APT21__2016__NetTraveler_Spear-Phishing_Email_Targets_Diplomat_of_Uzbekistan_-_Palo_Alto_Networks_BlogPalo_Alto_Networks_Blog.pdf
ID: 4e1aa1e7-5e59-4497-8146-856c66c4e3f3
STIX ID: report--4e1aa1e7-5e59-4497-8146-856c66c4e3f3
Threat Score
88/100
Uploaded: 2026-08-07
Published Date: 2016-08-11
Last Modified Date: 2016-08-11
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
Unit 42 describes a targeted NetTraveler spear‑phishing campaign that sent a malicious DOC attachment (exploiting CVE‑2012‑0158) to an Uzbek diplomat in China; the attachment drops a RAR SFX payload that uses DLL side‑loading (Symantec RasTls.exe + malicious rastls.dll) to load a NetTraveler DLL, which writes config.dat/CERTAPL.DLL, contacts C2 (voennovosti.com / 98.126.38.107), and supports download/execute and persistence; the report includes technical indicators (hashes, filenames, config parsing and decryption routines) and behavioral TTPs.
