Microsoft Word - ASERT Threat Intelligence Brief 2014-07 Illuminating Etumbot APT.docx
ID: b5fad715-42d2-4e85-a20a-1beda7a83570
STIX ID: report--b5fad715-42d2-4e85-a20a-1beda7a83570
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2014-06-06
Last Modified Date: 2014-06-06
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ASERT's brief analyzes the Etumbot backdoor (linked to Numbered Panda/IXESHE), detailing its two-stage installer/dropper and backdoor components, spearphishing delivery (often .7z/.rar with RTLO and password protection), persistence mechanisms, RC4-encrypted HTTP C2 protocol and commands (execute, upload, download, sleep, uninstall), use of HTran bouncers, associated file artifacts and numerous MD5s and C2 IPs/domains. The report includes campaign timelines (2011–2014), decoy documents targeting Taiwanese/Japanese interests, detection artifacts (byte-string/string-stacking), and actionable IoCs for network and host-based detection.
