y5qa5B
y5qa5B
y5qa5B
Create successful ePaper yourself
Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.
ASERT Threat Intelligence Report 2016-03: The Four-Element Sword Engagement<br />
Domain name First seen Last seen <br />
www.tibetimes.com 2015-‐12-‐01 02:04:24 2015-‐12-‐04 01:25:34 <br />
softinc.pw 2015-‐11-‐01 06:43:26 2015-‐11-‐30 18:57:21 <br />
An email address associated with these domains is lobsang[@]gmx.com and another is <br />
2732115454[@]qq.com. The IP and these mail addresses associate with Uyghur and Tibetan themed domains <br />
as shown here: <br />
The following diagram zooms in on the Uyghur-‐based domain names highlighting the connection between this <br />
Gh0stRAT sample domain metadata and other activity observed, such as the domain whitewall[.]top used in <br />
the PlugX configuration previously mentioned. <br />
42 Proprietary and Confidential Information of Arbor Networks, Inc.