02-12-25, 01:30 AM
Looking for information on Chinese APT activity related to [UTA0178] [UNC5221] [CL-STA-0048] [SILK TYPHOON] and [BRICKSTORM]. Willing to pay for unique and current information related to the following:
- Suspect Companies/Attribution:
- Qianxin Technology Group (奇安信科技集团) [Qianxin]
- Qianxin Legendsec Information Technology (Beijing) Co. Ltd. (奇安信网神信息技术(北京)股份有限公司) [Legendsec]
- Beijing Zhongke Wanghang Security Technology Co. Ltd. (北京中科网航安全技术有限公司) [Redcore]
- Qianxin Technology Group (奇安信科技集团) [Qianxin]
- Infrastructure:
- symantke[.]com
- entraide-internationale[.]fr
- tnegadge.s3.amazonaws[.]com
- 103.244.88.125
- 124.223.202.90
- 54.77.139.23
- 3.248.33.252
- symantke[.]com
- Tool hashes:
- Sample 1:
- SHA256 - 2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df, MD5 - 123e80a34508c4dede7cc70e76931fcc, SHA1 - 130fdc32de36a362e65c7138b560eb8d8f6ae599
- SHA256 - 2388ed7aee0b6b392778e8f9e98871c06499f476c9e7eae6ca0916f827fe65df, MD5 - 123e80a34508c4dede7cc70e76931fcc, SHA1 - 130fdc32de36a362e65c7138b560eb8d8f6ae599
- Sample 2:
- SHA256 - 4d7ddbaeb3d0b8c3c9d63d78a840b61c7f6d1a8f3769922d114586e0f0ee5bd7, MD5 - 4645f2f6800bc654d5fa812237896b00, SHA1 - cd513d9f7da7add1bba5fa8fe700f94a98215abd
- SHA256 - 4d7ddbaeb3d0b8c3c9d63d78a840b61c7f6d1a8f3769922d114586e0f0ee5bd7, MD5 - 4645f2f6800bc654d5fa812237896b00, SHA1 - cd513d9f7da7add1bba5fa8fe700f94a98215abd
- Sample 1:
