APT28__2018__20180713_CSE_APT28_X-Agent_Op-Roman_Holiday-Report_v6_1.pdf
ID: b97ae31d-6f60-42ac-a1f9-3090856c6a32
STIX ID: report--b97ae31d-6f60-42ac-a1f9-3090856c6a32
Threat Score
85/100
Uploaded: 2026-08-07
Published Date: 2018-07-15
Last Modified Date: 2018-07-15
Created by: dogesec
TLP:CLEAR
ADMIRALTY:B2
PAP:CLEAR
...
...
This report analyzes a multi-stage malware campaign attributed to APT28 (X‑Agent), describing four Delphi-based droppers (two UPX-packed), a secondary payload upnphost.exe that embeds an AutoIt script and communicates via HTTPS to multiple C2 IPs (45.124.132.127, 46.183.218.37) and a Delphi DLL (sdbn.dll) resolving to marina-info.net; it documents persistence, network traffic, WHOIS data, VirusTotal detection results, extracted IOCs (hashes, domains, IPs), and YARA rules for detection.
