logo

APT19__2015__crowdstrike-deep-panda-report.pdf

ID: 375d5987-3bd3-4e7c-9d29-8ff5ee853ec3

STIX ID: report--375d5987-3bd3-4e7c-9d29-8ff5ee853ec3

Threat Score

90/100

Uploaded: 2026-08-07

Published Date: 2015-05-20

Last Modified Date: 2015-05-20

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This CrowdStrike Global Intelligence report analyzes a multi‑component intrusion (dropper, DLL backdoors, .NET post‑exploitation tool, and kernel rootkit) observed in targeted attacks against high‑value organizations; it describes detailed technical behavior, network protocols and C2s (including 1.9.5.38:443 and 202.86.190.3:80), provides IOCs (MD5s, file/registry artifacts, Snort signatures), mitigation steps, and concludes with attribution indicators linking the tooling and code reuse to Chinese‑language forums and builders (termed 'Deep Panda').