logo

Microsoft Word - ASERT Threat Intelligence Brief 2014-07 Illuminating Etumbot APT.docx

ID: b5fad715-42d2-4e85-a20a-1beda7a83570

STIX ID: report--b5fad715-42d2-4e85-a20a-1beda7a83570

Threat Score

85/100

Uploaded: 2026-08-07

Published Date: 2014-06-06

Last Modified Date: 2014-06-06

Created by: dogesec

TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
ASERT's brief analyzes the Etumbot backdoor (linked to Numbered Panda/IXESHE), detailing its two-stage installer/dropper and backdoor components, spearphishing delivery (often .7z/.rar with RTLO and password protection), persistence mechanisms, RC4-encrypted HTTP C2 protocol and commands (execute, upload, download, sleep, uninstall), use of HTran bouncers, associated file artifacts and numerous MD5s and C2 IPs/domains. The report includes campaign timelines (2011–2014), decoy documents targeting Taiwanese/Japanese interests, detection artifacts (byte-string/string-stacking), and actionable IoCs for network and host-based detection.