Overview 115 indicators
Aoqin Dragon is a suspected Chinese cyber espionage threat group that has been active since at least 2013. Aoqin Dragon has primarily targeted government, education, and telecommunication organizations in Australia, Cambodia, Hong Kong, Singapore, and Vietnam. Security researchers noted a potential association between Aoqin Dragon and UNC94, based on malware, infrastructure, and targets.
| domain | 107 | G1007-domain.txt |
| ipv4 | 4 | G1007.json |
| url | 3 | G1007.json |
| url_path | 1 | G1007.json |
Techniques 9 ATT&CK
Open in ATT&CK Navigator → or download the layer (9 techniques, layer 4.5)
- T1027.002 Software Packing
- T1036 Masquerading
- T1083 File and Directory Discovery
- T1091 Replication Through Removable Media
- T1203 Exploitation for Client Execution
- T1204.002 Malicious File
- T1570 Lateral Tool Transfer
- T1587.001 Malware
- T1588.002 Tool
Software 2
Principal sources 19 reports
Ranked by how many of this actor's indicators each report brought in.
- 113sentinelone.com/labs/aoqin-dragon-newly-discovered-chin…
- 113virustotal.com/gui/ip-address/172.111.192.233/relations
- 113virustotal.com/gui/ip-address/210.209.118.165/relations
- 113virustotal.com/gui/ip-address/45.77.11.148/relations
- 113virustotal.com/gui/ip-address/59.188.234.233/relations
- 113virustotal.com/gui/file/c57bc203dca9dfd24cad72bee445b3…
- 113virustotal.com/gui/file/d7d29522157423cd4ccaab42612f7d…
- 113virustotal.com/gui/file/313355f5ecf62401247c61e147b43f…
Timeline 115 indicators
Each entry is a batch of indicators that appeared upstream on one date, under the report it was filed with.
No indicator matches. Only the most recent 300 are on this page — the rest are in the JSON.
-
sentinelone.com/labs/aoqin-dragon-newly-discovered-chin… · virustotal.com/gui/ip-address/172.111.192.233/relations · virustotal.com/gui/ip-address/210.209.118.165/relations · virustotal.com/gui/ip-address/45.77.11.148/relations · virustotal.com/gui/ip-address/59.188.234.233/relations · virustotal.com/gui/file/c57bc203dca9dfd24cad72bee445b3… · virustotal.com/gui/file/d7d29522157423cd4ccaab42612f7d… · virustotal.com/gui/file/313355f5ecf62401247c61e147b43f… · virustotal.com/gui/file/908bdcb18265b0a3d93e7070d09305… · virustotal.com/gui/file/9211a584ce32883437fba00adaa8df… · virustotal.com/gui/file/7e31a7da7322546220f74b3f055646… · virustotal.com/gui/file/4d082fbd76b9f8f83e29ea8fe5d235… · virustotal.com/gui/file/2110627fc40daaa7903210e310ee0f… · virustotal.com/gui/file/73125d33e358395f067849497b1694…
satunusa.org -
twitter.com/alex_lanstein/status/1757855436261245194 · twitter.com/AndreGironda/status/1757929271962550534 · virustotal.com/gui/file/cc1f543cbb4930e045f49e681fd0a1… · virustotal.com/gui/file/bec277998b7780eb67dc6f43628265… · virustotal.com/gui/file/929eefaafc3906ae27371366addb83…
domain soap.free.cloudns.asia url_path /rrd9cutaenieyb9hro6v_qgo2fvjgablyrklaqvbgwr1swjo -
sentinelone.com/labs/aoqin-dragon-newly-discovered-chin… · virustotal.com/gui/ip-address/172.111.192.233/relations · virustotal.com/gui/ip-address/210.209.118.165/relations · virustotal.com/gui/ip-address/45.77.11.148/relations · virustotal.com/gui/ip-address/59.188.234.233/relations · virustotal.com/gui/file/c57bc203dca9dfd24cad72bee445b3… · virustotal.com/gui/file/d7d29522157423cd4ccaab42612f7d… · virustotal.com/gui/file/313355f5ecf62401247c61e147b43f… · virustotal.com/gui/file/908bdcb18265b0a3d93e7070d09305… · virustotal.com/gui/file/9211a584ce32883437fba00adaa8df… · virustotal.com/gui/file/7e31a7da7322546220f74b3f055646… · virustotal.com/gui/file/4d082fbd76b9f8f83e29ea8fe5d235… · virustotal.com/gui/file/2110627fc40daaa7903210e310ee0f… · virustotal.com/gui/file/73125d33e358395f067849497b1694…
domain adsoft.name domain back.satunusa.org domain baomoi.vnptnet.info domain bbw.fushing.org domain bca.zdungk.com domain bkav.manlish.net domain bkav.welikejack.com domain bkavonline.vnptnet.info domain bluesky1234.com domain bush2015.net domain cl.weststations.com domain cloundvietnam.com domain comnnet.net domain cpt.vnptnet.inf domain cvb.hotcup.pw domain dellyou.com domain dinhk.net domain dns.foodforthought1.com domain dns.lioncity.top domain dns.satunusa.org domain dns.zdungk.com domain ds.vdcvn.com domain ds.xrayccc.top domain dungk.com domain facebookmap.top domain fbcl2.adsoft.name domain fbcl2.softad.net domain flower2.yyppmm.com domain followag.org domain foodforthought1.com domain fushing.org domain game.vietnamflash.com domain hello.bluesky1234.com domain hotcup.pw domain ipad.vnptnet.info domain ks.manlish.net domain lepad.fushing.org domain lllyyy.adsoft.name domain longvn.net domain lucky.manlish.net domain ma550.adsoft.name domain ma550.softad.net domain mail.comnnet.net domain mail.tiger1234.com domain mail.vdcvn.com domain manlish.net domain mass.longvn.net domain mcafee.bluesky1234.com domain media.vietnamflash.com domain mil.dungk.com domain mil.zdungk.com domain missyou.longvn.net domain mmchj2.telorg.net domain mmslsh.tiger1234.com domain mobile.vdcvn.com domain moit.longvn.net domain movie.vdcvn.com domain neverdropd.com domain news.philstar2.com domain news.welikejack.com domain npt.vnptnet.info domain ns.fushing.org domain nycl.neverdropd.com domain phcl.followag.org domain phcl.neverdropd.com domain philstar2.com domain phung123.com domain pna.adsoft.name domain pnavy3.neverdropd.com domain sky.bush2015.net domain sky.vietnamflash.com domain softad.net domain tcv.tiger1234.com domain telecom.longvn.net domain telecom.manlish.net domain telorg.net domain test.facebookmap.top domain th-y3.adsoft.name domain th550.adsoft.name domain th550.softad.net domain three.welikejack.com domain thy3.softad.net domain tiger1234.com domain trend.welikejack.com domain vdcvn.com domain video.philstar2.com domain viet.vnptnet.info domain viet.zdungk.com domain vietnam.vnptnet.info domain vietnamflash.com domain vnet.fushing.org domain vnn.bush2015.net domain vnn.phung123.com domain vnptnet.info domain webmail.philstar2.com domain welikejack.com domain yok.fushing.org domain yote.dellyou.com domain yyppmm.com domain zdungk.com domain zing.vietnamflash.com domain zingme.dungk.com domain zingme.longvn.net domain zw.dinhk.net domain zw.phung123.com ipv4 64.27.4.157:53 ipv4 64.27.4.157:8080 ipv4 67.210.114.99:443 ipv4 67.210.114.99:8080 url http://64.27.4.157 url http://64.27.4.19 url http://67.210.114.99
Further reading 20
- attack.mitre.org/groups/G1007
- sentinelone.com/labs/aoqin-dragon-newly-discovered-chin…
- virustotal.com/gui/file/929eefaafc3906ae27371366addb83…
- virustotal.com/gui/ip-address/59.188.234.233/relations
- virustotal.com/gui/file/cc1f543cbb4930e045f49e681fd0a1…
- virustotal.com/gui/file/c57bc203dca9dfd24cad72bee445b3…
- twitter.com/AndreGironda/status/1757929271962550534
- virustotal.com/gui/ip-address/172.111.192.233/relations
- virustotal.com/gui/file/9211a584ce32883437fba00adaa8df…
- virustotal.com/gui/file/7e31a7da7322546220f74b3f055646…
- virustotal.com/gui/file/d7d29522157423cd4ccaab42612f7d…
- virustotal.com/gui/ip-address/45.77.11.148/relations
- virustotal.com/gui/file/bec277998b7780eb67dc6f43628265…
- virustotal.com/gui/file/2110627fc40daaa7903210e310ee0f…
- virustotal.com/gui/file/908bdcb18265b0a3d93e7070d09305…
- virustotal.com/gui/file/4d082fbd76b9f8f83e29ea8fe5d235…
- virustotal.com/gui/file/313355f5ecf62401247c61e147b43f…
- twitter.com/alex_lanstein/status/1757855436261245194
- virustotal.com/gui/ip-address/210.209.118.165/relations
- virustotal.com/gui/file/73125d33e358395f067849497b1694…