2024년 9월 APT 그룹 동향 보고서 - ASEC
Tags
country: | China |
attack-pattern: | Dns - T1071.004 Dns - T1590.002 Dynamic Dns - T1311 Dynamic Dns - T1333 Connection Proxy - T1090 |
Common Information
Type | Value |
---|---|
UUID | f22a4e6a-3fb9-418c-887e-0cb777172ae8 |
Fingerprint | 8b6a7a8e6a03574b |
Analysis status | DONE |
Considered CTI value | 2 |
Text language | |
Published | Oct. 9, 2024, 3 p.m. |
Added to db | Oct. 10, 2024, 8:45 a.m. |
Last updated | Nov. 17, 2024, 6:54 p.m. |
Headline | 2024년 9월 APT 그룹 동향 보고서 |
Title | 2024년 9월 APT 그룹 동향 보고서 - ASEC |
Detected Hints/Tags/Attributes | 27/2/11 |
Source URLs
Redirection | Url | |
---|---|---|
Details | Source | https://asec.ahnlab.com/ko/83732/ |
URL Provider
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 18 | ✔ | ASEC | https://asec.ahnlab.com/ko/feed/ | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | CVE | 56 | cve-2024-36401 |
|
Details | Domain | 39 | www.wsj.com |
|
Details | Domain | 1 | blog.centurylink.com |
|
Details | File | 2 | earth-baxia-spear-phishing-and-geoserver-exploit.html |
|
Details | Threat Actor Identifier - APT-C | 83 | APT-C-36 |
|
Details | Threat Actor Identifier - APT | 522 | APT41 |
|
Details | Url | 1 | https://www.fortinet.com/blog/threat-research/threat-actors-exploit-geoserver-vulnerability-cve-2024-36401 |
|
Details | Url | 2 | https://www.zscaler.com/blogs/security-research/blindeagle-targets-colombian-insurance-sector-blotchyquasar |
|
Details | Url | 2 | https://www.trendmicro.com/en_us/research/24/i/earth-baxia-spear-phishing-and-geoserver-exploit.html |
|
Details | Url | 1 | https://www.wsj.com/politics/national-security/china-cyberattack-internet-providers-260bd835 |
|
Details | Url | 1 | https://blog.centurylink.com/derailing-the-raptor-train |