APT41__2017__Recent_Winnti_Infrastructure_and_Samples_ClearSky_Cybersecurity.pdf
ID: 47d6aa00-9cc1-4fd3-b2b8-cd20fbd83233
STIX ID: report--47d6aa00-9cc1-4fd3-b2b8-cd20fbd83233
Threat Score
78/100
Uploaded: 2026-08-14
Published Date: 2017-07-19
Last Modified Date: 2017-07-19
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ClearSky reports detecting a malicious RTF (curriculum vitae.rtf) exploiting CVE-2017-0199 used by the Winnti APT to download and execute a payload (shell.exe); the post provides IOCs (domains, IPs, hashes, filenames), the C2 domain backup.aolonline.cc and notes links to broader Winnti/LEAD infrastructure and related samples.
