PULSE NAME
Thallium domains sinkholed by Microsoft
WHITE Thallium AlienVault 2020-01-16 Modified: 2020-01-17
45
IOCs
MEDIUM VOLUME
On December 27, a U.S. district court unsealed documents detailing work Microsoft has performed to disrupt cyberattacks from a threat group we call Thallium, which is believed to operate from North Korea. Our court case against Thallium, filed in the U.S. District Court for the Eastern District of Virginia, resulted in a court order enabling Microsoft to take control of 50 domains that the group uses to conduct its operations. With this action, the sites can no longer be used to execute attacks.
Indicators of Compromise (45)
All email domain hostname
TYPEINDICATORDESCRIPTIONCREATED
email wusongha03@gmail.com 2020-01-16
email tiger199392@daum.net 2020-01-16
email tang_guanghui@hotmail.com 2020-01-16
email snow8949@hotmail.com 2020-01-16
email satoshiman0088@gmail.com 2020-01-16
email roman.alex2019@mail.ru 2020-01-16
email rninchurl@daum.net 2020-01-16
email okonoki_masao@yahoo.co.jp 2020-01-16
email norelyeverland@hanmail.net 2020-01-16
email jiahuzong@hotmail.com 2020-01-16
email infornail.noreply@gmail.com 2020-01-16
email hello-0978@daum.net 2020-01-16
email bitcoin025@hanmail.net 2020-01-16
email bitcoin024@hanmail.net 2020-01-16
email bitcoin018@hanmail.net 2020-01-16
domain grnaeil.com 2020-01-16
domain lnfo-master.com 2020-01-16
domain yrnall.com 2020-01-16
domain nid2-naver.com 2020-01-16
domain webmail-gooqle.com 2020-01-16
domain maingoogle.com 2020-01-16
domain rneail.com 2020-01-16
domain login-sec.com 2020-01-16
domain webmail-googie.com 2020-01-16
domain files-downloader.net 2020-01-16
domain mofako.com 2020-01-16
domain lh-logs.com 2020-01-16
domain imap-login.com 2020-01-16
domain wallet-vahoo.com 2020-01-16
domain maingoogie.com 2020-01-16
domain helpnaver.com 2020-01-16
domain navuor.com 2020-01-16
domain yalnoo.com 2020-01-16
domain iinaver.com 2020-01-16
domain rnaeil.com 2020-01-16
domain dauurn.net 2020-01-16
domain naerver.com 2020-01-16
domain blockochain.info 2020-01-16
domain dounn.net 2020-01-16
domain phlogin.com 2020-01-16
domain nidhelpnaver.com 2020-01-16
domain gstaticstorage.com 2020-01-16
domain rnail-163.com 2020-01-16
hostname yahoo.security-acount.info 2020-01-16
hostname yahoo.security-lnfo.com 2020-01-16