TA2541

APT / StateG1018
Techniques (MITRE ATT&CK)28
SourceMITRE ATT&CK
0

Vexday analysis

TA2541 é um grupo cibercriminoso ativo desde pelo menos 2017, com histórico de ataques direcionados aos setores de aviação, aeroespacial, transporte, manufatura e defesa. Suas campanhas são tipicamente de alto volume e fazem uso de ferramentas de acesso remoto comerciais, ofuscadas por crypters, com temáticas relacionadas a aviação, transporte e viagens. O grupo é rastreado pelo MITRE ATT&CK sob o identificador G1018, com 28 técnicas documentadas associadas à sua atuação.

Attack chain

Plausible scenario built from the group's real techniques, ordered by the phases of an attack. Each step shows how the group typically operates.

Arsenal severity35
Impact: High
T1566.001T1047T1547.001ENTRYInitial accessSpearphishingAttachmentEXECExecutionWindows ManagementInstrumentationPERSPersistenceRegistry Run Keys/ Startup FolderDISCDiscoveryInternetConnection Discov…

Illustrative chain derived from techniques documented in MITRE ATT&CK — it does not represent a specific past attack. Severity summarizes the known arsenal (kill-chain coverage, actively exploited CVEs, techniques).

Exploited vulnerabilities

No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.

Known infrastructure 641

Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).

ip:port38.247.165.127:8015AsyncRATthreatfox
ip:port34.186.150.169:6932AsyncRATthreatfox
ip:port185.34.147.35:2204AsyncRATthreatfox
ip:port185.34.147.34:443AsyncRATthreatfox
ip:port185.34.147.33:2204AsyncRATthreatfox
ip:port185.34.147.32:2204AsyncRATthreatfox
ip:port185.34.147.31:443AsyncRATthreatfox
ip:port128.90.63.100:4444AsyncRATthreatfox
ip:port107.174.33.36:80AsyncRATthreatfox
ip:port104.243.248.63:301AsyncRATthreatfox
ip:port104.234.4.217:4589AsyncRATthreatfox
domainpeakypinkers.ddns.netAsyncRATthreatfox
urlhttps://pastebin.com/raw/9stYNLmiAsyncRATthreatfox
md5_hashcaf5b7d0873fbac47a3dd246a9130ffeAsyncRATthreatfox
sha1_hashe7653a59dce272f06f56a32c7aa92a1037941930AsyncRATthreatfox
sha256_hash34bae751324dcb623efb9c061f097d715b1d2d93587e9b0ea59017a9e5778f6eAsyncRATthreatfox
md5_hashdc95438760cc8ae9e8b9bcbfa6f63da3AsyncRATthreatfox
sha256_hash396750d3837d60b8d8aa0253a5b569acfcdf872224e01ecd8f744dd73db4a850AsyncRATthreatfox
sha1_hash7e5b9bc2c4c04125bb903ae5786788bf36c895caAsyncRATthreatfox
sha1_hash1cd117fd3614866247ca58bd308485e26b21b6d4AsyncRATthreatfox
md5_hash8459f9cdeaaab6f25f4ee076dfc02770AsyncRATthreatfox
sha256_hash2d666c5083b8c3cd511b58e14e0191fb31b2c2c7cb8788d5f152fbfd1734d081AsyncRATthreatfox
ip:port185.34.147.35:443AsyncRATthreatfox
ip:port185.34.147.33:443AsyncRATthreatfox
ip:port159.203.69.210:12262AsyncRATthreatfox
ip:port185.235.137.195:6606AsyncRATthreatfox
ip:port41.100.227.210:3030AsyncRATthreatfox
ip:port121.200.216.84:443AsyncRATthreatfox
ip:port38.247.165.127:443AsyncRATthreatfox
ip:port91.92.42.94:4851AsyncRATthreatfox

+641 indicators in total. See them all on the IOCs page.

TA2541 uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.

Explore the AI Autonomous Pentest →