SilverTerrier

APT / StateG0083
Techniques (MITRE ATT&CK)4
SourceMITRE ATT&CK
Attribution confidence: 50%

Vexday analysis

SilverTerrier é um grupo de ameaça de origem nigeriana ativo desde 2014, classificado como APT e catalogado no MITRE ATT&CK sob o identificador G0083. O grupo tem como alvos preferenciais organizações dos setores de alta tecnologia, ensino superior e manufatura, com 4 técnicas documentadas na base ATT&CK.

Techniques (MITRE ATT&CK) 4

How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 378

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

urlhttps://pub-1c4ef2a315ec4b89b9dfad9472afee69.r2.dev/zuyoking.pngAgentTeslaurlhaus
urlhttps://pub-eab9eb7761644f51bceeecfefdf0ec2b.r2.dev/teddywon.htaAgentTeslaurlhaus
urlhttps://pub-1c4ef2a315ec4b89b9dfad9472afee69.r2.dev/radman.pngAgentTeslaurlhaus
sha256_hash508d3964e9d8c082d8ec6527d8a664ae0158fac5db7d16d1028cf1c27562220aAgentTeslamalwarebazaar
ip:port82.153.241.181:1604DarkCometthreatfox
sha256_hasheaf3dc2c2daed81473f7fc5067990ffda4cd2e53a52bd31563da6fb3358d4fc3AgentTeslamalwarebazaar
md5_hashd9bf7b1a5f8cb94f92ef00e67f7a285dAgent Teslathreatfox
sha1_hashdc1fe4117917b32c9a0e44cdc052fe444af95237Agent Teslathreatfox
sha256_hasha5268bb0447ddd8e13190ce95933ebd3c2a65a726df96a8662fe3d78bd874df8Agent Teslathreatfox
sha256_hasha5268bb0447ddd8e13190ce95933ebd3c2a65a726df96a8662fe3d78bd874df8AgentTeslamalwarebazaar
md5_hashdca6afeddc135645ec068160a47c9510Agent Teslathreatfox
sha1_hash54c5c2659e3af3aca44fa046fb366cd32f5ed387Agent Teslathreatfox
sha256_hashedc4460d3dd2fc1fcae6c617c8d2728ce311e8cd47f2d6a37d719b924c2ac868Agent Teslathreatfox
ip:port207.189.23.198:1024DarkCometthreatfox
ip:port79.100.86.116:1604DarkCometthreatfox
ip:port189.150.106.61:2320DarkCometthreatfox
ip:port170.244.195.143:3000DarkCometthreatfox
sha1_hashf7f9b71363f3ba30282cf093141164710a991463Agent Teslathreatfox
md5_hashc5a32a7a16d32f960b7387fc25ee7372Agent Teslathreatfox
sha256_hash0e0bca2b782fb3d91cfe6c3dd55a59226f1b6b4e20453aebc34db216c5c0a81aAgent Teslathreatfox
urlhttp://209.54.103.153/50/givingbesthingsforbetterforme.htaAgentTeslaurlhaus
urlhttp://204.77.9.56/img/img_081951.pngAgentTeslaurlhaus
urlhttps://pub-8ce03602555a436b80dbe377ce6f81de.r2.dev/bagcorn.pngAgentTeslaurlhaus
urlhttps://pub-7bb797b9d5664a109b755165099495ac.r2.dev/aphelope.htaAgentTeslaurlhaus
urlhttps://pub-8ce03602555a436b80dbe377ce6f81de.r2.dev/drumwork.pngAgentTeslaurlhaus
urlhttp://209.54.103.153/50/weneedbestthingsfromtheheartforbest.jsAgentTeslaurlhaus
urlhttps://stratagemzw.com/img_014220.pngAgentTeslaurlhaus
urlhttps://www.stratagemzw.com/MSI_PRO.pngAgentTeslaurlhaus
urlhttps://munihuacho.gob.pe/vehiculos/MSI_PRO.pngAgentTeslaurlhaus
urlhttps://munihuacho.gob.pe/vehiculos/img_065018.pngAgentTeslaurlhaus

+378 indicators in total. See them all on the IOCs page.

SilverTerrier uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →