WebDAV-as-a-Service: Uncovering the infrastructure behind Emmenhtal loader distribution - Sekoia.io Blog
· Published 19/09/2024 19:34 · Modified 19/09/2024 20:37
Essential information
- Published
- 19/09/2024 19:34
- Modified
- 19/09/2024 20:37
- Tags
- 2024-09-19 clearfake darkgate dcrat emmenhtal google cloud marko polo peaklight selfau3 webdav zgrat
- Related entities
- 120 observables, 3 techniques (mitre), 16 malware, 5 others
Description
Related entities
Vulnerabilities, IOCs, intrusion sets, MITRE techniques and other entities referenced in this report.
Observables (120)
95.216.196.8595.164.68.2494.156.8.3194.156.69.694.156.69.11194.156.65.13094.156.64.7694.156.65.12694.156.64.7492.118.112.25394.131.112.20692.118.112.22391.92.254.22591.92.254.16791.92.253.12691.92.251.3591.92.250.15091.92.250.4491.92.250.12391.92.248.9091.92.248.7791.92.248.5091.92.248.12991.92.246.10291.92.243.7491.92.243.19891.92.240.2991.92.240.24791.92.240.23489.23.113.14089.23.107.6789.23.107.25189.23.107.24489.23.107.24089.23.107.18189.23.107.16889.23.107.12389.23.103.9789.23.107.11389.23.103.889.23.103.5689.23.103.5789.23.103.25389.23.103.20589.23.103.18889.23.103.1589.23.103.11889.23.103.12389.110.78.5882.115.223.23484.247.187.23179.137.203.15878.153.139.20262.133.61.9862.133.61.9762.133.61.9062.133.61.7962.133.61.6962.133.61.7362.133.61.4962.133.61.3762.133.61.24062.133.61.20762.133.61.18962.133.61.16862.133.61.15562.133.61.14862.133.61.10662.133.61.10446.29.234.12962.133.61.10145.151.62.238212.18.104.111200.150.194.109206.188.196.28194.87.252.22194.190.152.108193.233.75.13191.243.196.114185.196.8.158185.143.223.188178.209.51.222168.100.9.199151.236.17.180147.45.79.82147.45.50.86147.45.50.57147.45.50.34147.45.50.23147.45.50.26147.45.50.214147.45.50.172147.45.50.144147.45.50.142141.98.234.166147.45.178.54104.131.7.207193.124.33.7191.92.245.22262.133.61.5662.133.61.4362.133.61.2691.92.245.18591.202.233.136http://94.156.64.74/Downloads/SecretTeachings.pdf.lnkhttp://91.92.251.35/Downloads/solaris-docs.lnkhttp://92.118.112.253/Downloads/releaseform.pdf.lnkhttp://91.92.243.198:81/Downloads/test.lnkhttp://89.23.107.67/Downloads/2023-Documents%20Shared.lnkhttp://89.23.107.244/Downloads/Test.lnkhttp://62.133.61.73/Downloads/Photo.lnkhttp://89.23.103.56/Downloads/Videof/Full%20Video%20HD%20%281080p%29.lnkhttp://62.133.61.37/Downloads/config.txt.lnkhttp://62.133.61.104/Downloads/test.pdf.lnkhttp://62.133.61.101/Downloads/Invoice.pdf.lnkhttp://206.188.196.28/Downloads/example.lnkhttp://147.45.50.57/Downloads/INVOICE%20340138551.pdf.lnkhttp://151.236.17.180/Wire%20Confirmation/WireConfirmation.pdf.lnkhttp://147.45.79.82/Downloads/qqeng.pdf.lnkhttp://147.45.50.214/Downloads/demo.pdf.lnk
Techniques (MITRE) (3)
Malware (16)
-
FamilyPublished 19/09/2024 19:34 · Modified 19/09/2024 19:34
-
FamilyPublished 11/10/2025 02:50 · Modified 11/10/2025 02:50
-
FamilyPublished 19/09/2024 19:34 · Modified 19/09/2024 19:34
-
FamilyPublished 19/02/2026 16:01 · Modified 19/02/2026 16:01
-
FamilyPublished 20/08/2025 18:39 · Modified 20/08/2025 18:39
-
FamilyPublished 04/04/2025 07:07 · Modified 04/04/2025 07:07
-
FamilyPublished 03/11/2025 14:28 · Modified 03/11/2025 14:28
-
FamilyPublished 21/08/2025 21:03 · Modified 21/08/2025 21:03
-
FamilyPublished 05/05/2026 18:45 · Modified 05/05/2026 18:45
-
AlienVault Confidence 100First seen 01/01/1970 · Last seen 16/11/5138 Published 20/12/2025 23:50 · Modified 21/12/2025 16:13
-
FamilyPublished 27/03/2026 08:45 · Modified 27/03/2026 08:45
-
FamilyPublished 08/05/2026 11:31 · Modified 08/05/2026 11:31
-
FamilyPublished 19/09/2024 19:34 · Modified 19/09/2024 19:34
-
Family The MITRE Corporation Confidence 100
[Amadey](https://attack.mitre.org/software/S1025) is a Trojan bot that has been used since at least October 2018.(Citation: Korean FSI TA505 2020)(Citation: BlackBerry Amadey 2020)
First seen 01/01/1970 · Last seen 16/11/5138 Published 14/07/2022 19:30 · Modified 27/03/2026 01:03 -
FamilyPublished 21/08/2025 00:37 · Modified 21/08/2025 00:37
-
FamilyPublished 11/06/2026 16:31 · Modified 11/06/2026 16:31
Others (5)
- Gaming
- Cryptocurrency
- Technology
- Media
- Financial