THEMETASEC

Cybersecurity News, Aggregated

Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data

CISA Advisories · 7 hours ago Breach

Advisory at a Glance  Title  Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data  Original Publication  October 8, 2026  Executive Summary  Chinese government-linked cyber threat actors, enabled by the Integrity Technology Group, are combining automated scanning tools, large-scale botnets, and hands-on exploitation techniques to target and steal sensitive data from organizations worldwide, including US critical infrastructure sectors. These actors exploit vulnerabilities by using scanning tools, cross-site scripting attacks, and password spraying on Microsoft Exchange servers, while establishing persistence through VPN software and exfiltrating emails and credentials using scripts. To help mitigate against this activity, organizations should prioritize disabling unused services and ports, sanitizing web application inputs to prevent injection attacks, implementing multifactor authentication for all services, and applying timely patches to reduce risks of compromise.  Affected Products  CVE-2014-6278  CVE-2015-3306  CVE-2015-5477  CVE-2016-3081  CVE-2019-11510  CVE-2021-22205  CVE-2021-3199  CVE-2023-22894  Key Actions  Disable unused services and ports, such as automatic configuration, remote access, or file sharing protocols.  Sanitize user input in web applications to prevent possible cross-site scripting (XSS) payload injection.  Implement identity, credential, and access management (ICAM) policies, and then require multifactor authentication (MFA) for services (to the extent possible).  Indicators of Compromise  For a downloadable copy of indicators of compromise, see:  AA26-281A STIX XML AA26-281A STIX JSON Intended Audience  Organizations: Government; Federal Civilian Executive Branch (FCEB); State, Local, Tribal, and Territorial (SLTT); Critical Infrastructure.  Sectors: Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology.  Roles: Defensive Cybersecurity Analysts, Vulnerability Analysts, Security Systems Managers, Incident Response Analysts Introduction  Integrity Technology Group, a China-based company with links to the Chinese government, enables China-linked threat actors to exploit US and foreign organization networks across multiple sectors using various tools and techniques. This advisory provides an analysis of tactics, techniques, and procedures (TTPs) and indicators of compromise (IOCs) from Integrity Technology Group and the threat actors they enable (hereafter referred to as “the threat actors”). The analysis in this advisory provides network defenders with detection and mitigation guidance to reduce the risk of threat actors compromising critical data.  The threat actors use a unique combination of large-scale botnets, virtual private network (VPN) infrastructure, living-off-the-land (LOTL) techniques, and repositories of computer network exploitation (CNE) tools. Although these techniques are not unique to Chinese threat actors, this advisory details how the threat actors use them to support CNE activity.  The threat actors targeted victims across multiple US critical infrastructure sectors, including: Government Services and Facilities, Critical Manufacturing, Healthcare and Public Health, and Information Technology. The actors also targeted victims in US law enforcement, education, and religious organizations, as well as organizations across Southeast Asia, Africa, and North America.  The information in this advisory originates from technical evidence recovered from, and observed during, multiple Federal Bureau of Investigation (FBI) investigations related to Integrity Technology Group.  The FBI, Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), United Kingdom National Cyber Security Centre (NCSC-UK), Australian Signals Directorate’s Australian Cyber Security Centre (ASD’s ACSC), the Canadian Centre for Cyber Security (Cyber Centre), Japan’s National Police Agency (NPA) and National Cybersecurity Office (NCO), New Zealand’s National Cyber Security Centre (NCSC-NZ), and Spain’s Centro Nacional de Inteligencia (CNI), hereafter referred to as “the authoring organizations”—are releasing this joint cybersecurity advisory to urge network defenders from government and relevant organizations to:  Hunt for potential compromises from this activity.  Better protect against this threat activity and other Chinese government-linked cyber targeting.  This advisory also provides our US federal, state, local, territorial, and tribal (FSLTT) government agencies, and international and industry partners, with the indicators and details necessary to proactively defend their networks against this threat and protect critical data.  For more information on People’s Republic of China (PRC) state-sponsored malicious cyber activity in general, see the FBI’s Cyber Threat Overview: China webpage. For more information on China-linked malicious cyber activity, see CISA’s People’s Republic of China Threat Overview and Advisories webpage.  The authoring organizations encourage network defenders to implement the recommendations in the Mitigations section of this advisory to reduce the likelihood and impact of these incidents.  Download the PDF version of this report: Chinese Government-linked Cyber Threat Actors Combine Automated and Hands-on Hacking Tools to Steal Sensitive Data (PDF, 1.40 MB ) For a downloadable copy of IOCs, see:  AA26-281A STIX (JSON, 1,021.16 KB ) AA26-281A STIX XML (XML, 658.87 KB ) Threat Actor Background  Integrity Technology Group (Integrity Tech) is a China-based for-profit company with links to the Chinese government. Integrity Tech employs individuals who support malicious cyber activity in different ways, including acquiring or building cyber tools for use and sale, acquiring and hosting infrastructure, and compromising networks across global victims, which the authoring organizations track as China-based malicious cyber activity. The services provided by Integrity Tech also contribute to the larger Chinese cyber ecosystem, which aims to exfiltrate sensitive data from victims around the world. Notably, the threat actors enabled by Integrity Tech use TTPs consistent with the cyber activity publicly known as Flax Typhoon, Ethereal Panda, and Red Juliett, among others. However, these threat actors may also perform activity not associated with Integrity Tech.  Note: Cybersecurity companies have different methods of tracking and attributing cyber actors and these may not be a 1:1 correlation to the US Government's methodology and understanding for all activity related to these groupings.  Technical Details  Note: This advisory uses the MITRE ATT&CK® Matrix for Enterprise framework, version 19. See Appendix A: Indicators of Compromise and the MITRE ATT&CK Tactics and Techniques section of this advisory for a table of the threat actors’ activity mapped to MITRE ATT&CK tactics and techniques. Reconnaissance   The threat actors use a variety of open source scanning tools to find vulnerabilities in networks and web-based applications, including: BBScan, dirsearch, Fscan, ksubdomain, masscan, NMAP, OneForAll, ShuiZe, and wpscan [T1595.002]. See Appendix A: Indicators of Compromise for a complete list of scanning tools.  Some of these tools contain features useful for fingerprinting remote applications, testing remote authentication protocols, or enumerating the pages of a website. The use of open source tools typically found on GitHub suggests the threat actors tend to look for more vulnerable targets. In general, the threat actors focus on scanning ports 21 (file transfer protocol [FTP]), 22 (SSH), 53 (domain name system [DNS]), 80 (HTTP), 443 (HTTPS), and 1080 (SOCKS). When scanning websites with dirsearch, the threat actors attempt to enumerate PHP and ASP (.NET) pages.  MicroScan  As early as 2017, these threat actors have also used a malicious application known as “MicroScan.” This Python-based web application contains over 1,300 penetration testing scripts written to scan websites for specific vulnerabilities. The threat actors used these scripts to target services including OpenSSL, Oracle WebLogic, Rejetto, WordPress, Juniper ScreenOS, Jenkins, and Apache Struts. See Appendix B: Observed Common Vulnerabilities and Exposures for a list of successfully exploited common vulnerabilities and exposures (CVEs) recovered from penetration testing scripts. Figure 1 shows a MicroScan account dashboard displaying detected vulnerabilities. Figure 1. MicroScan Account Dashboard Showing Detected Vulnerabilities Initial Access and Execution  Since at least mid-January 2021, the threat actors have gained access to victim networks and cloud-based services primarily through command line utilities built on exploit codes written in popular programming languages, such as Python and Go [T1059.006]. Additionally, the threat actors have used JavaScript [T1059.007] and HTML code to execute cross-site scripting (XSS) attacks. XSS vulnerabilities allow malicious actors to use unwitting third-party applications vulnerable to XSS to modify content on a webpage [T1189] and target other victims.  During the investigations, the FBI recovered an XSS payload used by the threat actors. When executed on a vulnerable website running JavaScript, this payload modifies webpage content to display username and password fields, facilitating user credential harvesting (see Figure 2). Figure 2. Executed XSS Payload After a user enters any username and password, the executed XSS payload page generates a link to download a password-protected .zip file. The .zip file’s contents originate from encoded bytes within the XSS payload and contain the executable file live700_v1.exe.  Analysis of live700_v1.exe demonstrated the executable begins a process named DiagTrack.exe, which shares its name with legitimate Windows software [T1036.003]. DiagTrack.exe then establishes encrypted communications over the HTTP protocol with the domain dns.studiocloud.xyz, which the FBI attributes to Integrity Tech. Given that the executable also contains functions designed to query data from user mailboxes, the FBI assesses the malware likely targets user email data for exfiltration.  EBurst  The threat actors use EBurst, an open source Python-based tool, to target accounts in the Microsoft Office365 Cloud environment. The tool compromises email accounts on Microsoft Exchange servers using multiple interfaces for password spraying [T1110.003] and password guessing [T1110.001] against each supplied email address. Based on the open source EBurst ReadMe file, these interfaces include: Exchange Control Panel (ECP);  Exchange Web Services (EWS);  Offline Address Book (OAB);  Outlook Web Access (OWA);  Remote Procedure Call (RPC);  Application Programming Interface (API);  Messaging Application Programming Interface (MAPI);  PowerShell;  Autodiscover; and   Microsoft-Server-ActiveSync.  Network defenders should include these interfaces when defending against EBurst.  Persistence  To establish persistence, the threat actors install virtual private network (VPN) software clients on victim devices [T1133] to obfuscate command and control (C2) communications or other actions, further preventing victims from attributing malicious network activity.  The threat actors typically download SoftEther installers onto victim devices from threat actor-controlled infrastructure using PowerShell or LOTL binaries for Windows Systems [T1059.001]. For Linux/Unix distributions, the threat actors download SoftEther installers via curl or wget. For either operating system, the actors configure the SoftEther client to automatically reconnect on startup. They often name the installers conhost.exe or dllhost.exe to appear as common Windows executables [T1036.003]. Additionally, endpoint detection software is less likely to flag SoftEther because it is a legitimate VPN software.  In some observed cases, the threat actors stored the SoftEther program directly on the server. Analysis of these servers revealed victim domains and subdomains that hosted the SoftEther connections:  98aiblog[.]com;  hmbcloud[.]com;  hmbcloud[.]net;  hmbiplc-01[.]com;  iepl.node[.]cm;   javacheck.ooguy[.]com;  javaupdate.giize[.]com;  sexytube0[.]com; and  twimg.co[.]uk.  The threat actors use SoftEther to maintain persistent remote access to victim devices to enable data exfiltration. The FBI observed the threat actors installing the client on the end-user’s system, which connected to the C2 server using one of the identified domains, subdomains, or the server’s IP address. The threat actors also accessed other targets, including cybersecurity websites, connected to these hubs.  Collection and Exfiltration  The FBI observed the threat actors downloading databases or manually pulling data from the victim emails and staging the exfiltration data with discreet file names to minimize detection of the MySQL email dump. Some of these names include:  001.gif;  All_scanner_vXX.pl.gz (XX represents either a one- or two-digit number);  Css.js;  Include.png;  M2k.js;  M2k_list.js; and  M2k_ui_adm.js.  Curlc4.txt  The FBI observed that the threat actors created a bot using the PHP script Curlc4.txt to obtain emails from victims. The script is specifically designed to interface with the Microsoft EWS API, which allows the threat actors to access email and content items, such as calendars and contacts [T1114.002].  Based on observations, the script appears to be stand-alone rather than installed on a compromised device. The script uploaded emails to a remote server [T1020], obfuscating many of the directories and files it created, and changed the name of the child process to crypto.  The script downloaded the original file from https://upl.natcloudservice[.]com using IP address 149.28.132[.]137. The main C2 domain for the bot was natcloudservice[.]com, and the domain communicated with https://natcloudservice[.]com/ews and upl.natcloudservice[.]com/ews. Before exfiltration, the bot compressed emails. In some instances, the threat actor also used a password to encrypt emails using RC4 or AES-128-CBC [T1560.003].  The PHP script took up to two command-line arguments. The first argument appeared to be the root directory where the scripts execute. If the first argument was not supplied, then the script searched for a writeable directory [T1074.001] to use as its directory. The script searched the directories listed in Table 1 until it found a writeable one. The script stored the second command-line argument in a variable saved to the targeted system. Table 1. Directories Searched by Curlc4  Directory to Search  Subdirectories to Skip  /  /bin, /boot, /dev, /etc, /run, /proc, /sys, /var, /tmp, /usr  /home    /var/www    /usr    /var/tmp    The following is a list of unique strings found in the script: $dir/storage/fm/.run;  $dir/.run;  public $password='jh4jnryw76ikmh';  public $file='/var/tmp/.sess.zip'; https://upl.natcloudservice[.]com.ews;  public $key='rhnr5m54pk65wertc';  $this->enc="r";this->cipher="rc4";this->iv="";  $this->enc="a";this->cipher="aes-128-cbc";this->iv="1111111111111111";  https://natcloudservice[.]com/ews; and  curl_setopt($this->ch, CURLOPT_HTTPHEADER,array("X-Id: $clientid")).  Other directories and files that indicate this script may be executed on a system include:  RUNNING_DIRECTORY/storage/fm;  RUNNING_DIRECTORY /storage/fm.run (file);  RUNNING_DIRECTORY /.run;  RUNNING_DIRECTORY/clientid (file); and  RUNNING_DIRECTORY/cp (file).  DC.exe The threat actors used DC.exe to execute the DCSync replication technique [T1003.006] to copy sensitive information from the Active Directory (AD), including account credentials, group membership details, and trust relationships. DC.exe used a Remote Procedure Call (RPC) binding to the victim’s domain controller. The file then used the Directory Replication Service to retrieve data from the victim’s AD. Specifically, it retrieved a handle to the local security policy object, which is used to query the domain controller for the DNS domain name, domain security identifier (SID), and domain replication epoch. The file also used the following object IDs to retrieve information about Active Directory attributes and configurations:  1.2.840.113556.1.2.48;  1.2.840.113556.1.4.1;  1.2.840.113556.1.4.125;  1.2.840.113556.1.4.129;  1.2.840.113556.1.4.133;  1.2.840.113556.1.4.135;  1.2.840.113556.1.4.146;  1.2.840.113556.1.4.159;  1.2.840.113556.1.4.160;  1.2.840.113556.1.4.221;  1.2.840.113556.1.4.27;  1.2.840.113556.1.4.302;  1.2.840.113556.1.4.55;  1.2.840.113556.1.4.609;  1.2.840.113556.1.4.656;  1.2.840.113556.1.4.8;  1.2.840.113556.1.4.90;  1.2.840.113556.1.4.94; and  1.2.840.113556.1.4.96.  Data Exfiltration  The FBI recovered an archived email database the threat actors used to target email accounts of victim organizations. The threat actors collect account credentials and exfiltrate victim email data from on-premise systems and cloud-based services. Observed victims of email data theft included government organizations, law enforcement agencies, healthcare systems, and religious institutions located in Southeast Asia. In some instances, the threat actors restricted access to the exfiltrated data to only IP addresses from Xiamen, China.  Office-cli Program The threat actors use a command-line utility office-cli [T1059.004] to continuously target and access Microsoft Outlook 365 email accounts to exfiltrate emails across different time periods. The threat actors occasionally update these accounts and swap them for the most recent accounts. The threat actors use office-cli to automate access and exfiltration of mail content using configuration files, such as client_id, tenant_id, and secret. The FBI observed the threat actors executing office-cli from the command line or by running it from a Bash script. In both instances, the threat actors place the JSON files required to access the mailboxes in the config directory. Additionally, office-cli saves data gathered from the victims in a subdirectory of the dump directory. The threat actors evade detection when using this program by using legitimate access methods. The threat actors maintain a custom web application that provides third-party access to stolen email content. Users of this application can pass specific arguments in URLs to see email content for specific accounts. Indicators of Compromise See Appendix A: Indicators of Compromise for a list of all observed indicators. MITRE ATT&CK Tactics and Techniques See Table 2 to Table 9 for all referenced threat actor tactics and techniques in this advisory. For assistance with mapping malicious cyber activity to the MITRE ATT&CK framework, see CISA and MITRE ATT&CK’s Best Practices for MITRE ATT&CK Mapping and CISA’s Decider Tool. Table 2. Reconnaissance  Technique Title  ID  Use  Active Scanning: Vulnerability Scanning  T1595.002  The threat actors leverage several scanning tools to find vulnerabilities in networks and web-based applications.  Table 3. Initial Access  Technique Title  ID  Use  Drive-by Compromise  T1189  The threat actors execute XSS attacks to leverage an unwitting third-party application to modify content on a webpage.  Table 4. Execution  Technique Title  ID  Use  Command and Scripting Interpreter: PowerShell  T1059.001  The threat actors typically download SoftEther installers onto victim devices from threat actor controlled infrastructure using PowerShell.  Command and Scripting Interpreter: Unix Shell  T1059.004  The threat actors use office-cli, a Linux-based binary, to continuously target and access Microsoft Outlook 365 accounts. Office-cli automates exfiltration of mail content using configuration files, including account credentials.  Command and Scripting Interpreter: Python  T1059.006  The threat actors gain access to victim networks and cloud-based services primary through command-line utility tools based on exploit codes written in Python.  Command and Scripting Interpreter: JavaScript  T1059.007  The threat actors use JavaScript to execute XSS attacks.  Table 5. Persistence  Technique Title   ID  Use  External Remote Services  T1133  The threat actors install VPN software clients on victim devices to establish persistence and obfuscate C2 communications.  Table 6. Defense Evasion  Technique Title   ID  Use  Masquerading: Rename Legitimate Utilities  T1036.003  The threat actors run executables with the same name of a known, legitimate Windows software and installers to evade detection.  Table 7. Credential Access  Technique Title   ID  Use  OS Credential Dumping: DCSync  T1003.006  The threat actors use DC.exe to execute the DCSync replication technique to copy sensitive information from the Active Directory.  Brute Force: Password Guessing  T1110.001  The threat actors use eburst.py to conduct password guessing to compromise email accounts on Microsoft Exchange servers.  Brute Force: Password Spraying  T1110.003  The threat actors use eburst.py to conduct password spraying to compromise email accounts on Microsoft Exchange servers.  Table 8. Collection  Technique Title   ID  Use  Email Collection: Remote Email  T1114.002  The threat actors use the PHP script to interface with the Microsoft EWS API, enabling them to access email and content items.  Archive Collection Data: Archive via Custom Method  T1560.003  The threat actors use a custom bot to compress, and in some cases encrypt, files prior to exfiltration.  Data Staged: Local Data Staging  T1074.001  The PHP script searches for a writeable directory to use as its directory.  Table 9. Exfiltration  Technique Title   ID  Use  Automated Exfiltration  T1020  The threat actors leverage the PHP script to automatically upload emails to a remote server.  Incident Response If a potential compromise is detected, organizations should take the following actions:  Determine which hosts were compromised and isolate them by quarantining or taking them offline.   Initiate threat hunting activities to scope the intrusion.   Collect and review relevant artifacts, logs, and other data to identify threat actor TTPs, compromised devices and accounts, a timeline of activity, etc.   Follow national guidelines and requirements in your country on reporting cyber incidents (see Contact Information).  Apply eviction countermeasures to contain the incident and eradicate the threat actor from the network. Start applying countermeasures after collecting enough threat hunting data to inform effective countermeasure selection; this will likely overlap with threat hunting activities):  Use CISA’s Eviction Strategies Tool to assemble countermeasures for a systematic eviction plan—the tool comprises Playbook-NG (a web application) and COUN7ER (a database of post-compromise countermeasures mapped to adversary TTPs).   Use Playbook-NG and COUN7ER together to assemble a systematic eviction plan, or playbook, that leverages distinct countermeasures to contain and evict cyber threat actors.   The playbook features a list of recommended response actions based on threat actor TTPs and includes each action’s intended outcome, preparatory steps, and associated risks. For more information, see CISA’s Eviction Strategies Tool Fact Sheet.  Harden the network to prevent additional malicious activity (see Mitigations for guidance).  Mitigations The authoring organizations recommend network defenders and organizations implement the mitigations below to improve your organization’s cybersecurity posture on the basis of the threat actors’ activity. These mitigations align with the Cross-Sector Cybersecurity Performance Goals (CPGs) developed by CISA and the National Institute of Standards and Technology (NIST). The CPGs provide a minimum set of practices and protections that CISA and NIST recommend all organizations implement. CISA and NIST based the CPGs on existing cybersecurity frameworks and guidance to protect against the most common and impactful threats and TTPs. Visit CISA’s CPGs webpage for more information on the CPGs, including additional recommended baseline protections.  The authoring organizations recommend network defenders and organizations implement these mitigations: Disable unused services and ports, such as automatic configuration, remote access, or file sharing protocols.  Configure applications to reveal as little information as possible when serving login pages or banner information in response to external requests.  Consider using an attack surface management service or web-based search platforms that search the internet to identify exposed services or ports [CPG 3.S]. For additional support, follow CISA’s Internet Exposure Reduction Guidance and NSA’s Attack Surface Management.  Sanitize user input in web applications to prevent possible XSS payload injection.  Implement identity, credential, and access management (ICAM) policies across the organization and then require multifactor authentication (MFA) [CPG 3.F] for all services (to the extent possible), particularly for webmail, VPNs, and accounts that access critical systems.  Replace default passwords with strong passwords [CPG 3.A].  Limit and audit user accounts with administrative privileges and configure access controls with least privilege in mind.   Ensure only users that need administrator privileges are granted these privileges, and regularly review access to assess whether it is still required [CPG 3.G].  Enable download and domain reputation screening in web browsers, along with protective DNS resolution, to block downloads of known malware and connections to websites and domains with unsafe reputations.  Monitor for signs of unauthorized use of LOTL tools and unexpected Active Directory replication [CPG 4.B].  Implement network segmentation to ensure a compromised device has no access to sensitive resources of another organizational unit [CPG 3.I].  Use the principle of least privilege to provide just enough connectivity for devices to perform their intended functions [CPG 3.H].  For a less resource constrictive mitigation, organizations may segment edge devices internally.  Monitor cloud accounts for connected applications that can access sensitive data in file systems and email data.  Review web application access logs for signs of exploitation attempts, such as malicious directory traversal attempts, command injection attempts, or enumeration attempts [CPG 3.Q].  Apply patches and updates, including software and firmware updates (regular patching mitigates many high-risk security vulnerabilities) [CPG 2.B].  If available, use automatic update channels from trusted network locations.  Do not trust email messages claiming to provide software updates as attachments or via links to untrusted websites.  Install and regularly update antivirus software on all hosts and enable real time detection.  Monitor for abnormal and high volumes of unexpected traffic (scanning) using firewalls and/or intrusion detection systems [CPG 4.B].  Since an attempted compromise using a distributed denial of service (DDoS) technique may appear as normal traffic, it is critical for organizations to define, monitor, and prepare for abnormal traffic volumes.  Monitor for high volumes of outbound or upload traffic from workstations or other devices that usually have low volumes of uploads compared to downloads.  Monitor logs and investigate unusual IP addresses and ports in command lines, registry entries, and firewall logs to identify other hosts that are potentially involved in actor actions [CPG 3.Q].  Review perimeter firewall configurations for unauthorized changes and/or entries that may permit external connections to internal hosts.  Monitor for abnormal account activity, such as logons outside of normal working hours and impossible time and distance logons (e.g., a user logging on from two geographically separated locations at the same time) [CPG 4.B].  Implement a recovery plan to maintain and retain multiple copies of sensitive or proprietary data and servers in a physically separate, segmented, and secure location (i.e., hard drive, storage device, or the cloud) [CPG 1.C].  Regularly back up data and password protect backup copies offline [CPG 3.O].  Ensure copies of critical data are not accessible for modification or deletion from the system where data resides.  Replace end-of-life products with supported alternatives that are included in vendor support plans.  Ensure systems use the strongest feasible form of authentication [CPG 3.B; CPG 3.F].  Harden authentication protocols and access lists [CPG 3.H].  Regularly rotate keys for your service accounts, use strong key lengths to enhance security and minimize the risk of key compromise, and implement role-based access control (RBAC) to avoid granting excess privileges.  Provide cyber security awareness and training [CPG 3.J].  Regularly train users on information security principles and techniques, as well as overall emerging cybersecurity risks and vulnerabilities (e.g., ransomware and phishing scams).  Regularly engage reputable and skilled penetration testing services to evaluate your public attack surface and remediate the most commonly exploited vulnerabilities used by these actors.  Validate Security Controls  In addition to applying mitigations, the authoring organizations recommend exercising, testing, and validating your organization's security program against the threat behaviors mapped to the MITRE ATT&CK for Enterprise framework in this advisory. The authoring organizations recommend testing your existing security controls inventory to assess how they perform against the ATT&CK techniques described in this advisory.  To get started:  Select an ATT&CK technique described in this advisory (see Table 2 to Table 9).  Align your security technologies against the technique.  Test your technologies against the technique.  Analyze your detection and prevention technologies’ performance.  Repeat the process for all security technologies to obtain a set of comprehensive performance data.  Tune your security program, including people, processes, and technologies, based on the data generated by this process.  The authoring organizations recommend continually testing your security program, at scale, in a production environment to ensure optimal performance against the MITRE ATT&CK techniques identified in this advisory. Resources  For more information on attack surface management, see:  CISA’s Internet Exposure Reduction Guidance;  CISA’s Cyber Hygiene Services for US critical infrastructure; and  NSA’s Attack Surface Management for the US Defense Industrial Base (DIB). For additional information on the UK’s National Cyber Security Centre’s (NCSC-UK’s) resources see:  Network Security Fundamentals;  Protective DNS Service;  Guidance Selecting Right Methods to Authenticate Customers;  Guidance Ransomware-Resistant Backups; and  Penetration testing guidance, see Penetration Testing.  For more information on sanitizing user input, see:  CISA’s Secure by Design Alert: Eliminating Cross Site Scripting Vulnerabilities; The Open Worldwide Application Security Project’s (OWASP) Input Validation Cheat Sheet; and  OWASP’s Cross-Site Scripting Prevention Cheat Sheet.  For more information on protective DNS (PDNS), see:  NSA and CISA’s guidance Selecting a Protective DNS Service; and   NSA’s Protective DNS Service offerings for the US Defense Industrial Base.   For more information on LOTL, see ASD’s ACSC and CISA’s joint guidance Identifying and Mitigating Living Off the Land Techniques.  For more information on defending Active Directory, see ASD’s ACSC’s joint guidance Detecting and Mitigating Active Directory Compromises.  For more information on Canadian Cyber Centre resources, see:  Phishing-resistant MFA;  Top 10 security actions on network segmentation;  Top 10 security actions for patching OS and applications;  Obsolete products (end-of-life);  Preventative security tools; and  Best practices with passphrases and passwords.  Contact Information   US organizations are encouraged to report suspicious or criminal activity related to information in this advisory to the FBI, CISA, and/or NSA:  File a claim with FBI’s Internet Crime Complaint Center (IC3) or contact your local FBI field office, or contact CISA via CISA’s 24/7 Operations Center at contact@cisa.dhs.gov or 1-844-Say-CISA (1-844-729-2472). When available, please include the following information regarding the incident:  Date, time, and location of the incident;  Type of activity;  Number of people affected;  Type of equipment used for the activity; and  Name of the submitting company or organization, and a designated point of contact.  For NSA cybersecurity guidance inquiries, contact CybersecurityReports@nsa.gov.  United Kingdom organizations: Report a significant cyber security incident at ncsc.gov.uk/report-an-incident (monitored 24 hours) or, for urgent assistance, call 03000 200 973.  Australian organizations: Visit cyber.gov.au or call 1300 292 371 (1300 CYBER 1) to report cybersecurity incidents and access alerts and advisories. Canadian organizations: Report incidents by emailing the Canadian Centre for Cyber Security (Cyber Centre) at contact@cyber.gc.ca, (613) 949-7048, or 1-833-CYBER-88.  Japan organizations: Report an incident to the National Cybersecurity Office (NCO) via email at first-team@cyber.go.jp or the National Police Agency’s (NPAs) web portal at https://www.npa.go.jp/bureau/cyber/soudan.html.  New Zealand organizations: Visit ncsc.govt.nz or call 0800 114 115 to report cyber security incidents.  Disclaimer  The information in this report is being provided “as is” for informational purposes only. The authoring organizations do not endorse any commercial entity, product, company, or service, including any entities, products, or services linked within this document. Any reference to specific commercial entities, products, processes, or services by service mark, trademark, manufacturer, or otherwise, does not constitute or imply endorsement, recommendation, or favoring by the authoring organizations.  Version History  October 8, 2026: Initial version.  Appendix A: Indicators of Compromise See Table 10 to Table 15 for a list of observed IOCs. The IOCs listed in the appendices may or may not be addressed in detail in the body of this document; however, endpoint detection systems can ingest all of these IOCs to help mitigate threat activity.  Disclaimer: Several of the observed IOCs date back to as early as 2016. The authoring organizations recommend investigating or vetting these IOCs prior to taking action, such as blocking.  Note: The first and last dates are included in this table, with an asterisk (*) denoting the WHOIS registry expiration date specified within.  Table 10. Domain Names  Domain  First Seen  Last Seen  _msdcs.cktime.ooguy[.]com  12/26/2023  7/30/2024  067[.]cz  12/6/2018  1/16/2021  1421.client.96html[.]com  1/18/2019  1/18/2027*  1421.cloud.96html[.]com  1/18/2019  1/18/2027*  1421.support.96html[.]com  1/18/2019  1/18/2027*  154-119-131-252-103-58-216-162-36.m.secshow[.]net  6/26/2023  6/26/2026*  20656.hus1.ptps[.]tk  12/5/2019  7/24/2021  20656.hus3.ptps[.]tk  12/5/2019  7/24/2021  2-12-44-140-78-81-211-109-241.h.secshow[.]net  6/26/2023  6/26/2026*  22852.careers.96html[.]com  1/18/2019  1/18/2027*  22852.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  22852.trendmicro.96html[.]com  1/18/2019  1/18/2027*  23175.careers.96html[.]com  1/18/2019  1/18/2027*  23175.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  24280.hus1.ptps[.]tk  12/5/2019  7/24/2021  2637596418.softether[.]net  9/22/2023  6/22/2024  28394.careers.96html[.]com  1/18/2019  1/18/2027*  28394.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  28394.trendmicro.96html[.]com  1/18/2019  1/18/2027*  28733.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  28733.trendmicro.96html[.]com  1/18/2019  1/18/2027*  30773.hus2.ptps[.]tk  12/5/2019  7/24/2021  30773.hus3.ptps[.]tk  12/5/2019  7/24/2021  35584.careers.96html[.]com  1/18/2019  1/18/2027*  35584.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  35584.trendmicro.96html[.]com  1/18/2019  1/18/2027*  39583.b.alitagotest[.]cf  1/27/2020  12/7/2021  3w.feeee[.]io  2/8/2024  2/8/2025  44673.careers.96html[.]com  1/18/2019  1/18/2027*  44673.trendmicro.96html[.]com  1/18/2019  1/18/2027*  47298.96html[.]com  1/18/2019  1/18/2027*  47298.client.96html[.]com  1/18/2019  1/18/2027*  47298.cloud.96html[.]com  1/18/2019  1/18/2027*  47298.support.96html[.]com  1/18/2019  1/18/2027*  50669.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  51640.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  51943.hus1.ptps[.]tk  12/5/2019  7/24/2021  51943.hus3.ptps[.]tk  12/5/2019  7/24/2021  54-2-32-236-208-2-40-107-38.h.secshow[.]net  6/26/2023  6/26/2026*  60928.hus1.ptps[.]tk  12/5/2019  7/24/2021  66-37-178-96-110-2-40-107-38.h.secshow[.]net  6/26/2023  6/26/2026*  74788.careers.96html[.]com  1/18/2019  1/18/2027*  74788.trendmicro.96html[.]com  1/18/2019  1/18/2027*  77692.careers.96html[.]com  1/18/2019  1/18/2027*  77692.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  77692.trendmicro.96html[.]com  1/18/2019  1/18/2027*  82262.careers.96html[.]com  1/18/2019  1/18/2027*  82262.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  85005.careers.96html[.]com  1/18/2019  1/18/2027*  85005.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  85005.trendmicro.96html[.]com  1/18/2019  1/18/2027*  88783.hus1.ptps[.]tk  12/5/2019  7/24/2021  90174.careers.96html[.]com  1/18/2019  1/18/2027*  90174.careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  96976.careers.96html[.]com  1/18/2019  1/18/2027*  96976.trendmicro.96html[.]com  1/18/2019  1/18/2027*  96cee[.]com  1/7/2016  5/9/2024  96html[.]com  1/18/2019  9/3/2024  98aiblog[.]com  3/11/2024  3/12/2026*  a.alitagotest[.]cf  1/27/2020  12/7/2021  a.studiocloud[.]xyz  12/31/2021  12/3/2024  admin.dellme[.]ml  3/20/2020  8/8/2020  alitagotest[.]cf  1/27/2020  12/7/2021  arforcex[.]com  3/5/2019  5/11/2021  asean.twimg.co[.]uk  9/21/2024  12/15/2024  az.studiocloud[.]xyz  12/31/2021  12/3/2024  b.alitagotest[.]cf  1/27/2020  12/7/2021  bailbonding[.]info  1/3/2020  1/3/2022  bbs.sunmoon[.]website  9/20/2023  9/20/2024  bj-hk.hmbcloud[.]net  3/29/2021  3/29/2021  bj-jp.hmbcloud[.]net  4/10/2021  5/7/2021  blog.98aiblog[.]com  7/12/2024  8/14/2024  bsnl.twimg.co[.]uk  6/17/2024  7/7/2024  careers.96html[.]com  1/18/2019  1/18/2027*  careers.trendmicro.96html[.]com  1/18/2019  1/18/2027*  cch.ooguy[.]com  10/11/2024  10/11/2024  check.96html[.]com  1/18/2019  1/18/2027*  checkapi[.]tk  1/6/2022  4/10/2023  checkinfo[.]tk  9/22/2012  12/14/2022  chr0mail[.]com  6/23/2021  6/23/2026*  cktime.ooguy[.]com  12/26/2023  7/30/2024  client.96html[.]com  1/18/2019  1/18/2027*  cloud.96html[.]com  1/18/2019  1/18/2027*  csrfproxy.studiocloud[.]xyz  12/31/2021  12/3/2024  dasxcyb[.]ga  1/29/2021  1/29/2021  dc-29465b27aa45.96html[.]com  1/18/2019  1/18/2027*  dc-4fe9871cb224.96html[.]com  1/18/2019  1/18/2027*  dc-582fc0f46da9.96html[.]com  1/18/2019  1/18/2027*  dc-843d98722400.96html[.]com  1/18/2019  1/18/2027*  dc-bb503834b7dc.96html[.]com  1/18/2019  1/18/2027*  dc-c11a983d7f83.96html[.]com  1/18/2019  1/18/2027*  dellme[.]ml  3/20/2020  8/8/2020  dns.studiocloud[.]xyz  12/10/2021  5/9/2024  dns361[.]tk  2/7/2022  11/19/2023  dsdsei[.]com  4/10/2018  4/10/2025  eck.giize[.]com  9/28/2024  9/30/2024  eg.twimg.co[.]uk  9/22/2024  12/14/2024  etechhosting.twimg.co[.]uk  9/21/2024  12/16/2024  fcchk.twimg.co[.]uk  9/21/2024  12/14/2024  feeee[.]io  2/8/2024  2/8/2025  findfindx[.]com   1/6/2022  8/10/2023  fukua[.]org  11/24/2017  11/24/2027*  gate.sinica.edu.tw.checkapi[.]cf  1/6/2022  4/10/2023  googles.ddns[.]net  10/22/2021  10/22/2021  gz-hk.hmbcloud[.]net  12/28/2020  1/22/2021  h.secshow[.]net  6/26/2023  6/26/2026*  h5.feeee[.]io  2/8/2024  2/8/2025  halloween.checkapi[.]cf  1/6/2022  4/10/2023  helpuself.ptps[.]tk  12/5/2019  7/24/2021  hgiga.96html[.]com  1/18/2019  1/18/2027*  honey1314520[.]com  11/23/2020  11/23/2022  hook.studiocloud[.]xyz  12/31/2021  12/3/2024  hus1.ptps[.]tk  12/5/2019  7/24/2021  hus3.ptps[.]tk  12/5/2019  7/24/2021  hw1.ptps[.]tk  12/5/2019  7/24/2021  ica.96html[.]com  1/18/2019  1/18/2027*  im.arforcex[.]com  3/4/2019  3/5/2026*  imap.sunmoon[.]website  9/20/2023  9/20/2024  info.96html[.]com  1/18/2019  1/18/2027*  integritytoch[.]com  12/11/2020  12/11/2022  iplc-hk.hmbcloud[.]com  11/30/2020  12/8/2020  javacheck.ooguy[.]com  12/22/2023  6/25/2024  javaupdate.giize[.]com  12/22/2023  6/15/2024  just.checkapi[.]cf  1/6/2022  4/10/2023  kk.dasxcyb[.]ga  1/29/2021  1/29/2021  leicc009[.]ga  5/24/2020  4/24/2021  live.studiocloud[.]xyz  12/31/2021  12/3/2024  ls.twimg.co[.]uk  9/21/2024  12/14/2024  m.secshow[.]net  6/26/2023  6/26/2026*  ma.studiocloud[.]xyz  12/31/2021  12/3/2024  mail.bailbonding[.]info  1/3/2020  1/3/2022  mail.sunmoon[.]website  9/20/2023  9/20/2024  masaplus[.]club  7/22/2021  7/22/2024  microscan[.]me  12/10/2017  12/10/2018  mitt.96html[.]com  1/18/2019  1/18/2027*  ms.studiocloud[.]xyz  12/31/2021  12/3/2024  msedge[.]store  11/9/2023  11/9/2025  mx.sunmoon[.]website  9/20/2023  9/20/2024  natcloudservice[.]com  9/8/2023  9/8/2024  nikoes[.]gq  6/15/2021  3/22/2023  np.twimg.co[.]uk  9/21/2024  11/25/2024  ns1.alitagotest[.]cf  1/27/2020  12/7/2021  ns1.honey1314520[.]com  11/23/2020  11/23/2022  ns1.nikoes[.]gq  6/15/2021  3/22/2023  ns2.nikoes[.]gq  6/15/2021  3/22/2023  one.hmbiplc-01[.]com  4/2/2022  4/2/2022  payment.feeee[.]io  2/8/2024  2/8/2025  pdc._msdcs.cktime.ooguy[.]com  12/26/2023  7/30/2024  ptps[.]tk  12/5/2019  7/24/2021  puc.checkapi[.]tk  1/6/2022  4/10/2023  purple76[.]com  11/11/2021  11/11/2026*  pw.sexytube0[.]com  8/6/2021  4/18/2024  pw2.sexytube0[.]com  10/7/2017  10/8/2027*  random.cktime.ooguy[.]com  12/26/2023  7/30/2024  s3crts.softether[.]net  3/25/2021  7/27/2022  scallpay[.]com  7/3/2023  7/3/2024  search.96html[.]com  1/18/2019  1/18/2027*  secretr.feeee[.]io  2/8/2024  2/8/2025  secshow[.]net  6/26/2023  6/26/2026*  senate.twimg.co[.]uk  9/21/2024  12/14/2024  server.feeee[.]io  2/8/2024  2/8/2025  sexytube0[.]com  10/7/2017  10/8/2027*  shifuj[.]com  6/3/2019  6/5/2019  sh-jp.hmbcloud[.]net  4/10/2021  4/25/2021  shop.96html[.]com  1/18/2019  1/18/2027*  shopify.feeee[.]io  2/8/2024  2/8/2025  smtp.sunmoon[.]website  9/20/2023  9/20/2024  streescans[.]com  5/10/2022  3/4/2025  studiocloud[.]xyz  12/10/2021  5/9/2024  sunmoon[.]website  9/20/2023  9/20/2024  supper.feeee[.]io  2/8/2024  2/8/2025  support.96html[.]com  1/18/2019  1/18/2027*  szxcm-hkg01.iepl.node[.]cm  12/7/2020  1/8/2021  t.checkinfo[.]tk  9/22/2012  12/14/2022  teyan.microscan[.]me  12/10/2017  12/10/2018  tj.twimg.co[.]uk  9/21/2024  12/14/2024  traffic.96html[.]com  1/18/2019  1/18/2027*  trendmicro.96html[.]com  1/18/2019  1/18/2027*  trust[.]feeee  2/8/2024  2/8/2025  tsedws[.]com  6/1/2020  6/1/2026*  txt.studiocloud[.]xyz  12/31/2021  12/3/2024  update.96html[.]com  1/18/2019  1/18/2027*  upgrate.checkapi[.]cf  1/6/2022  4/10/2023  upl.natcloudservice[.]com  9/8/2023  9/8/2024  v3.streescans[.]com  5/10/2022  3/4/2025  vnpt.sexytube0[.]com  10/7/2017  10/8/2027*  vpn21.arforcex[.]com  3/4/2019  3/5/2026*  vpn328433596.softether[.]net   3/28/2023  10/17/2024  vpn614174689.softether[.]net  9/2/2023  9/2/2023  vpn677190427.softether[.]net  4/17/2024  4/30/2024  vpn718535264.softether[.]net  3/11/2022  3/11/2022  vpn823494147.softether[.]net  6/26/2023  6/26/2023  wanfang.accesscam[.]org  9/18/2024  9/26/2024  webdisk.bailbonding[.]info  1/3/2020  1/3/2022  webmail.studiocloud[.]xyz  12/31/2021  12/3/2024  well.96html[.]com  1/18/2019  1/18/2027*  ws.studiocloud[.]xyz  12/31/2021  12/3/2024  wss.studiocloud[.]xyz  12/31/2021  12/3/2024  www.96html[.]com  1/18/2019  1/18/2027*  www.alitagotest[.]cf  1/27/2020  12/7/2021  www.chr0mail[.]com  6/23/2021  6/23/2026*  www.cktime.ooguy[.]com  12/26/2023  7/30/2024  www.dns361[.]tk  2/7/2022  11/19/2023  www.feeee[.]io  2/8/2024  2/8/2025  www.javacheck.ooguy[.]com  6/17/2024  7/25/2024  www.leicc009[.]ga  5/24/2020  4/24/2021  www.msedge[.]store  11/9/2023  11/9/2025  www.mx.sunmoon[.]website  9/20/2023  9/20/2024  www.purple76[.]com  11/11/2021  11/11/2026*  www.smtp.sunmoon[.]website  9/20/2023  9/20/2024  www.sofeter[.]ml  3/13/2023  3/13/2023  www.studiocloud[.]xyz  12/31/2021  12/3/2024  www.sunmoon[.]website  9/20/2023  9/20/2024  www.www.smtp.sunmoon[.]website  9/20/2023  9/20/2024  www.www.sunmoon[.]website  9/20/2023  9/20/2024  xassxxdns.alitagotest[.]cf  1/27/2020  12/7/2021  ximmd.sexytube0[.]com  7/14/2020  10/31/2020  zerogravity1986.softether[.]net  12/9/2023  12/9/2023    Table 11. IP Addresses  IP Address  First Seen  Last Seen  1.34.140[.]5  3/15/2023  3/20/2023  2.58.242[.]74  12/2/2024  12/2/2024  5.188.34[.]134  8/30/2024  9/12/2024  5.188.230[.]69  8/7/2023  4/19/2024  8.219.119[.]5  9/12/2024  9/12/2024  14.1.98[.]160  3/22/2024  4/28/2024  14.128.33[.]8  12/4/2023  1/9/2024  14.1.98[.]223  6/20/2023  10/9/2023  27.154.215[.]126  7/11/2023  7/11/2023  27.154.105[.]36  2/3/2024  2/3/2024  27.149.115[.]78  3/22/2023  3/22/2023  27.149.79[.]35  3/23/2023  3/23/2023  31.232.221[.]35  5/14/2024  5/17/2024  36.112.10[.]102  9/4/2023  9/12/2024  36.112.188[.]119  8/13/2023  8/13/2023  36.112.186[.]135  8/14/2023  8/14/2023  36.112.206[.]121  8/12/2023  8/13/2023  36.249.156[.]117  11/29/2023  11/29/2023  36.249.156[.]122  11/15/2023  11/18/2023  36.249.156[.]159  5/31/2023  6/5/2023  36.249.156[.]178  5/22/2023  12/6/2023  36.249.156[.]205  11/13/2023  11/13/2023  36.249.156[.]206  11/23/2023  11/24/2023  36.249.156[.]220  6/7/2022  6/7/2022  36.249.156[.]226  5/8/2023  5/13/2023  36.112.200[.]35  8/9/2023  8/10/2023  36.249.156[.]51  11/20/2023  11/22/2023  36.112.198[.]68  8/13/2023  8/13/2023  36.249.156[.]69  5/31/2023  5/31/2023  36.112.10[.]99  9/19/2024  9/19/2024  39.72.220[.]221  3/20/2023  3/20/2023  42.73.98[.]232  5/13/2024  5/13/2024  45.123.189[.]19  11/16/2021  2/14/2022  45.32.140[.]182  1/8/2021  1/8/2021  45.32.232[.]146  12/18/2020  12/25/2020  45.63.123[.]142  6/4/2021  7/25/2024  45.63.116[.]190  11/20/2019  11/20/2019  45.131.69[.]197  3/31/2023  3/31/2023  45.76.169[.]12  5/11/2020  5/13/2020  45.77.195[.]169  6/12/2020  6/16/2020  45.32.61[.]246  11/11/2024  12/16/2024  45.77.231[.]209  1/25/2024  6/5/2024  45.76.37[.]168  12/20/2019  12/20/2019  45.63.59[.]121  3/19/2020  3/19/2020  45.77.11[.]47  9/29/2020  9/29/2020  45.32.84[.]223  4/23/2020  5/9/2020  45.63.62[.]217  10/28/2020  11/4/2020  45.63.48[.]36  1/10/2020  1/10/2020  45.76.43[.]37  2/17/2020  2/27/2020  45.76.66[.]19  4/16/2024  5/6/2024  45.76.243[.]67  7/1/2020  7/9/2020  45.63.17[.]9  5/9/2024  6/19/2024  45.77.28[.]77  12/5/2021  4/3/2023  45.76.194[.]89  11/22/2021  9/25/2023  45.76.37[.]85  2/10/2020  2/10/2020  45.63.95[.]62  4/10/2020  4/13/2020  45.63.94[.]71  9/30/2019  12/16/2024  45.77.86[.]70  12/21/2019  12/23/2019  49.93.136[.]14  3/25/2024  3/25/2024  49.93.184[.]194  3/25/2024  3/25/2024  59.120.144[.]153  5/24/2023  5/25/2023  59.124.120[.]178  2/20/2023  9/27/2023  59.120.167[.]25  1/15/2024  1/15/2024  59.125.128[.]54  3/30/2023  10/7/2023  59.120.58[.]176  3/8/2022  3/8/2022  60.250.199[.]112  11/15/2022  12/1/2022  60.250.146[.]19  11/17/2022  12/18/2023  60.251.155[.]19  1/4/2023  9/23/2023  60.248.152[.]204  5/11/2023  5/16/2023  59.120.82[.]67  11/22/2023  1/8/2024  60.184.242[.]224  3/23/2023  3/23/2023  60.251.205[.]37  12/20/2021  12/23/2021  60.220.43[.]193  10/3/2023  10/3/2023  60.251.58[.]145  6/8/2023  1/22/2024  60.248.1[.]64  12/8/2022  4/23/2023  60.251.201[.]8  5/16/2023  3/5/2024  60.248.88[.]151  6/8/2023  2/26/2024  60.248.110[.]97  3/31/2023  1/4/2024  60.249.239[.]86  9/18/2021  1/5/2022  61.220.112[.]137  5/25/2023  5/26/2023  60.220.84[.]41  2/9/2024  2/9/2024  61.247.165[.]27  4/8/2022  4/11/2022  60.220.84[.]63  10/1/2023  10/1/2023  61.220.35[.]15  5/24/2023  9/7/2023  61.221.55[.]4  5/24/2024  11/13/2024  61.222.245[.]73  4/11/2023  7/25/2023  61.219.118[.]99  12/1/2022  11/23/2023  61.216.74[.]97  1/29/2024  1/29/2024  64.176.38[.]35  8/30/2024  12/16/2024  65.20.97[.]251  1/25/2024  6/5/2024  66.42.103[.]188  11/26/2019  11/26/2019  66.42.42[.]109  7/11/2024  8/20/2024  66.42.40[.]189  9/4/2024  12/16/2024  66.42.36[.]236  2/28/2024  7/25/2024  66.42.60[.]242  2/23/2024  12/16/2024  66.42.77[.]138  2/9/2022  6/19/2024  77.111.226[.]5  4/19/2023  4/19/2023  78.141.221[.]241  2/29/2020  3/10/2020  78.141.238[.]97  1/25/2024  6/5/2024  84.17.57[.]40  4/4/2023  4/4/2023  89.187.163[.]216  9/19/2024  9/19/2024  95.179.189[.]106  6/4/2020  6/4/2020  95.179.235[.]135  1/27/2021  1/27/2021  95.179.186[.]251  2/2/2021  2/2/2021  98.159.37[.]4  7/4/2024  7/4/2024  103.107.198[.]117  9/26/2023  9/26/2023  103.16.231[.]220  3/7/2022  7/4/2024  103.16.231[.]254  11/9/2022  2/10/2023  103.233.253[.]197  3/19/2023  9/6/2023  103.25.254[.]210  10/28/2019  11/26/2019  103.149.200[.]44  4/25/2023  10/11/2023  103.179.45[.]203  9/23/2024  12/16/2024  103.73.160[.]232  3/17/2023  3/17/2023  103.77.211[.]193  5/8/2024  5/8/2024  103.106.230[.]88  6/25/2024  6/25/2024  103.172.80[.]35  11/26/2022  11/30/2022  104.238.149[.]146  3/6/2020  7/8/2024  104.238.182[.]153  6/24/2020  7/1/2020  104.238.152[.]209  2/24/2022  4/2/2022  103.51.145[.]98  4/26/2023  5/28/2023  103.73.162[.]99  3/17/2023  11/20/2023  104.156.231[.]98  5/29/2020  6/2/2020  106.53.181[.]231  5/31/2024  5/31/2024  106.122.171[.]92  1/31/2024  1/31/2024  108.61.181[.]104  7/11/2024  12/12/2024  108.61.177[.]81  1/25/2024  6/5/2024  110.42.10[.]148  4/10/2021  5/5/2021  110.85.170[.]125  2/10/2020  2/10/2020  111.203.153[.]245  11/5/2023  11/5/2023  110.74.172[.]80  10/29/2021  2/17/2022  111.55.138[.]141  7/4/2024  7/4/2024  111.55.137[.]40  7/5/2024  7/5/2024  111.203.153[.]95  11/5/2023  11/5/2023  112.5.168[.]102  2/21/2022  2/21/2022  112.5.168[.]104  3/29/2021  3/29/2021  112.5.145[.]154  6/29/2023  6/29/2023  112.5.143[.]161  6/27/2023  6/27/2023  112.5.168[.]138  4/24/2022  4/24/2022  112.5.168[.]151  7/20/2023  8/4/2023  112.5.168[.]160  10/31/2023  11/9/2023  112.54.132[.]162  7/3/2023  7/5/2023  112.5.168[.]187  8/27/2021  8/27/2021  112.5.168[.]218  8/31/2023  9/1/2023  112.5.168[.]231  8/16/2023  8/17/2023  112.5.168[.]234  6/5/2023  6/16/2023  112.5.168[.]238  4/6/2023  5/18/2023  112.51.26[.]151  6/26/2023  6/29/2023  112.66.108[.]16  8/14/2023  8/14/2023  112.5.168[.]29  11/11/2021  11/11/2021  112.51.44[.]102  7/10/2023  7/18/2023  112.51.44[.]142  6/16/2023  6/16/2023  112.51.44[.]143  11/21/2023  11/21/2023  112.51.44[.]188  12/15/2022  12/20/2022  112.51.44[.]189  12/4/2023  12/4/2023  112.51.44[.]20  11/27/2023  11/29/2023  112.51.44[.]206  9/6/2023  9/22/2023  112.51.44[.]217  8/6/2022  8/6/2022  112.51.44[.]234  4/24/2022  5/5/2022  112.5.168[.]65  3/18/2022  3/21/2022  112.51.44[.]37  7/21/2023  8/2/2023  112.80.50[.]138  6/5/2024  6/5/2024  112.51.44[.]57  7/4/2023  7/5/2023  112.5.168[.]93  3/26/2020  3/26/2020  113.76.136[.]171  3/23/2023  3/23/2023  114.246.237[.]111  6/4/2024  6/4/2024  114.255.70[.]18  6/30/2022  9/1/2023  114.255.70[.]20  9/24/2023  7/16/2024  114.255.70[.]30  5/26/2023  7/14/2023  114.246.93[.]103  4/18/2023  4/18/2023  114.246.94[.]102  11/19/2023  1/11/2024  114.35.122[.]83  3/28/2024  12/13/2024  114.246.94[.]154  6/9/2024  6/10/2024  114.246.92[.]58  6/8/2023  6/8/2023  114.246.92[.]71  8/23/2023  9/11/2023  117.133.51[.]176  3/21/2024  3/21/2024  117.61.244[.]135  10/15/2020  10/15/2020  117.56.214[.]246  6/8/2023  7/4/2023  117.132.198[.]70  7/5/2024  7/5/2024  117.92.127[.]132  3/24/2023  3/24/2023  117.130.201[.]90  3/21/2024  3/21/2024  118.163.217[.]199  3/12/2024  4/17/2024  118.163.197[.]241  5/12/2023  10/16/2023  118.163.31[.]226  5/16/2024  5/28/2024  118.163.104[.]67  3/11/2024  12/6/2024  118.163.142[.]80  3/20/2024  3/22/2024  118.163.3[.]76  3/18/2024  10/29/2024  119.116.159[.]217  3/24/2023  3/24/2023  119.13.79[.]145  3/20/2023  3/21/2023  120.233.10[.]212  4/2/2022  4/2/2022  120.36.251[.]100  12/21/2023  12/21/2023  120.36.248[.]104  1/2/2024  1/2/2024  120.42.128[.]165  3/19/2023  3/19/2023  120.36.250[.]103  10/20/2023  5/31/2024  120.36.254[.]100  8/19/2021  8/19/2021  120.36.248[.]109  5/11/2021  5/11/2021  120.36.253[.]106  1/12/2023  1/12/2023  120.36.255[.]105  10/29/2021  11/1/2021  120.36.251[.]110  3/7/2024  3/7/2024  120.36.251[.]11  6/12/2024  6/13/2024  120.36.249[.]114  3/7/2022  3/10/2022  120.36.251[.]114  1/4/2024  1/8/2024  120.36.254[.]112  12/26/2022  12/26/2022  120.36.249[.]121  6/19/2024  6/19/2024  120.36.249[.]122  9/28/2022  9/28/2022  120.36.254[.]119  8/19/2021  8/19/2021  120.36.254[.]120  10/25/2023  10/27/2023  120.36.249[.]127  2/10/2023  2/14/2023  120.36.251[.]130  10/18/2021  10/21/2021  120.36.255[.]127  8/5/2022  8/6/2022  120.36.252[.]13  3/31/2023  3/31/2023  120.36.250[.]133  7/11/2022  7/14/2022  120.36.250[.]134  7/15/2021  7/15/2021  120.36.250[.]135  2/25/2022  3/3/2022  120.36.254[.]131  6/30/2023  6/30/2023  120.36.254[.]135  8/27/2021  8/27/2021  120.36.251[.]141  12/13/2022  12/13/2022  120.36.250[.]142  1/12/2024  1/12/2024  120.41.125[.]225  7/11/2023  7/11/2023  120.36.253[.]148  8/5/2021  8/11/2021  120.36.250[.]152  5/23/2024  5/24/2024  120.36.252[.]151  11/15/2023  11/15/2023  120.36.253[.]152  4/12/2021  5/19/2023  120.36.254[.]151  3/21/2024  3/22/2024  120.36.255[.]153  9/25/2023  9/26/2023  120.36.252[.]157  1/28/2023  1/28/2023  120.37.162[.]246  3/21/2023  3/21/2023  120.36.252[.]166  9/6/2024  9/6/2024  120.36.249[.]172  10/17/2022  10/21/2022  120.36.253[.]169  12/10/2021  12/10/2021  120.36.252[.]175  2/23/2023  2/23/2023  120.36.254[.]175  5/31/2022  5/31/2022  120.36.251[.]179  5/17/2021  5/24/2021  120.36.253[.]178  4/28/2021  4/29/2021  120.36.252[.]18  5/9/2024  5/9/2024  120.36.252[.]181  4/21/2021  4/27/2021  120.36.248[.]185  2/26/2024  2/26/2024  120.36.253[.]180  5/15/2024  5/17/2024  120.36.255[.]179  3/19/2024  3/20/2024  120.36.253[.]186  2/27/2024  3/4/2024  120.36.253[.]187  9/24/2021  9/24/2021  120.36.250[.]19  10/9/2021  10/9/2021  120.36.251[.]19  5/24/2021  5/24/2021  120.36.251[.]190  8/29/2023  8/31/2023  120.36.255[.]189  6/21/2023  6/27/2023  120.41.244[.]15  1/25/2024  1/25/2024  120.36.254[.]192  7/6/2021  7/7/2021  120.36.249[.]197  8/13/2021  8/16/2021  120.36.248[.]200  11/17/2022  11/17/2022  120.36.253[.]195  11/22/2023  11/24/2023  120.36.251[.]2  3/4/2022  3/4/2022  120.36.251[.]20  4/25/2022  4/25/2022  120.36.255[.]196  6/3/2024  6/3/2024  120.36.251[.]202  12/24/2021  12/24/2021  120.36.254[.]202  8/23/2021  8/25/2021  120.36.250[.]207  7/14/2023  7/19/2023  120.36.250[.]210  12/15/2023  12/15/2023  120.36.249[.]213  5/9/2022  5/13/2022  120.36.251[.]213  10/13/2023  10/16/2023  120.36.253[.]212  4/24/2022  4/24/2022  120.36.251[.]215  4/19/2023  4/19/2023  120.36.252[.]215  9/8/2022  9/8/2022  120.36.255[.]214  10/7/2023  10/7/2023  120.36.250[.]221  11/2/2023  11/2/2023  120.36.255[.]22  3/26/2024  3/28/2024  120.36.251[.]230  12/4/2023  12/4/2023  120.36.255[.]228  11/8/2021  11/11/2021  120.36.253[.]23  11/7/2023  11/7/2023  120.36.253[.]231  12/1/2022  12/1/2022  120.36.251[.]234  10/12/2021  10/12/2021  120.36.248[.]237  12/28/2021  12/28/2021  120.36.253[.]232  3/31/2023  3/31/2023  120.36.253[.]233  4/15/2024  4/20/2024  120.36.249[.]238  9/20/2022  9/22/2022  120.36.251[.]237  2/18/2022  2/24/2022  120.36.255[.]233  2/6/2024  2/6/2024  120.36.255[.]237  6/15/2022  6/21/2022  120.36.249[.]245  5/24/2022  5/25/2022  120.36.252[.]242  3/5/2024  3/6/2024  120.36.255[.]24  9/8/2023  9/8/2023  120.36.249[.]248  7/23/2021  7/23/2021  120.36.250[.]247  11/25/2021  11/30/2021  120.36.253[.]247  5/6/2021  5/6/2021  120.36.253[.]248  4/19/2021  4/20/2021  120.36.251[.]25  6/7/2024  6/11/2024  120.36.251[.]254  3/22/2021  3/28/2021  120.36.249[.]28  10/24/2022  10/28/2022  120.36.251[.]3  12/8/2021  12/8/2021  120.36.251[.]30  1/19/2022  1/21/2022  120.36.254[.]3  6/30/2021  7/5/2021  120.36.254[.]32  7/30/2024  7/30/2024  120.36.249[.]33  11/7/2022  11/7/2022  120.36.250[.]4  3/31/2021  3/31/2021  120.36.250[.]43  6/8/2021  6/8/2021  120.36.249[.]47  1/3/2023  1/3/2023  120.36.248[.]48  3/15/2021  3/18/2021  120.36.250[.]48  5/25/2023  5/25/2023  120.36.249[.]52  5/16/2022  5/20/2022  120.36.250[.]53  1/22/2024  1/22/2024  120.36.249[.]54  9/13/2022  9/15/2022  120.36.251[.]54  7/8/2021  7/9/2021  120.36.249[.]55  4/7/2024  4/7/2024  120.36.251[.]56  11/16/2022  11/17/2022  120.36.248[.]57  6/5/2023  6/5/2023  120.36.250[.]58  3/22/2022  3/25/2022  120.36.250[.]6  1/14/2022  1/19/2022  120.36.253[.]6  8/11/2021  8/12/2021  120.36.254[.]63  3/30/2023  6/11/2024  120.36.250[.]65  9/5/2023  9/6/2023  120.36.251[.]65  6/22/2022  6/23/2022  120.36.250[.]67  5/27/2021  5/27/2021  120.36.252[.]69  4/8/2024  4/12/2024  120.36.248[.]73  8/17/2021  8/17/2021  120.36.255[.]74  11/19/2021  11/25/2021  120.36.250[.]76  6/5/2024  6/6/2024  120.41.222[.]74  11/4/2023  11/4/2023  120.36.248[.]80  10/11/2022  10/12/2022  120.36.251[.]80  7/27/2021  7/28/2021  120.36.251[.]84  7/5/2022  7/5/2022  120.36.252[.]90  4/24/2024  4/25/2024  120.36.249[.]91  4/6/2021  4/9/2021  120.36.251[.]91  9/29/2022  9/29/2022  120.36.252[.]91  6/24/2022  6/27/2022  120.36.254[.]92  9/15/2023  9/20/2023  120.36.254[.]94  11/12/2021  11/18/2021  120.36.248[.]97  3/14/2022  3/18/2022  120.36.251[.]97  8/19/2021  8/19/2021  120.36.249[.]98  2/1/2023  2/3/2023  120.36.252[.]98  4/13/2022  4/15/2022  121.207.60[.]123  3/19/2023  3/19/2023  122.116.33[.]118  5/12/2023  3/5/2024  122.232.149[.]231  3/23/2023  3/23/2023  122.201.241[.]230  5/23/2023  8/3/2023  122.116.159[.]52  5/22/2023  9/25/2023  122.116.102[.]93  5/21/2024  5/21/2024  123.121.157[.]240  4/12/2022  4/12/2022  123.51.237[.]194  4/8/2024  11/4/2024  123.252.121[.]7  2/26/2024  3/4/2024  123.252.122[.]7  2/28/2024  3/4/2024  123.12.90[.]227  1/26/2023  1/26/2023  123.60.61[.]104  9/12/2024  9/12/2024  124.126.158[.]130  2/21/2024  2/21/2024  124.126.139[.]199  5/31/2023  5/31/2023  124.127.17[.]171  8/10/2023  8/11/2023  124.127.220[.]223  8/21/2023  8/21/2023  124.150.135[.]3  9/7/2023  9/7/2023  123.51.223[.]96  3/14/2023  4/18/2023  124.64.22[.]13  12/11/2023  12/11/2023  124.126.141[.]74  4/23/2023  4/23/2023  124.127.78[.]22  8/15/2023  8/16/2023  124.127.72[.]52  8/12/2023  8/12/2023  125.227.147[.]106  11/1/2023  12/5/2023  125.227.140[.]168  3/18/2024  11/12/2024  125.227.1[.]220  5/25/2023  11/14/2023  125.227.196[.]157  1/19/2024  1/29/2024  125.227.219[.]145  3/6/2024  7/1/2024  125.228.239[.]13  4/2/2024  12/2/2024  125.227.218[.]2  5/16/2024  5/16/2024  124.64.23[.]80  7/7/2023  7/7/2023  125.229.172[.]48  5/23/2024  5/23/2024  125.227.136[.]60  5/11/2023  2/28/2024  137.220.34[.]137  12/16/2020  12/17/2020  137.220.39[.]222  1/21/2021  1/25/2021  137.220.43[.]47  7/17/2020  7/24/2020  137.220.36[.]87  3/16/2023  7/7/2024  138.199.62[.]148  12/5/2024  12/14/2024  139.180.137[.]219  1/25/2024  6/5/2024  139.180.217[.]19  6/5/2024  6/19/2024  139.180.158[.]51  12/13/2021  7/8/2024  139.84.174[.]129  6/17/2024  12/16/2024  140.82.27[.]163  1/2/2020  1/8/2020  140.82.50[.]151  3/5/2021  3/17/2021  141.164.41[.]128  4/11/2023  7/8/2024  140.82.48[.]6  7/13/2020  7/17/2020  141.164.55[.]227  9/4/2024  12/16/2024  141.164.56[.]93  6/20/2025  6/20/2025  144.202.26[.]205  5/14/2020  5/14/2020  144.34.171[.]162  3/29/2023  11/28/2023  144.202.33[.]164  9/17/2020  9/27/2020  144.202.62[.]109  10/16/2019  10/28/2019  144.202.91[.]107  10/19/2020  10/27/2020  144.202.94[.]216  8/17/2020  8/18/2020  144.202.98[.]41  11/18/2020  11/18/2020  147.139.133[.]246  5/26/2023  6/6/2023  149.28.132[.]137  2/23/2024  7/5/2024  149.28.132[.]161  5/17/2024  7/4/2024  149.28.201[.]146  11/20/2020  12/11/2020  149.28.188[.]184  11/21/2019  11/21/2019  149.248.34[.]100  6/5/2020  6/5/2020  149.28.149[.]29  4/30/2024  4/30/2024  149.28.252[.]19  11/18/2019  11/18/2019  149.248.38[.]179  6/3/2020  6/3/2020  149.248.39[.]202  6/8/2023  2/29/2024  149.248.44[.]191  2/23/2024  5/10/2024  149.248.51[.]22  1/25/2024  6/5/2024  149.28.72[.]106  2/24/2023  3/2/2023  155.138.155[.]170  2/4/2021  2/4/2021  155.138.136[.]190  12/5/2019  12/16/2019  155.138.151[.]225  6/5/2024  6/5/2024  155.138.133[.]56  1/25/2024  6/5/2024  156.146.45[.]152  9/21/2024  9/21/2024  156.146.45[.]194  9/19/2024  9/19/2024  158.247.197[.]28  6/25/2023  9/26/2023  159.138.152[.]61  3/16/2023  3/22/2023  162.14.178[.]86  3/29/2021  5/7/2021  167.172.33[.]16  4/14/2023  4/14/2023  167.179.87[.]215  11/21/2022  6/20/2025  167.179.97[.]121  12/14/2022  3/20/2023  171.120.88[.]137  9/27/2023  9/27/2023  178.62.208[.]162  4/14/2023  4/14/2023  180.122.149[.]177  3/22/2023  3/22/2023  182.34.19[.]234  3/23/2023  3/23/2023  183.240.139[.]216  12/7/2020  1/8/2021  183.253.28[.]104  2/27/2024  2/27/2024  183.253.29[.]110  5/6/2024  5/10/2024  183.253.28[.]121  12/6/2023  12/14/2023  183.250.213[.]20  4/3/2023  4/3/2023  183.253.29[.]189  8/9/2024  8/9/2024  183.250.213[.]55  9/26/2023  10/11/2023  183.253.29[.]66  3/25/2024  3/28/2024  183.253.28[.]67  10/12/2024  10/12/2024  183.250.213[.]80  3/3/2023  3/31/2023  183.250.213[.]83  3/24/2023  3/24/2023  183.166.90[.]97  3/20/2023  3/20/2023  185.216.118[.]71  6/7/2024  7/2/2024  185.135.73[.]192  1/4/2022  1/5/2022  185.213.82[.]239  6/27/2024  7/3/2024  185.213.82[.]243  6/28/2024  6/28/2024  185.213.82[.]55  10/16/2024  10/16/2024  185.213.82[.]65  9/21/2023  9/21/2023  190.92.241[.]15  3/20/2023  3/27/2023  191.232.188[.]144  6/23/2022  6/23/2022  193.42.24[.]68  11/28/2024  11/28/2024  193.42.25[.]73  3/24/2024  7/11/2024  198.13.38[.]211  7/5/2024  7/5/2024  202.182.109[.]151  6/1/2024  9/13/2024  202.101.145[.]22  3/23/2023  3/23/2023  202.182.106[.]31  1/25/2024  7/2/2024  202.39.151[.]239  3/8/2024  12/5/2024  202.99.19[.]250  7/10/2023  7/10/2023  202.99.19[.]254  7/13/2023  7/13/2023  203.74.126[.]20  3/28/2023  3/31/2023  203.69.36[.]122  4/1/2024  12/12/2024  207.246.118[.]144  10/21/2022  12/15/2022  207.246.117[.]149  3/24/2020  3/27/2020  207.246.114[.]173  10/30/2019  10/30/2019  207.148.68[.]131  1/25/2024  6/5/2024  207.148.122[.]69  1/25/2024  6/5/2024  207.148.67[.]146  1/6/2021  1/20/2021  207.246.108[.]64  1/16/2020  1/16/2020  207.246.127[.]64  9/12/2019  9/6/2024  207.148.73[.]238  6/14/2023  9/13/2024  207.148.92[.]220  4/25/2024  7/5/2024  207.148.4[.]96  9/30/2019  5/18/2023  208.72.154[.]55  4/24/2022  5/17/2022  210.242.152[.]155  3/26/2024  12/12/2024  210.242.38[.]241  3/14/2023  1/15/2024  210.243.225[.]41  5/14/2024  11/29/2024  210.66.220[.]39  10/18/2021  10/21/2021  210.242.76[.]32  5/23/2024  5/23/2024  210.71.166[.]50  6/3/2024  6/11/2024  211.20.144[.]116  5/16/2024  5/19/2024  211.20.104[.]187  5/21/2024  5/21/2024  211.21.19[.]11  3/6/2024  4/2/2024  211.22.143[.]228  7/27/2023  7/27/2023  211.20.115[.]60  2/27/2023  3/5/2024  211.20.154[.]60  3/18/2024  4/1/2024  211.20.100[.]78  12/21/2023  12/22/2023  211.20.100[.]79  12/22/2023  12/22/2023  211.99.103[.]102  12/1/2020  12/8/2020  211.21.61[.]46  4/2/2024  4/29/2024  211.75.185[.]37  10/30/2023  1/4/2024  211.99.103[.]243  12/28/2020  1/22/2021  212.107.28[.]16  9/9/2022  9/9/2022  212.107.28[.]22  9/9/2022  9/9/2022  212.107.28[.]23  9/9/2022  9/9/2022  211.78.84[.]17  12/27/2023  12/27/2023  211.20.91[.]77  4/17/2024  4/18/2024  211.99.100[.]90  4/8/2021  4/8/2021  211.99.100[.]91  4/9/2021  4/9/2021  211.99.98[.]197  11/30/2020  11/30/2020  216.128.149[.]106  12/15/2022  2/22/2023  216.128.128[.]238  2/21/2021  2/21/2021  218.26.159[.]254  10/5/2023  10/5/2023  218.5.173[.]137  3/22/2023  3/22/2023  218.5.157[.]171  3/20/2023  3/20/2023  218.66.163.188  3/24/2023  3/24/2023  219.143.179[.]250  7/10/2023  7/13/2023  220.128.108[.]164  10/28/2022  7/19/2023  220.130.153[.]127  4/3/2023  12/18/2023  220.130.176[.]23  12/18/2023  3/1/2024  220.128.125[.]3  3/8/2023  5/9/2023  220.130.254[.]251  12/13/2023  12/13/2023  219.92.229[.]53  5/15/2023  5/15/2023  220.162.9[.]150  3/20/2023  3/23/2023  220.250.44[.]62  6/28/2023  6/29/2023  221.218.143[.]112  2/29/2024  3/11/2024  221.218.136[.]12  7/16/2023  8/9/2023  221.218.138[.]123  5/23/2024  5/23/2024  221.218.143[.]122  6/4/2023  7/3/2023  221.218.143[.]184  7/5/2023  7/12/2023  221.218.136[.]192  10/8/2023  11/15/2023  221.216.116[.]238  4/24/2024  4/24/2024  221.218.137[.]229  6/4/2024  6/4/2024  221.218.139[.]248  1/18/2024  1/24/2024  221.216.208[.]188  6/19/2023  6/19/2023  221.218.142[.]26  5/9/2024  5/13/2024  221.218.141[.]96  4/2/2024  4/3/2024  222.92.153[.]125  6/6/2024  6/6/2024  223.104.40[.]128  4/16/2024  4/16/2024  223.104.41[.]13  4/18/2024  4/18/2024  223.104.40[.]142  4/17/2024  4/17/2024  223.104.40[.]204  4/19/2024  4/19/2024  223.27.34[.]132  4/10/2024  12/13/2024  223.104.55[.]183  7/3/2024  7/3/2024  223.104.39[.]82  7/11/2023  7/11/2023    Table 12 shows observed domain names attributed to this threat activity and obfuscation network hosts.   Table 12. Domain Names Attributed to Threat Activity and Obfuscation Network Hosts  Name  Type  First Seen  Last Seen  96cee[.]com  Infrastructure  6/29/2020  5/9/2024  asean.twimg.co[.]uk  SoftEther Host  9/21/2024  12/15/2024  bj-hk.hmbcloud[.]net  SoftEther Host  3/29/2021  3/29/2021  bj-jp.hmbcloud[.]net  SoftEther Host  4/10/2021  5/7/2021  blog.98aiblog[.]com  SoftEther Host  7/12/2024  8/14/2024  bsnl.twimg.co[.]uk  SoftEther Host  6/17/2024  7/7/2024  dns.studiocloud[.]xyz  Infrastructure  12/10/2021  5/9/2024  eg.twimg.co[.]uk  SoftEther Host  9/22/2024  12/14/2024  etechhosting.twimg.co[.]uk  SoftEther Host  9/21/2024  12/16/2024  fcchk.twimg.co[.]uk  SoftEther Host  9/21/2024  12/14/2024  gz-hk.hmbcloud[.]net  SoftEther Host  12/28/2020  1/22/2021  iplc-hk.hmbcloud[.]com  SoftEther Host  11/30/2020  12/8/2020  javacheck.ooguy[.]com  SoftEther Host  12/22/2023  6/25/2024  javaupdate.giize[.]com  SoftEther Host  12/22/2023  6/15/2024  ls.twimg.co[.]uk  SoftEther Host  9/21/2024  12/14/2024  np.twimg.co[.]uk  SoftEther Host  9/21/2024  11/25/2024  one.hmbiplc-01[.]com  SoftEther Host  4/2/2022  4/2/2022  pw.sexytube0[.]com  SoftEther Host  8/6/2021  4/18/2024  senate.twimg.co[.]uk  SoftEther Host  9/21/2024  12/14/2024  sh-jp.hmbcloud[.]net  SoftEther Host  4/10/2021  4/25/2021  studiocloud[.]xyz  Infrastructure  12/10/2021  5/9/2024  szxcm-hkg01.iepl.node[.]cm  SoftEther Host  12/7/2020  1/8/2021  tj.twimg.co[.]uk  SoftEther Host  9/21/2024  12/14/2024  ximmd.sexytube0[.]com  SoftEther Host  7/14/2020  10/31/2020    Table 13 contains known webshells from the threat actor’s repository of CNE tooling, which may appear on a compromised system. The threat actors have used these webshell files for unauthorized access to victim environments.  Table 13. Leveraged Webshells  Name  Hashes  b374.php  MD5: 48ca18a25424a0f52276290b619a7a83  SHA-256: 72c6af6a4be99e31c4a7a0aa4f01750792788e7f6f9749243a9f2c47c14a708f  back.pl  MD5: 38f5ff8169423e2c756848c02e8cac3b  SHA-256: 456586ababa08f70216c4459f4d6375676166ebfddd98a33b447ceb5099e8dc5  error.jsp  MD5: d61326c4e6d24aa9b67e2b7a3ef7cedf  SHA-256: 2f5c406eb64ad8902c8e30610d43fd3efc05a14cdb8fb158818953eaf3dc6a81  file_back. aspx  MD5: f8de2e99dc7523d2c83d1a48e844c5ff  SHA-256: 5782ff2c835c88cc1ee521d2e8c523cfad73db3f9a29c93b40c4223f0338ade9  gf.phtml  MD5: 5b5a2c7fa705d8b1eb04da5db900b0d7  SHA-256: 0e6fecb2d369b0eae63731616a3daada52036634885ab1b85b115af6bc5bcb86  yaml-payload.jar  MD5: 655cd134976d3e80c521708aa8be418b  SHA-256: 36f3b7645609ef40444dbc68f01d26c543d67689eda4937272ea5cfa4df1b522    Table 14 contains known binaries and scripts from the threat actor’s repository of CNE tooling. The threat actors used these utilities to perform various scanning or computer intrusion tasks.   Table 14. Leveraged Binaries and Scripts  Name  Category  Hashes  ksubdomain  Enumeration  MD5: dae8f50ea44225fae3ba1f160b42bfdc  SHA-256: 670fa10a2ddde21fd594c4fef86b554d864089ed2de7153b472e921c623403ae  ksubdomain_linux  Enumeration  MD5: fdece34bc084f1e252aeae274650eb8d  SHA-256: 645f6f2667af01a94d04a9d7a71916a13d9426835d636b4ceee2e25ccb34e525  oneforall.py  Enumeration  MD5: 596b990b0b389d906a8f4384837c1878  SHA-256: 4d488f21269b18e37aaca93ac2a61707c9b611e506cdb3b287277746e94636b5  subDomainsBrute.py  Enumeration  MD5: a73eca669fe80628dbbd2c7d9bb14c8f  SHA-256: a14844e982f172d0f23910558c3f390a9d4c45dc32db825c2af7cf0ed8631db2  office-cli  Information dump  MD5: be121e707f817aa9392c55af1e7ec2aa  SHA-256: add7dd142e4f7e2873bc8f7b7fb6308063608e0b49a773dea93abad4047f1489  JuicyPotato.exe  Privilege escalation  MD5: 7ce68f0dd85355ba2897a68521167e56  SHA-256: e7e727458f573dded05537baddac2867d2801db1c3c74410398d063dfd6f6575  BBScan.py  Scanning  MD5: f82694de2f19e1bff333c27bb7eb7a56  SHA-256: 8e1b56ef51ba70aa4c4cfd4430820f20875b354588d5d723ba4d3940ea6c924b  dirmap.py  Scanning  MD5: 1933c314041415939331fce183939547  SHA-256: 46e59172c40c95d83c3a6f24f801fc2265653c8b575b66a726463e2a4eebd7f2  dirsearch.py  Scanning  MD5: 8829f6f1cc5fc0aab2f6e71bfd7dc53d  SHA-256: 752b14c6e6936991d51fcd5ebf40d303e657c2372893604f96044848ad9a5f24  fscan.exe  Scanning  MD5: cf903e4a1629aa0582fd0363b5786676  SHA-256: 7b9efc7ef8957411cdd22582ce4bfb3a5f76d9c91cdb7e36bf85c9785a2480e9  nbtscan.exe  Scanning  MD5: f01a9a2d1e31332ed36c1a4d2839f412  SHA-256: c9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e  nbtscan_linux  Scanning  MD5: ef713447f18f5b7ee16af4ac37ec4133  SHA-256: 2fbcb1995c458e5affd5fb8f1f979a08ddce21714a2e413aa3d5dc44f9f245fe  PackerFuzzer.py   Scanning  MD5: 8dcc4f9ccc6b6adf7eeeb3f51c95afad  SHA-256: 33790218d5871af646feef5be29e0596d4703a45ce675c1eb2ca00140b3a1bde  ShuiZe.py  Scanning  MD5: b04375cca637f0702bf27feaff22a92d  SHA-256: c7f86a4623db5c90273cea041d43207849c5c6b0060c370b2095f13871b1366d  sqlmap.py  Scanning  MD5: bcacc7ca999980d26c186ef791242fb5  SHA-256: 2ecb51d7fa3bc3fa7ad7df64c6d0cd1f4ff2b37ed6839d3cff529fb08af49fb0  wpscan  Scanning  MD5: 1b8e29b6b7972fb124425aaa257f8f6d  SHA-256: efb0437e6a6a0f07169952f1a8b734299ec9a8b1faadbed811fe017f2cf54976    Table 15 contains known files that the threat actors dropped onto victim systems and used to install unauthorized software, dump sensitive information, or enable other follow-on activity from within a victim’s network.  Table 15. Potentially Dropped Files  Name  Category  Hashes  curlc4.txt  Malware  MD5: 4f61b9ab907f351bb40b37b10f4974d0  SHA-256: 8b869a5edaff74ff18bca3658a519a19771e66d00ff7849af7a142dd6fc8da85  DiagTrack.exe   Malware  MD5: 6d57c42dee8bd7789969e2dd28671162  SHA-256: 804a53be802378a8ec4c94602fd3d6584e0d472d83148e8a42c731950fec415d  live700_v1.exe  Malware  MD5: 776807750280daad05348f931a33e4ef  SHA-256: c4503db6ece93eddf4511e787607cb14606a1df9f526f1e39992497119437cec  conhost.exe  SoftEther  MD5: a973c0ab904c1b74655a906b99b76850  SHA-256: b1552703ff0035f197c22cdb3a514bb6aa45ec98de3ef5409faab0978f18c35e  dllhost.exe  SoftEther  MD5: f62cbbbdf35c7790909c26c7c5fbce05  SHA-256: 8a592e22c51311d482272ec5aba0103c9cd0cfd78e5b5ba75dfa8f1c56926672  dllhost.exe  SoftEther  MD5: a05cdf6afcbb107961307f59cbab5e4f  SHA-256: 86f1cfa6a2e0a8cb6fc1fbee28472308e6467932f8658a6a4885e29ed8c34a67  b.exe  Information dump  MD5: 7d5a182f70bed0e4fa2f8615aba070de  SHA-256: e93244080a749b521f63476343ce3c81cc8c1b672fa0d9e67359aee37544c784  dc.exe  Information dump  MD5: 1bcaef76b2063f1b80b0fa0d277ec9c5  SHA-256: 9dc85f9569a15eaf51c7d34254767ea30dd67b2178cec4cc7125288b9544fe00  secretsdump.exe  Information dump  MD5: 4d33bfb75e27fefaa72526899604d557  SHA-256: 644decbc6ce8c52382f4755fa6fc2cb4d89a0e7ec0e574c11b398a6f2eed04b1  secretsdump.py  Information dump  MD5: fc6e8ca41cf4f6100177352660e520b4  SHA-256: 67db57a1f957031b78f29aa91e2e87780eae3835290259eff846d8f14afb794b    Appendix B: Observed Common Vulnerabilities and Exposures Table 16 displays successfully exploited common vulnerabilities and exposures (CVEs). The asterisk (*) indicates CVEs that were newly added to CISA’s Known Exploited Vulnerabilities (KEV) Catalog.  Table 16. Successfully Exploited CVEs  CVE  Vendor  Product  Versions Affected  Vulnerability Type  CVE-2014-6278 [Common Weakness Enumeration (CWE)-78: Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’)]  GNU  Bash  Through 4.3 bash43-026  Remote code execution  CVE-2015-3306* [CWE-284: Improper Access Control]  ProFTPD  Proftpd  1.3.5  Unauthorized read  CVE-2015-5477* [CWE-19: Data Processing Errors]  ISC  BIND 9.x  Before 9.9.7-P2 and 9.10.x before 9.10.2-P3  Denial of service  CVE-2016-3081* [CWE-77: Improper Neutralization of Special Elements used in a Command (‘Command Injection’)]  Apache  Struts  2.3.19 to 2.3.20.2, 2.3.21 to 2.3.24.1, and 2.3.25 to 2.3.28  Remote code execution  CVE-2019-11510 [CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)]  Pulse Secure  Pulse Connect Secure  8.2 before 8.2R12.1, 8.3 before 8.3R7.1, and 9.0 before 9.0R3.4  Unauthorized read  CVE-2021-22205 [CWE-94: Improper Control of Generation of Code (‘Code Injection’)]  GitLab  GitLab  All versions starting from 11.9  Remote code execution  CVE-2021-3199* [CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’)]  ONLYOFFICE  DocumentServer  5.1.5 through 5.6.2  Unauthorized write  CVE-2023-22894* [CWE-312: Cleartext Storage of Sensitive Information]  Strapi  Strapi  Up to 4.5.5  Information disclosure  CISA is committed to providing access to our web pages and documents for individuals with disabilities, both members of the public and federal employees. If the format of any elements or content within this document interferes with your ability to access the information, as defined in the Rehabilitation Act, please email Central@cisa.dhs.gov. To enable us to respond in a manner most helpful to you, please indicate the nature of your accessibility problem and the preferred format in which to receive the material.

Read full story at CISA Advisories →