Vexday analysis
SilverTerrier é um grupo de ameaça de origem nigeriana ativo desde 2014, classificado como APT e catalogado no MITRE ATT&CK sob o identificador G0083. O grupo tem como alvos preferenciais organizações dos setores de alta tecnologia, ensino superior e manufatura, com 4 técnicas documentadas na base ATT&CK.
Techniques (MITRE ATT&CK) 4
How the group operates, mapped to the MITRE ATT&CK matrix and organized by the phases of an attack.
Exploited vulnerabilities
No CVEs attributed to this group in public sources (MITRE ATT&CK). Absence of attribution does not mean absence of activity.
Known infrastructure 378
Real indicators (C2, domains, URLs and hashes) associated with the malware this group uses. Source: abuse.ch (ThreatFox, URLhaus, MalwareBazaar).
https://pub-1c4ef2a315ec4b89b9dfad9472afee69.r2.dev/zuyoking.pngAgentTeslaurlhaushttps://pub-eab9eb7761644f51bceeecfefdf0ec2b.r2.dev/teddywon.htaAgentTeslaurlhaushttps://pub-1c4ef2a315ec4b89b9dfad9472afee69.r2.dev/radman.pngAgentTeslaurlhaus508d3964e9d8c082d8ec6527d8a664ae0158fac5db7d16d1028cf1c27562220aAgentTeslamalwarebazaar82.153.241.181:1604DarkCometthreatfoxeaf3dc2c2daed81473f7fc5067990ffda4cd2e53a52bd31563da6fb3358d4fc3AgentTeslamalwarebazaard9bf7b1a5f8cb94f92ef00e67f7a285dAgent Teslathreatfoxdc1fe4117917b32c9a0e44cdc052fe444af95237Agent Teslathreatfoxa5268bb0447ddd8e13190ce95933ebd3c2a65a726df96a8662fe3d78bd874df8Agent Teslathreatfoxa5268bb0447ddd8e13190ce95933ebd3c2a65a726df96a8662fe3d78bd874df8AgentTeslamalwarebazaardca6afeddc135645ec068160a47c9510Agent Teslathreatfox54c5c2659e3af3aca44fa046fb366cd32f5ed387Agent Teslathreatfoxedc4460d3dd2fc1fcae6c617c8d2728ce311e8cd47f2d6a37d719b924c2ac868Agent Teslathreatfox207.189.23.198:1024DarkCometthreatfox79.100.86.116:1604DarkCometthreatfox189.150.106.61:2320DarkCometthreatfox170.244.195.143:3000DarkCometthreatfoxf7f9b71363f3ba30282cf093141164710a991463Agent Teslathreatfoxc5a32a7a16d32f960b7387fc25ee7372Agent Teslathreatfox0e0bca2b782fb3d91cfe6c3dd55a59226f1b6b4e20453aebc34db216c5c0a81aAgent Teslathreatfoxhttp://209.54.103.153/50/givingbesthingsforbetterforme.htaAgentTeslaurlhaushttp://204.77.9.56/img/img_081951.pngAgentTeslaurlhaushttps://pub-8ce03602555a436b80dbe377ce6f81de.r2.dev/bagcorn.pngAgentTeslaurlhaushttps://pub-7bb797b9d5664a109b755165099495ac.r2.dev/aphelope.htaAgentTeslaurlhaushttps://pub-8ce03602555a436b80dbe377ce6f81de.r2.dev/drumwork.pngAgentTeslaurlhaushttp://209.54.103.153/50/weneedbestthingsfromtheheartforbest.jsAgentTeslaurlhaushttps://stratagemzw.com/img_014220.pngAgentTeslaurlhaushttps://www.stratagemzw.com/MSI_PRO.pngAgentTeslaurlhaushttps://munihuacho.gob.pe/vehiculos/MSI_PRO.pngAgentTeslaurlhaushttps://munihuacho.gob.pe/vehiculos/img_065018.pngAgentTeslaurlhaus+378 indicators in total. See them all on the IOCs page.
References
SilverTerrier uses real techniques and exploits real flaws. TrueHacking's AI Autonomous Pentest simulates these attacks against your infrastructure and brings more security to your application.
Explore the AI Autonomous Pentest →