Overview 38 indicators
No published description. This group is tracked by Maltrail from vendor reporting but is not named in MITRE ATT&CK, so there is no curated profile to show.
| domain | 30 | CALYPSO-domain.txt |
| url | 5 | CALYPSO.json |
| ipv4 | 3 | CALYPSO.json |
Principal sources 10 reports
Ranked by how many of this actor's indicators each report brought in.
- 17ptsecurity.com/ww-en/analytics/calypso-apt-2019
- 17virustotal.com/gui/ip-address/46.105.227.110/relations
- 17virustotal.com/gui/file/a32b3e0f9b0daaaea6ddda9875f463…
- 17virustotal.com/gui/file/aea4d3d01ab9a564ca12af0d1a8b5e…
- 12st.drweb.com/static/new-www/news/2022/march/telecom_…
- 12otx.alienvault.com/pulse/6267dbe17cdc91a784b256d6
- 9recordedfuture.com/chinese-group-calypso-exploiting-micros…
- 9otx.alienvault.com/pulse/60638f7aff63f9956797e899
Related groups 1
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 38 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
st.drweb.com/static/new-www/news/2022/march/telecom_… · otx.alienvault.com/pulse/6267dbe17cdc91a784b256d6
blog.globnewsline.com clark.l8t.net mail.sultris.com pop3.wordmoss.com surfanny.com webmail.surfanny.com wordmoss.com youtubemail.club zmail.wordmoss.com -
ptsecurity.com/ww-en/analytics/calypso-apt-2019 · virustotal.com/gui/ip-address/46.105.227.110/relations · virustotal.com/gui/file/a32b3e0f9b0daaaea6ddda9875f463… · virustotal.com/gui/file/aea4d3d01ab9a564ca12af0d1a8b5e…
etheraval.com streleases.com teldcomtv.com -
twitter.com/TI_ESC/status/1264843775232421888 · ptsecurity.com/upload/corporate/ww-en/analytics/calyps…
usergetacss.com -
st.drweb.com/static/new-www/news/2022/march/telecom_… · otx.alienvault.com/pulse/6267dbe17cdc91a784b256d6
globnewsline.com mail.globnewsline.com -
recordedfuture.com/chinese-group-calypso-exploiting-micros… · otx.alienvault.com/pulse/60638f7aff63f9956797e899
aztecoo.com draconess.com membrig.com prowesoo.com rawfuns.com rosyfund.com waxgon.com yolkish.com -
twitter.com/TI_ESC/status/1264843775232421888 · ptsecurity.com/upload/corporate/ww-en/analytics/calyps…
uv.usergetacss.com -
ptsecurity.com/ww-en/analytics/calypso-apt-2019 · virustotal.com/gui/ip-address/46.105.227.110/relations · virustotal.com/gui/file/a32b3e0f9b0daaaea6ddda9875f463… · virustotal.com/gui/file/aea4d3d01ab9a564ca12af0d1a8b5e…
domain dealsgle.com domain krgod.qqm8.com domain r01.etheraval.com domain tc.streleases.com domain tv.teldcomtv.com ipv4 103.224.82.47:321 ipv4 103.224.82.47:445 ipv4 46.105.227.110:7003 url http://23.227.207.137 url http://36.44.74.47 url http://45.63.114.127 url http://45.63.96.120 url http://46.166.129.241 -
ptsecurity.com/ww-en/analytics/calypso-apt-2019 · virustotal.com/gui/ip-address/46.105.227.110/relations · virustotal.com/gui/file/a32b3e0f9b0daaaea6ddda9875f463… · virustotal.com/gui/file/aea4d3d01ab9a564ca12af0d1a8b5e… · recordedfuture.com/chinese-group-calypso-exploiting-micros… · otx.alienvault.com/pulse/60638f7aff63f9956797e899 · st.drweb.com/static/new-www/news/2022/march/telecom_… · otx.alienvault.com/pulse/6267dbe17cdc91a784b256d6
sultris.com
Further reading 10
- recordedfuture.com/chinese-group-calypso-exploiting-micros…
- virustotal.com/gui/file/aea4d3d01ab9a564ca12af0d1a8b5e…
- virustotal.com/gui/ip-address/46.105.227.110/relations
- ptsecurity.com/ww-en/analytics/calypso-apt-2019
- virustotal.com/gui/file/a32b3e0f9b0daaaea6ddda9875f463…
- st.drweb.com/static/new-www/news/2022/march/telecom_…
- twitter.com/TI_ESC/status/1264843775232421888
- otx.alienvault.com/pulse/6267dbe17cdc91a784b256d6
- otx.alienvault.com/pulse/60638f7aff63f9956797e899
- ptsecurity.com/upload/corporate/ww-en/analytics/calyps…