20.04.2016 Views

y5qa5B

y5qa5B

y5qa5B

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

ASERT Threat Intelligence Report 2016-03: The Four-Element Sword Engagement<br />

which at analysis time resolved to 122.10.112[.]126. The C2 port appears to be TCP/8030, but was not <br />

responding during analysis. An ASN lookup reveals that the C2 is in China or Hong Kong: <br />

133731 | 122.10.112.126 | CN | TOINTER-­‐AS-­‐AP Royal Network Technology Co., Ltd. in Guangzhou,CN <br />

134121 | 122.10.112.126 | CN | RAINBOW-­‐HK Rainbow network limited,HK <br />

The LURK0 variant of Gh0stRAT is well documented and has been used against the Tibetan community and <br />

others for years [33] [34] [35]. Network activity appears as such, with the telltale “LURK0” string appearing at <br />

the start of the packet. <br />

The following network-­‐based alerts can notify organizations of Gh0stRAT LURK0 variant traffic: <br />

[2016922] ET TROJAN Backdoor family PCRat/Gh0st CnC traffic <br />

[2021716] ET TROJAN Backdoor family PCRat/Gh0st CnC traffic (OUTBOUND) 101 <br />

[2808814] ETPRO TROJAN Backdoor family PCRat/Gh0st CnC Response <br />

IOCs<br />

C2: manhaton.123nat[.]com <br />

C2: 122.10.112[.]126 TCP/8030 <br />

MD5 (90t69cf82.dll): 86ebcbb3bdd8af257b52daa869ddd6c1 <br />

MD5 (RTF): b51dd4d5731b71c1a191294466cc8288 <br />

MD5 (B412.tmp): 111273c8cba88636a036e250c2626b12 <br />

MD5 (~tmp.doc): e538ad13417b773714b75b5d602e4c6e -­‐ recognized as Gh0stRAT <br />

MD5 (Micbt/BTFly.dump): f7c04e8b188fa38d0f62f620e3bf01dc <br />

MD5 (Micbt/CltID.ini): 54afa267dd5acef3858dd6dbea609cd9 <br />

MD5 (Micbt/IconConfigBt.DAT): 516774cb0d5d56b300c402f63fe47523 <br />

MD5 (Micbt/MemoryLoad.dump): db0f8ba69aa71e9404b52d951458b97c <br />

MD5 (Micbt/RasTls.dll): 1e9e9ce1445a13c1ff4bf82f4a38de0d <br />

MD5 (Micbt/RasTls.exe): 62944e26b36b1dcace429ae26ba66164 <br />

40 Proprietary and Confidential Information of Arbor Networks, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!