PULSE NAME
Multi-level Dropbox commands and TutorialRAT behind APT43
WHITE APT43 AlienVault 2024-04-22 Modified: 2024-05-22
32
IOCs
MEDIUM VOLUME
Genians confirmed that the APT43 group focuses on evading signature-based anti-virus detection technology by utilizing a multi-stage attack chain. In particular, tactical efforts are being made to escape the scope of threat monitoring by using DropBox cloud storage, which is widely used legally, as an attack base.
MITRE ATT&CK & Malware Families
ATT&CK TECHNIQUES
MALWARE FAMILIES
XenoRAT TutRAT
Indicators of Compromise (13 / 32 total)
All FileHash-MD5 FileHash-SHA1 FileHash-SHA256 domain
TYPEINDICATORDESCRIPTIONCREATED
FileHash-MD5 0040f03faf5bbdc555f2039a4e33a82b 2024-04-22
FileHash-MD5 1e66ac680d0edfe18d97b89e46c7e82e 2024-04-22
FileHash-MD5 2f9125a538d84dd952f72722f28575b8 2024-04-22
FileHash-MD5 544963f602ec6c97994d38ce39368d79 2024-04-22
FileHash-MD5 781acd3a8250da862e48425d078b54ad 2024-04-22
FileHash-MD5 8133c5f663f89b01b30a052749b5a988 2024-04-22
FileHash-MD5 a4bd6d00abbd79ab00161ff538cfe703 2024-04-22
FileHash-MD5 a9276bae977589f3f670f26b2cb8a9f1 2024-04-22
FileHash-MD5 ade1d12604dd9d62f6ef97a93cda142b 2024-04-22
FileHash-MD5 b70bc31b537caf411f97a991d8292c5a 2024-04-22
FileHash-MD5 c700195f61635b9a6fb1ee4359b91940 2024-04-22
FileHash-MD5 f395012ff30a846d0e7ed787147f5723 2024-04-22
FileHash-MD5 fb5aec165279015f17b29f9f2c730976 2024-04-22