Overview 60 indicators
Lotus Blossom is a long-standing threat group largely targeting various entities in Asia since at least 2009. In addition to government and related targets, Lotus Blossom has also targeted entities such as digital certificate issuers.
| domain | 51 | G0030-domain.txt |
| ipv4 | 5 | G0030.json |
| url | 3 | G0030.json |
| url_path | 1 | G0030.json |
Techniques 21 ATT&CK
Open in ATT&CK Navigator → or download the layer (21 techniques, layer 4.5)
- T1012 Query Registry
- T1016 System Network Configuration Discovery
- T1016.001 Internet Connection Discovery
- T1018 Remote System Discovery
- T1046 Network Service Discovery
- T1047 Windows Management Instrumentation
- T1049 System Network Connections Discovery
- T1074.001 Local Data Staging
- T1083 File and Directory Discovery
- T1087.001 Local Account
- T1087.002 Domain Account
- T1090.001 Internal Proxy
- T1090.003 Multi-hop Proxy
- T1112 Modify Registry
- T1134 Access Token Manipulation
- T1482 Domain Trust Discovery
- T1539 Steal Web Session Cookie
- T1543.003 Windows Service
- T1560.001 Archive via Utility
- T1560.003 Archive via Custom Method
- T1588.002 Tool
Software 9
Principal sources 17 reports
Ranked by how many of this actor's indicators each report brought in.
- 34paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/…
- 18x.com/cyb3rops/status/2018253965645766993
- 18x.com/cyb3rops/status/2018361184626356411
- 18x.com/ValidinLLC/status/2018680305364685102
- 18notepad-plus-plus.org/news/hijacked-incident-info-update
- 18rapid7.com/blog/post/tr-chrysalis-backdoor-dive-in…
- 18validin.com/blog/exploring_notepad_plus_plus_networ…
- 18securelist.com/notepad-supply-chain-attack/118708
Timeline 60 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/cyb3rops/status/2018253965645766993 · x.com/cyb3rops/status/2018361184626356411 · x.com/ValidinLLC/status/2018680305364685102 · notepad-plus-plus.org/news/hijacked-incident-info-update · rapid7.com/blog/post/tr-chrysalis-backdoor-dive-in… · validin.com/blog/exploring_notepad_plus_plus_networ… · securelist.com/notepad-supply-chain-attack/118708 · virustotal.com/gui/ip-address/160.250.93.48/relations · virustotal.com/gui/file/e7cd605568c38bd6e0aba31045e163… · virustotal.com/gui/file/0755d2dc99c0a44f4e5435c398d9af… · virustotal.com/gui/file/0a9b8df968df41920b6ff07785cbfe… · virustotal.com/gui/file/7f2e0f51e83d6cf9c50922f898126b… · virustotal.com/gui/file/f365cfbca03a28a7692308c9766f8a… · virustotal.com/gui/file/b4169a831292e245ebdffedd582058… · virustotal.com/gui/file/fcc2765305bcd213b7558025b2039d…
safe-dns.it.com -
x.com/cyb3rops/status/2018253965645766993 · x.com/cyb3rops/status/2018361184626356411 · x.com/ValidinLLC/status/2018680305364685102 · notepad-plus-plus.org/news/hijacked-incident-info-update · rapid7.com/blog/post/tr-chrysalis-backdoor-dive-in… · validin.com/blog/exploring_notepad_plus_plus_networ… · securelist.com/notepad-supply-chain-attack/118708 · virustotal.com/gui/ip-address/160.250.93.48/relations · virustotal.com/gui/file/e7cd605568c38bd6e0aba31045e163… · virustotal.com/gui/file/0755d2dc99c0a44f4e5435c398d9af… · virustotal.com/gui/file/0a9b8df968df41920b6ff07785cbfe… · virustotal.com/gui/file/7f2e0f51e83d6cf9c50922f898126b… · virustotal.com/gui/file/f365cfbca03a28a7692308c9766f8a… · virustotal.com/gui/file/b4169a831292e245ebdffedd582058… · virustotal.com/gui/file/fcc2765305bcd213b7558025b2039d…
domain api.cloudtrafficservice.com domain api.skycloudcenter.com domain api.wiresguard.com domain cdncheck.it.com domain cloudtrafficservice.com domain self-dns.it.com domain skycloudcenter.com domain wiresguard.com ipv4 124.222.137.114:9999 ipv4 59.110.7.32:8880 ipv4 59.110.7.32:8999 ipv4 95.179.213.0:443 ipv4 95.179.213.0:8080 url http://45.32.144.255 url http://45.76.155.202 url http://95.179.213.0 url_path /ukalDxyz -
accenture.com/t20180131T100734Z__w__/us-en/_acnmedia/…
38qmk6.0to9.info 3qyo4o7.7r7i3.info 7g91xhp.envuy3.net dtdf5vu.nt7yq.info j.4tc3ldw.g9ml.www0.org l.hovux.eln9wj7.7gpj.org ubkv1t.ec0.com w.7sytdjc.wroi.cxy.com -
paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/…
aliancesky.com babysoal.com iascas.net imonju.com imonju.net interhero.net seachers.net serchers.net tgecc.org tintuchoahau.com vienclp.com -
paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/…
asean-star.com aseaneco.org aseansec.dynalias.org beckhammer.xicp.net boshman09.com chris201.net cpcl2006.dyndns-free.com cybertunnel.dyndns.info harryleed.dyndns.org jackyson.dyndns.info kid.dyndns.org kjd.dyndns.org newinfo32.eicp.net newshappys.dyndns-blog.com petto.mooo.com phil-army.gotdns.org phil-gov.gotdns.org scristioned.dyndns-web.com shotacon.dyndns.info usa-moon.net verolalia.dyndns.org wsi.dyndns.org www3.bkav2010.net
Further reading 24
- attack.mitre.org/groups/G0030
- blog.talosintelligence.com/lotus-blossom-espionage-group
- learn.microsoft.com/en-us/microsoft-365/security/intelligen…
- securelist.com/the-spring-dragon-apt/70726
- web.archive.org/web/20190508165226/https://www.accentur…
- paloaltonetworks.com/resources/research/unit42-operation-lot…
- security.com/threat-intelligence/espionage-asia-gove…
- virustotal.com/gui/file/0755d2dc99c0a44f4e5435c398d9af…
- virustotal.com/gui/file/7f2e0f51e83d6cf9c50922f898126b…
- virustotal.com/gui/file/b4169a831292e245ebdffedd582058…
- x.com/ValidinLLC/status/2018680305364685102
- notepad-plus-plus.org/news/hijacked-incident-info-update
- virustotal.com/gui/ip-address/160.250.93.48/relations
- virustotal.com/gui/file/0a9b8df968df41920b6ff07785cbfe…
- x.com/cyb3rops/status/2018253965645766993
- paloaltonetworks.com/content/dam/paloaltonetworks-com/en_US/…
- virustotal.com/gui/file/f365cfbca03a28a7692308c9766f8a…
- validin.com/blog/exploring_notepad_plus_plus_networ…
- x.com/cyb3rops/status/2018361184626356411
- rapid7.com/blog/post/tr-chrysalis-backdoor-dive-in…
- virustotal.com/gui/file/fcc2765305bcd213b7558025b2039d…
- securelist.com/notepad-supply-chain-attack/118708
- accenture.com/t20180131T100734Z__w__/us-en/_acnmedia/…
- virustotal.com/gui/file/e7cd605568c38bd6e0aba31045e163…