Overview 71 indicators
APT19 is a Chinese-based threat group that has targeted a variety of industries, including defense, finance, energy, pharmaceutical, telecommunications, high tech, education, manufacturing, and legal services. In 2017, a phishing campaign was used to target seven law and investment firms. Some analysts track APT19 and Deep Panda as the same group, but it is unclear from open source information if the groups are the same.
| domain | 57 | G0073-domain.txt |
| url | 8 | G0073.json |
| url_path | 4 | G0073.json |
| ipv4 | 2 | G0073.json |
Techniques 21 ATT&CK
Open in ATT&CK Navigator → or download the layer (21 techniques, layer 4.5)
- T1016 System Network Configuration Discovery
- T1027.010 Command Obfuscation
- T1027.013 Encrypted/Encoded File
- T1033 System Owner/User Discovery
- T1059 Command and Scripting Interpreter
- T1059.001 PowerShell
- T1071.001 Web Protocols
- T1082 System Information Discovery
- T1112 Modify Registry
- T1132.001 Standard Encoding
- T1140 Deobfuscate/Decode Files or Information
- T1189 Drive-by Compromise
- T1204.002 Malicious File
- T1218.010 Regsvr32
- T1218.011 Rundll32
- T1543.003 Windows Service
- T1547.001 Registry Run Keys / Startup Folder
- T1564.003 Hidden Window
- T1566.001 Spearphishing Attachment
- T1574.001 DLL
- T1588.002 Tool
Software 2
Principal sources 16 reports
Ranked by how many of this actor's indicators each report brought in.
- 36symantec.com/content/en/us/enterprise/media/security…
- 9fortinet.com/blog/threat-research/deep-panda-log4she…
- 9otx.alienvault.com/pulse/6245655996f5a1a01e2b5d94
- 9virustotal.com/gui/file/c0a2a3708516a321ad2fd68400bef6…
- 7fireeye.com/blog/threat-research/2017/06/phished-at…
- 6x.com/skocherhan/status/2024248493037015409
- 6virustotal.com/gui/file/3f62db0ff8ee1ce8cb2015c5bd2af8…
- 6unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group
Timeline 71 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
x.com/skocherhan/status/2024248493037015409 · virustotal.com/gui/file/3f62db0ff8ee1ce8cb2015c5bd2af8…
premrera.com vpn.premrera.com -
cisa.gov/uscert/ncas/alerts/aa22-174a · otx.alienvault.com/pulse/62b5767285717d7d3a45b2b8
104.223.34.198:443 -
fortinet.com/blog/threat-research/deep-panda-log4she… · otx.alienvault.com/pulse/6245655996f5a1a01e2b5d94 · virustotal.com/gui/file/c0a2a3708516a321ad2fd68400bef6…
domain b.gnisoft.com domain giga.gnisoft.com domain gnisoft.com domain smi1egate.com domain svn1.smi1egate.com domain vpn2.smi1egate.com ipv4 192.95.36.61:443 url http://104.223.34.198 -
x.com/skocherhan/status/2024248493037015409 · virustotal.com/gui/file/3f62db0ff8ee1ce8cb2015c5bd2af8…
/example/McAltLib.dll /lifeandstyle/marmalade-paddington-sales-up-making-drinking /money/ofcom-fines-nuisance-calls /world/video/shrien-dewani-arrives-uk-murder-trial-collapses-video -
unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group · domaintools.com/resources/blog/domaintools-101-the-art-…
http://210.181.184.64 http://218.54.139.20 http://42.200.18.194 -
attack.mitre.org/wiki/Group/G0009 · krebsonsecurity.com/wp-content/uploads/2015/02/FBI-Flash-Wa…
googlewebcache.com outlookssl.com -
symantec.com/content/en/us/enterprise/media/security…
kaspersyk.com -
twitter.com/unpacker/status/1343143954007482369 · cybergeeks.tech/analyzing-apt19-malware-using-a-step-by… · virustotal.com/gui/file/8b0877209594dada522e606ebac60c…
http://106.185.43.96/user/atv.html -
fortinet.com/blog/threat-research/deep-panda-log4she… · otx.alienvault.com/pulse/6245655996f5a1a01e2b5d94 · virustotal.com/gui/file/c0a2a3708516a321ad2fd68400bef6…
client.gnisoft.com -
unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group · domaintools.com/resources/blog/domaintools-101-the-art-…
jbossas.org supermanbox.org -
unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group · domaintools.com/resources/blog/domaintools-101-the-art-… · twitter.com/unpacker/status/1343143954007482369 · cybergeeks.tech/analyzing-apt19-malware-using-a-step-by… · virustotal.com/gui/file/8b0877209594dada522e606ebac60c…
microsoft-cache.com -
fireeye.com/blog/threat-research/2017/06/phished-at…
domain autodiscover.2bunny.com domain lyncdiscover.2bunny.com domain sfo02s01-in-f2.cloudsend.net domain tk-in-f156.2bunny.com url http://104.236.77.169 url http://138.68.45.9 url http://162.243.143.145 -
attack.mitre.org/wiki/Group/G0009 · krebsonsecurity.com/wp-content/uploads/2015/02/FBI-Flash-Wa…
images.googlewebcache.com smtp.outlookssl.com -
twitter.com/unpacker/status/1343143954007482369 · cybergeeks.tech/analyzing-apt19-malware-using-a-step-by… · virustotal.com/gui/file/8b0877209594dada522e606ebac60c…
google-dash.com -
symantec.com/content/en/us/enterprise/media/security…
EmpireB1ue.com ameteksen.com asconline.we11point.com assso.net capstoneturbine.cechire.com caref1rst.com careflrst.com extcitrix.we11point.com facefuture.us gifas.blogsite.org gifas.cechire.com healthslie.com hrsolutions.we11point.com icbcqsz.com me.we11point.com mycitrix.we11point.com myhr.we11point.com oa.ameteksen.com oa.technical-requre.com oa.trustneser.com polarroute.com prennera.com savmpet.com sharepoint-vaeit.com sinmoung.com ssl-vaeit.com ssl-vait.com topsec2014.com vipreclod.com vpn.we11point.com we11point.com webmail.kaspersyk.com webmail.vipreclod.com wiki-vaeit.com ysims.com
Further reading 22
- attack.mitre.org/groups/G0073
- researchcenter.paloaltonetworks.com/2016/01/new-attacks-linked-to-c0d0s0-gr…
- web.archive.org/web/20171017072306/https://icitech.org/…
- darkreading.com/attacks-breaches/chinese-hacking-group-…
- fireeye.com/blog/threat-research/2017/06/phished-at…
- fireeye.com/current-threats/apt-groups.html#apt19
- symantec.com/content/en/us/enterprise/media/security…
- x.com/skocherhan/status/2024248493037015409
- attack.mitre.org/wiki/Group/G0009
- cisa.gov/uscert/ncas/alerts/aa22-174a
- twitter.com/unpacker/status/1343143954007482369
- fireeye.com/blog/threat-research/2017/06/phished-at…
- virustotal.com/gui/file/3f62db0ff8ee1ce8cb2015c5bd2af8…
- krebsonsecurity.com/wp-content/uploads/2015/02/FBI-Flash-Wa…
- cybergeeks.tech/analyzing-apt19-malware-using-a-step-by…
- otx.alienvault.com/pulse/6245655996f5a1a01e2b5d94
- unit42.paloaltonetworks.com/new-attacks-linked-to-c0d0s0-group
- fortinet.com/blog/threat-research/deep-panda-log4she…
- domaintools.com/resources/blog/domaintools-101-the-art-…
- virustotal.com/gui/file/c0a2a3708516a321ad2fd68400bef6…
- virustotal.com/gui/file/8b0877209594dada522e606ebac60c…
- otx.alienvault.com/pulse/62b5767285717d7d3a45b2b8