20.04.2016 Views

y5qa5B

y5qa5B

y5qa5B

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

ASERT Threat Intelligence Report 2016-03: The Four-Element Sword Engagement<br />

Domain name First seen Last seen <br />

www.tibetimes.com 2015-­‐12-­‐01 02:04:24 2015-­‐12-­‐04 01:25:34 <br />

softinc.pw 2015-­‐11-­‐01 06:43:26 2015-­‐11-­‐30 18:57:21 <br />

An email address associated with these domains is lobsang[@]gmx.com and another is <br />

2732115454[@]qq.com. The IP and these mail addresses associate with Uyghur and Tibetan themed domains <br />

as shown here: <br />

The following diagram zooms in on the Uyghur-­‐based domain names highlighting the connection between this <br />

Gh0stRAT sample domain metadata and other activity observed, such as the domain whitewall[.]top used in <br />

the PlugX configuration previously mentioned. <br />

42 Proprietary and Confidential Information of Arbor Networks, Inc.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!