AridViper__2020__Mapping_out_AridViper_Infrastructure_Using_Augury_s_Malware_Module_Team_Cymru.pdf
ID: 53a237a4-1dc4-4394-86d0-c3e7923ef121
STIX ID: report--53a237a4-1dc4-4394-86d0-c3e7923ef121
Threat Score
82/100
Uploaded: 2026-08-14
Published Date: 2020-12-17
Last Modified Date: 2020-12-17
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report describes an investigation using the Augury malware module to map AridViper (APT-C-23/GnatSpy) infrastructure: starting from a seed packed Windows executable (hash faff57734fe08af63e90c0492b4a9a56) the analyst pivoted on a discovered C2 (judystevenson.info), a dropped artifact (C:\ProgramData\GUID.bin), a distinctive Googlebot-like user-agent, ImpHash and AV signatures, ultimately identifying ~40 malware samples communicating with 13 command-and-control domains and associated passive DNS/hosting data (noting frequent use of NameCheap infrastructure).
