APT19__2013__AdversaryIntelligenceReport_DeepPanda_0.pdf
ID: 2b1ede63-6cb7-4989-a351-13d3bad67eba
STIX ID: report--2b1ede63-6cb7-4989-a351-13d3bad67eba
Threat Score
90/100
Uploaded: 2026-08-07
Published Date: 2013-02-21
Last Modified Date: 2013-02-21
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
### Executive summary
This CrowdStrike Deep Panda report analyzes three malicious samples (a dropper, a .NET post-exploitation tool, and a C++ backdoor with a kernel-mode rootkit) used in targeted intrusions against high-value organizations; it documents technical behavior, network protocols and C2 infrastructure (including IPs and MD5s), persistence and anti-forensic techniques, mitigation signatures and artifacts, and provides attribution to a Chinese-speaking actor.
