← Back to Pulse Feed
PULSE DETAIL
Back in February, the ThreatConnect team conducted an in-depth independent analysis of the Anthem breach, finding connections to amorphous Chinese APT activity. Although our primary concern at the time was with the malicious Wellpoint/Anthem and VAE, Inc. (a Federal contractor) command and control domains, we couldn’t help but notice a peculiar related OPM-themed domain, opm-learning[.]org. This finding was listed in our Anthem blog, and we have continued to monitor it in ThreatConnect since mid February.
| TYPE | INDICATOR | DESCRIPTION | CREATED | |
|---|---|---|---|---|
| domain | wiki-vaeit.com | — | 2015-06-05 | |
| domain | ssl-vaeit.com | — | 2015-06-05 | |
| domain | ssl-vait.com | — | 2015-06-05 | |
| domain | sharepoint-vaeit.com | — | 2015-06-05 | |
| domain | opm-learning.org | — | 2015-06-05 | |
| domain | opmsecurity.org | — | 2015-06-05 | |
| hostname | images.googlewebcache.com | — | 2015-06-05 | |
| hostname | smtp.outlookssl.com | — | 2015-06-05 | |
| vrzunyjkmf@gmx.com | — | 2015-06-05 | ||
| taprhpalhl@gmx.com | — | 2015-06-05 |
References (1)