.004 |
Common Information
Type | Value |
---|---|
UUID | c696b71a-7b60-4f48-9583-f322788f8140 |
Fingerprint | ed6933c9fb6306c7 |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Jan. 23, 2017, 9:52 a.m. |
Added to db | Jan. 18, 2023, 9:59 p.m. |
Last updated | Nov. 17, 2024, 6:54 p.m. |
Headline | Keitaro TDS Used to Redirect Hosts to Sundown EK and RIG-v EK. |
Title | Keitaro TDS Used to Redirect Hosts to Sundown EK and RIG-v EK. |
Detected Hints/Tags/Attributes | 29/2/17 |
Source URLs
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 1 | qj.fse.mobi |
|
Details | Domain | 3 | badboys.net.in |
|
Details | Domain | 1 | mhn.jku.mobi |
|
Details | Domain | 1 | nso.fzo.mobi |
|
Details | Domain | 2 | domainfilsdomainc.study |
|
Details | Domain | 1 | thiscouldbeyourgreenhome.com |
|
Details | Domain | 2 | tds.com |
|
Details | Domain | 2 | update-flash-player.com |
|
Details | File | 9 | flashplayer.exe |
|
Details | File | 816 | index.html |
|
Details | sha256 | 1 | 31d8a6fe4c875f8f5de2ec43e27cf68eecacf23c4ff3ada234e9456d6e3e4f63 |
|
Details | sha256 | 1 | 3b482fbb430d9b6e575eb166af630e8624d7731f671f1f42c483ed240291bf90 |
|
Details | IPv4 | 2 | 88.99.41.189 |
|
Details | IPv4 | 1 | 86.106.131.137 |
|
Details | IPv4 | 2 | 93.190.143.82 |
|
Details | IPv4 | 3 | 93.158.215.169 |
|
Details | IPv4 | 1 | 46.119.217.132 |