Overview 17 indicators
APT18 is a threat group that has operated since at least 2009 and has targeted a range of industries, including technology, manufacturing, human rights groups, government, and medical.
| domain | 14 | G0026-domain.txt |
| url | 2 | G0026.json |
| ipv4 | 1 | G0026.json |
Techniques 12 ATT&CK
Open in ATT&CK Navigator → or download the layer (12 techniques, layer 4.5)
- T1027.013 Encrypted/Encoded File
- T1053.002 At
- T1059.003 Windows Command Shell
- T1070.004 File Deletion
- T1071.001 Web Protocols
- T1071.004 DNS
- T1078 Valid Accounts
- T1082 System Information Discovery
- T1083 File and Directory Discovery
- T1105 Ingress Tool Transfer
- T1133 External Remote Services
- T1547.001 Registry Run Keys / Startup Folder
Software 5
Principal sources 4 reports
Ranked by how many of this actor's indicators each report brought in.
- 17fireeye.com/blog/threat-research/2015/07/demonstrat…
- 17github.com/fireeye/iocs/blob/master/APT18/0ae061d7…
- 17virustotal.com/gui/ip-address/137.175.4.132/relations
- 17virustotal.com/gui/ip-address/223.25.233.248/relations
Related groups 3
What the sources have in common — not a claim that these are the same actor. See the whole graph.
Timeline 17 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
fireeye.com/blog/threat-research/2015/07/demonstrat… · github.com/fireeye/iocs/blob/master/APT18/0ae061d7… · virustotal.com/gui/ip-address/137.175.4.132/relations · virustotal.com/gui/ip-address/223.25.233.248/relations
domain 128.er1620.com domain 223-25-233-248.revdns.8toinfinity.com.sg domain admin.er1620.com domain exp0day.com domain ftp.exp0day.com domain gmail.bkz88.com domain hello.mjw.bz domain info.imly.org domain login.3bz.org domain logo.mjw.bz domain suck.er1620.com domain test.3bz.org ipv4 223.25.233.248:8080 url http://137.175.4.132 url http://223.25.233.248 -
fireeye.com/blog/threat-research/2015/07/demonstrat… · github.com/fireeye/iocs/blob/master/APT18/0ae061d7… · virustotal.com/gui/ip-address/137.175.4.132/relations · virustotal.com/gui/ip-address/223.25.233.248/relations
good.myftp.org zip.redirectme.net
Further reading 8
- secureworks.com/resources/blog/where-you-at-indicators-…
- attack.mitre.org/groups/G0026
- anomali.com/blog/evasive-maneuvers-the-wekby-group-…
- threatstream.com/blog/evasive-maneuvers-the-wekby-group-…
- fireeye.com/blog/threat-research/2015/07/demonstrat…
- github.com/fireeye/iocs/blob/master/APT18/0ae061d7…
- virustotal.com/gui/ip-address/223.25.233.248/relations
- virustotal.com/gui/ip-address/137.175.4.132/relations