PULSE NAME
Hacking stemming from malicious DGA Insurance domains under Cisco Umbrella
WHITE scoreblue 2023-10-29 Modified: 2023-11-27
13527
IOCs
HIGH VOLUME
Extremely strange & disturbing report. A disruption at root of Cisco hack may be linked to a matrix of DGA insurance domains. AIG.com. Unclear validity. Spoof Domain, a tool AIG uses? Targets Tsara Brashears. Tulach unlikely a person more likely a profile accessed by entities. Rogue attornoes, etc. Large smear campaign wild cover up including death threats. Reports assert target's been harassed & harmed for years. Is this a cybercrime? Example of malicious tools deployed against innocents. Missing STSH Verdict: Concerning potential for physical harm to Target or associates Why: Avoid lawsuit and press / reputation Who: ? IP: 167.230.100.44 Host: am1mxi05.aig.com Registrar: CSC CORPORATE DOMAINS, INC. Creation date: 28 years ago
ssl certificatethreat roundupcontactedexecutionaugustmarchwhois recordcontacted urlsmalwarecopyaprilcryptoalivemaliciousducktailransomwaredeadskynetchineseoctoberroundupfebruarygoldfindersibothacktoolmetrogoldmaxinstallerawfulopenandroidbankerkeyloggerunitedmaltiversemail spammerphishing sitecyber threatengineeringemotetphishingspammerfireholbankazorultteammiraiponynanocorebradescocobalt strikeinstallcorenymaimsuppoboxdownloadlooquerdomainscisco umbrellasiteheuralexa topmillionsafe siteadwaremalware sitemalicious siteartemisopencandyriskwaretofseegandcrabtrojanxtrojangenericbankerxservicerunescapefacebookexploitagentmimikatzunsafealexaunionwebtoolbarip summaryurl summarysummaryurlsdetection listblacklist httpsdsp1noname057tag countsamplesamplesblacklisttsara brashearsalohatubetrojanscanning_hostBotnetmalvertizingabusecyber stalkingdefacementadult contentthreatssilencingharassmenttargetaigworkers compensationsevereattackhackingyixun toolspywaremalwareevasionmaliciousprivate investigatorlegal entitiesinsurance companyremote attackcoloradotulachAttack origin: United Statesappleiosvictimallegationsassaultrevengeretaliationlibelmonitoringtrackingpegatechbam.nr-data.netbamnr-data.netmatrixdata.netasp.netapple private data collectionnorad.milnorad trackerb.scopecommand_and_controlpornhubalohatubesweetheart videosusers voiceinterfacingsocial engineeringBankerXlaw enforcement aware, complacent or complicit?NSA tool Tulach malawaremetro tmobileAS 10975 (NET-AIG) USrecord typettl valuealgorithmdatav3 serialnumbercus ouentrustoentrustl1k validitycus stnewgroupinfodomain statusserverdateregistrar abusenew yorkpostal codecontact phoneregistrar urlcsc corporatecodemicrosoftwin32 exefilesdetections typenameconfednetworklabel netaigregistry arincountry uscontinent nawhois lookupno matchgoogledns replicationdomaintype namepine streetwhois databaseemailregistrar ianaicann whoiscontactformtechiana idtech emailadmin countryCVE-2017-0147CVE-2018-0802CVE-2017-17215CVE-2016-7255CVE-2017-11882CVE-2017-8570defense entity fraud?
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
Chinese Looquer Inmortal Domains WebToolbar Maltiverse Mimikatz HiddenTear Neurovt Ransomexx TrojanSpy TrojanX Emotet Nymaim Mirai Tofsee Sibot AZORult Trojan:Win32/InstallCore Yixun GoldFinder GoldMax - S0588 DUCKTAIL Artemis GandCrab Ransomware BlackNET Raccoon Stealer Skynet OpenCandy FireHOL HackTool.BruteForce HackTool.CheatEngine HackTool NanoCore Immortal Stealer WebToolBar
Indicators of Compromise (6 / 13527 total)
All URL FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain hostname CVE email CIDR
TYPEINDICATORDESCRIPTIONCREATED
CVE CVE-2016-7255 2023-10-29
CVE CVE-2017-11882 2023-10-29
CVE CVE-2017-8570 2023-10-29
CVE CVE-2018-0802 2023-10-29
CVE CVE-2017-17215 2023-10-29
CVE CVE-2017-0147 2023-10-29