PULSE NAME
OPM Breach Analysis
WHITE AlienVault 2015-06-05 Modified: 2015-06-05
10
IOCs
LOW VOLUME
Back in February, the ThreatConnect team conducted an in-depth independent analysis of the Anthem breach, finding connections to amorphous Chinese APT activity. Although our primary concern at the time was with the malicious Wellpoint/Anthem and VAE, Inc. (a Federal contractor) command and control domains, we couldn’t help but notice a peculiar related OPM-themed domain, opm-learning[.]org. This finding was listed in our Anthem blog, and we have continued to monitor it in ThreatConnect since mid February.
Indicators of Compromise (10)
All domain hostname email
TYPEINDICATORDESCRIPTIONCREATED
domain wiki-vaeit.com 2015-06-05
domain ssl-vaeit.com 2015-06-05
domain ssl-vait.com 2015-06-05
domain sharepoint-vaeit.com 2015-06-05
domain opm-learning.org 2015-06-05
domain opmsecurity.org 2015-06-05
hostname images.googlewebcache.com 2015-06-05
hostname smtp.outlookssl.com 2015-06-05
email vrzunyjkmf@gmx.com 2015-06-05
email taprhpalhl@gmx.com 2015-06-05