Add Proofpoint's report on TA406

This commit is contained in:
Jan Gru 2021-11-19 08:04:21 +01:00
parent 5f22c8dfd7
commit db18f8bb5f
2 changed files with 154 additions and 0 deletions

@ -0,0 +1,154 @@
IoC,Type
acount-pro[.]club,Domain
acount-pro[.]live,Domain
anlysis-info[.]xyz,Domain
asia-studies[.]net,Domain
bignaver[.]com,Domain
carnegieinsider[.]com,Domain
change-pw[.]com,Domain
clonesec[.]us,Domain
cloudnaver[.]com,Domain
cloudocument[.]com,Domain
cloudsecurityservice[.]net,Domain
dailycloudservice[.]com,Domain
daumhelp[.]net,Domain
daum-protect[.]com,Domain
deioncube[.]biz,Domain
delivernaver[.]com,Domain
delivers-security[.]com,Domain
delivers-security[.]net,Domain
diplomatictraining[.]com,Domain
document-package[.]online,Domain
documentpackages[.]link,Domain
documentpackages[.]online,Domain
documentpackage[.]space,Domain
documentpackages[.]space,Domain
documentpackages[.]store,Domain
documentserver[.]site,Domain
down-error[.]com,Domain
download-apks[.]com,Domain
downloader-hanmail[.]net,Domain
download-live[.]com,Domain
emailnaver[.]com,Domain
globalcloudservices[.]org,Domain
gooapi[.]online,Domain
google-acount[.]com,Domain
goolg-e[.]com,Domain
goolge[.]space,Domain
govermentweb[.]site,Domain
help-master[.]online,Domain
helpnaver[.]host,Domain
helpnaver[.]link,Domain
helpnaver[.]online,Domain
help-naver[.]site,Domain
helpnaver[.]site,Domain
help-secure[.]info,Domain
hpronto-login[.]com,Domain
itamaraty[.]net,Domain
knowledgeofworld[.]org,Domain
lnfo-master[.]com,Domain
login-protect[.]club,Domain
login-protect[.]online,Domain
mail-master[.]online,Domain
mail[.]summitz[.]com,Domain
microsoft-pro[.]host,Domain
microsoft-pro[.]live,Domain
microsoft-pro[.]site,Domain
microsoft-pro[.]space,Domain
midsecurity[.]org,Domain
mid-service[.]com,Domain
mid-service[.]org,Domain
myethrvvallet[.]com,Domain
mysoftazure[.]com,Domain
naverhelp[.]com,Domain
naversecurity[.]us,Domain
nicnaver[.]com,Domain
nidnaver[.]host,Domain
nidnaver[.]press,Domain
nidnaver[.]site,Domain
nidnaver[.]store,Domain
noreply-cc[.]online,Domain
noreply-goolge[.]com,Domain
noreply-sec[.]online,Domain
noreply-yahoo[.]com,Domain
oaass-torrent[.]com,Domain
proattachfile[.]com,Domain
pronto-login[.]info,Domain
pw-change[.]com,Domain
resetpolicy[.]com,Domain
resetprofile[.]com,Domain
rfa[.]news,Domain
rnaii[.]com,Domain
rnail-inbox[.]com,Domain
rnailm[.]com,Domain
rnail-suport[.]site,Domain
rneail[.]com,Domain
secureaction[.]ru,Domain
securelevel[.]site,Domain
security-acount[.]info,Domain
securitycounci1report[.]org,Domain
security-delivers[.]com,Domain
securityforcastreport[.]com,Domain
security-lnfo[.]com,Domain
security-nid[.]space,Domain
security-pro[.]me,Domain
security-pro[.]online,Domain
securitysettings[.]info,Domain
seoulhobi[.]biz,Domain
servicenaver[.]com,Domain
servicenidnaver[.]com,Domain
sinoforecast[.]com,Domain
softfilemanage[.]com,Domain
ssidnaver[.]com,Domain
stategov[.]biz,Domain
support-info[.]network,Domain
unosa[.]org,Domain
voakorea[.]news,Domain
voakoreas[.]com,Domain
voipgoogle[.]com,Domain
vpsino[.]org,Domain
webofknowledg[.]com,Domain
xfindphoneloc[.]com,Domain
xn--mcrosoft-online-hic[.]com,Domain
0member-services[.]hol[.]es,Domain
attachdown[.]000webhostapp[.]com,Domain
attachdownload[.]000webhostapp[.]com,Domain
attachdownload[.]99on[.]com,Domain
dnsservice[.]esy[.]es,Domain
emailru[.]99on[.]com,Domain
firefox-plug[.]c1[.]biz,Domain
koryogroup[.]1apps[.]com,Domain
lookyes[.]c1[.]biz,Domain
north-korea[.]medianewsonline[.]com,Domain
online-manual[.]c1[.]biz,Domain
romanovawillkillyou[.]c1[.]biz,Domain
securitydownload[.]99on[.]com,Domain
silverlog[.]hol[.]es,Domain
softlay-ware[.]c1[.]biz,Domain
takemetoyouheart[.]c1[.]biz,Domain
taketodjnfnei898[.]c1[.]biz,Domain
taketodjnfnei898[.]ueuo[.]com,Domain
upsrv[.]16mb[.]com,Domain
vscode-plug[.]c1[.]biz,Domain
win10-ms[.]c1[.]biz,Domain
1006ieudneu[.]atwebpages[.]com,Domain
1995ieudneu[.]atwebpages[.]com,Domain
fd-com[.]fr,Compromised Infrastructure
influencer[.]jvproduccionessv[.]com,Compromised Infrastructure
mail[.]apm[.]co[.]kr,Compromised Infrastructure
oaass[.]co[.]kr,Compromised Infrastructure
rabadaun[.]com,Compromised Infrastructure
simple[.]kswebdesign[.]eu,Compromised Infrastructure
www[.]acl-medias[.]fr,Compromised Infrastructure
u13448720[.]ct[.]sendgrid[.]net,SendGrid Hostnames
u19402039[.]ct[.]sendgrid[.]net,SendGrid Hostnames
u7747409[.]ct[.]sendgrid[.]net,SendGrid Hostnames
u8253848[.]ct[.]sendgrid[.]net,SendGrid Hostnames
u9810308[.]ct[.]sendgrid[.]net,SendGrid Hostnames
222.118.183[.]131,Email Sending Infrastructure (March 2021)
192.109.119[.]6,Email Sending Infrastructure (April 2021)
108.177.235[.]226,Email Sending Infrastructure (May 2021)
108.62.12[.]11,Email Sending Infrastructure (May 2021)
212.114.52[.]227,Email Sending Infrastructure (July 2021)
de1d1931f2e821209f1508e4b7306e7eef296a42f21fe9784e22cf4670acd296,YoreKey
347fdbd435f044fb1209125b22aaac5a9d826cfe5e5d543b190dc904cdd371c3,YoreKey
1 IoC Type
2 acount-pro[.]club Domain
3 acount-pro[.]live Domain
4 anlysis-info[.]xyz Domain
5 asia-studies[.]net Domain
6 bignaver[.]com Domain
7 carnegieinsider[.]com Domain
8 change-pw[.]com Domain
9 clonesec[.]us Domain
10 cloudnaver[.]com Domain
11 cloudocument[.]com Domain
12 cloudsecurityservice[.]net Domain
13 dailycloudservice[.]com Domain
14 daumhelp[.]net Domain
15 daum-protect[.]com Domain
16 deioncube[.]biz Domain
17 delivernaver[.]com Domain
18 delivers-security[.]com Domain
19 delivers-security[.]net Domain
20 diplomatictraining[.]com Domain
21 document-package[.]online Domain
22 documentpackages[.]link Domain
23 documentpackages[.]online Domain
24 documentpackage[.]space Domain
25 documentpackages[.]space Domain
26 documentpackages[.]store Domain
27 documentserver[.]site Domain
28 down-error[.]com Domain
29 download-apks[.]com Domain
30 downloader-hanmail[.]net Domain
31 download-live[.]com Domain
32 emailnaver[.]com Domain
33 globalcloudservices[.]org Domain
34 gooapi[.]online Domain
35 google-acount[.]com Domain
36 goolg-e[.]com Domain
37 goolge[.]space Domain
38 govermentweb[.]site Domain
39 help-master[.]online Domain
40 helpnaver[.]host Domain
41 helpnaver[.]link Domain
42 helpnaver[.]online Domain
43 help-naver[.]site Domain
44 helpnaver[.]site Domain
45 help-secure[.]info Domain
46 hpronto-login[.]com Domain
47 itamaraty[.]net Domain
48 knowledgeofworld[.]org Domain
49 lnfo-master[.]com Domain
50 login-protect[.]club Domain
51 login-protect[.]online Domain
52 mail-master[.]online Domain
53 mail[.]summitz[.]com Domain
54 microsoft-pro[.]host Domain
55 microsoft-pro[.]live Domain
56 microsoft-pro[.]site Domain
57 microsoft-pro[.]space Domain
58 midsecurity[.]org Domain
59 mid-service[.]com Domain
60 mid-service[.]org Domain
61 myethrvvallet[.]com Domain
62 mysoftazure[.]com Domain
63 naverhelp[.]com Domain
64 naversecurity[.]us Domain
65 nicnaver[.]com Domain
66 nidnaver[.]host Domain
67 nidnaver[.]press Domain
68 nidnaver[.]site Domain
69 nidnaver[.]store Domain
70 noreply-cc[.]online Domain
71 noreply-goolge[.]com Domain
72 noreply-sec[.]online Domain
73 noreply-yahoo[.]com Domain
74 oaass-torrent[.]com Domain
75 proattachfile[.]com Domain
76 pronto-login[.]info Domain
77 pw-change[.]com Domain
78 resetpolicy[.]com Domain
79 resetprofile[.]com Domain
80 rfa[.]news Domain
81 rnaii[.]com Domain
82 rnail-inbox[.]com Domain
83 rnailm[.]com Domain
84 rnail-suport[.]site Domain
85 rneail[.]com Domain
86 secureaction[.]ru Domain
87 securelevel[.]site Domain
88 security-acount[.]info Domain
89 securitycounci1report[.]org Domain
90 security-delivers[.]com Domain
91 securityforcastreport[.]com Domain
92 security-lnfo[.]com Domain
93 security-nid[.]space Domain
94 security-pro[.]me Domain
95 security-pro[.]online Domain
96 securitysettings[.]info Domain
97 seoulhobi[.]biz Domain
98 servicenaver[.]com Domain
99 servicenidnaver[.]com Domain
100 sinoforecast[.]com Domain
101 softfilemanage[.]com Domain
102 ssidnaver[.]com Domain
103 stategov[.]biz Domain
104 support-info[.]network Domain
105 unosa[.]org Domain
106 voakorea[.]news Domain
107 voakoreas[.]com Domain
108 voipgoogle[.]com Domain
109 vpsino[.]org Domain
110 webofknowledg[.]com Domain
111 xfindphoneloc[.]com Domain
112 xn--mcrosoft-online-hic[.]com Domain
113 0member-services[.]hol[.]es Domain
114 attachdown[.]000webhostapp[.]com Domain
115 attachdownload[.]000webhostapp[.]com Domain
116 attachdownload[.]99on[.]com Domain
117 dnsservice[.]esy[.]es Domain
118 emailru[.]99on[.]com Domain
119 firefox-plug[.]c1[.]biz Domain
120 koryogroup[.]1apps[.]com Domain
121 lookyes[.]c1[.]biz Domain
122 north-korea[.]medianewsonline[.]com Domain
123 online-manual[.]c1[.]biz Domain
124 romanovawillkillyou[.]c1[.]biz Domain
125 securitydownload[.]99on[.]com Domain
126 silverlog[.]hol[.]es Domain
127 softlay-ware[.]c1[.]biz Domain
128 takemetoyouheart[.]c1[.]biz Domain
129 taketodjnfnei898[.]c1[.]biz Domain
130 taketodjnfnei898[.]ueuo[.]com Domain
131 upsrv[.]16mb[.]com Domain
132 vscode-plug[.]c1[.]biz Domain
133 win10-ms[.]c1[.]biz Domain
134 1006ieudneu[.]atwebpages[.]com Domain
135 1995ieudneu[.]atwebpages[.]com Domain
136 fd-com[.]fr Compromised Infrastructure
137 influencer[.]jvproduccionessv[.]com Compromised Infrastructure
138 mail[.]apm[.]co[.]kr Compromised Infrastructure
139 oaass[.]co[.]kr Compromised Infrastructure
140 rabadaun[.]com Compromised Infrastructure
141 simple[.]kswebdesign[.]eu Compromised Infrastructure
142 www[.]acl-medias[.]fr Compromised Infrastructure
143 u13448720[.]ct[.]sendgrid[.]net SendGrid Hostnames
144 u19402039[.]ct[.]sendgrid[.]net SendGrid Hostnames
145 u7747409[.]ct[.]sendgrid[.]net SendGrid Hostnames
146 u8253848[.]ct[.]sendgrid[.]net SendGrid Hostnames
147 u9810308[.]ct[.]sendgrid[.]net SendGrid Hostnames
148 222.118.183[.]131 Email Sending Infrastructure (March 2021)
149 192.109.119[.]6 Email Sending Infrastructure (April 2021)
150 108.177.235[.]226 Email Sending Infrastructure (May 2021)
151 108.62.12[.]11 Email Sending Infrastructure (May 2021)
152 212.114.52[.]227 Email Sending Infrastructure (July 2021)
153 de1d1931f2e821209f1508e4b7306e7eef296a42f21fe9784e22cf4670acd296 YoreKey
154 347fdbd435f044fb1209125b22aaac5a9d826cfe5e5d543b190dc904cdd371c3 YoreKey