Taidoor - a truly persistent threat
Tags
attack-pattern: | Data Domains - T1583.001 Domains - T1584.001 Malware - T1587.001 Malware - T1588.001 Software - T1592.002 Tool - T1588.002 |
Common Information
Type | Value |
---|---|
UUID | e9499f16-cdcf-4563-a33a-911c4d8d13b2 |
Fingerprint | 16545318cb3f22d2 |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Sept. 22, 2020, midnight |
Added to db | Sept. 26, 2022, 9:31 a.m. |
Last updated | Sept. 4, 2024, 2:13 a.m. |
Headline | Taidoor - a truly persistent threat |
Title | Taidoor - a truly persistent threat |
Detected Hints/Tags/Attributes | 34/1/17 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://blog.reversinglabs.com/blog/taidoor-a-truly-persistent-threat |
URL Provider
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 14 | blog.reversinglabs.com |
|
Details | File | 2 | mm.dll |
|
Details | File | 1 | mm_tcp_dll.dll |
|
Details | File | 1 | mm_tcp_svchost.dll |
|
Details | File | 1 | svchost.cpp |
|
Details | File | 1 | mm_http_dll.dll |
|
Details | File | 1 | mm_udt_dll.dll |
|
Details | File | 1 | taidoor_sha1_list.txt |
|
Details | File | 1 | taidoor_c2_list.txt |
|
Details | sha1 | 1 | f1a1ea963ae8aca3a4623912c405cc97df510c07 |
|
Details | sha1 | 1 | 859e0f0ccbcafd25b0877a0c6df0c94cd84d2433 |
|
Details | sha1 | 1 | 4118cc4ee6e22bca1933b0033cfe07924293b6bb |
|
Details | sha1 | 1 | de7b0889fce6e38ac4f902e2399c9a794f8f00df |
|
Details | sha1 | 1 | 22c55ded3486614728eaa29a7526d760ac496b20 |
|
Details | Pdb | 1 | mm_tcp_svchost.pdb |
|
Details | Url | 1 | https://blog.reversinglabs.com/hubfs/blog/taidoor_sha1_list.txt |
|
Details | Url | 1 | https://blog.reversinglabs.com/hubfs/blog/taidoor_c2_list.txt |