s2
--:--:--UTC

Searching APEX

Starting…

  1. Searching Threats, IOCs & Threat Intelligence locally
  2. Querying external providers
  3. Asking AI Forensic Validator
  4. Creating new entry from validated hit

0s elapsed

OTX-686e3015617386ee38c7d6d1 high

📛 Threat Title

ShadowPad - C2 IP/Domain Tracker

Category: ShadowPad Published: Source updated: First seen: Last updated: Source: AlienVaulkt OTX

Description

This pulse contains IOCs related to ShadowPad Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.

Indicators of Compromise (5)

Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.

ipv4 122.114.166.126

IOC database

Type
ipv4
Value
122.114.166.126
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 106.52.243.150

IOC database

Type
ipv4
Value
106.52.243.150
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 43.153.63.174

IOC database

Type
ipv4
Value
43.153.63.174
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 122.114.12.82

IOC database

Type
ipv4
Value
122.114.12.82
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.

ipv4 122.114.252.115 VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/122.114.252.115

IOC database

Type
ipv4
Value
122.114.252.115
First seen
Last seen
Attached to this threat
Appears in
1 threat

Open the full IOC page →

Threat Hunt — feed corroboration

Not present in any configured threat-intel feed.

Details From VirusTotal

VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/122.114.252.115

References (1)

  • OTX pulse AlienVaulkt OTX

    This pulse contains IOCs related to ShadowPad Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.

Remediations (8)

  • web:attack.mitre.org

    ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by APT41, but has since been observed to be used by various Chinese threat activity groups.

  • web:github.com

    Command and Control T1140 - Deobfuscate/Decode Files or Information ShadowPad has decrypted a binary blob to start execution. Command and Control T1568.002 - Dynamic Resolution: Domain Generation Algorithms ShadowPad uses a DGA that is based on the day of the month for C2 servers.

  • web:hunt.io

    Learn about ShadowPad , a sophisticated backdoor malware used by Chinese threat actors. Discover its variants, targeted industries, and effective mitigation strategies.

  • web:medium.com

    Identifying & Tracking ShadowPad Infrastructure SSL Certificate Pivoting from 02 Scenarios ShadowPad is a modular Remote Access Trojan (RAT) that is believed to be developed by the Chinese-State …

  • web:technewsday.com

    VMware Threat Analysis Unit (TAU) have uncovered 85 command-and-control ( C2 ) servers supported by ShadowPad malware since September 2021. ShadowPad is a modular backdoor known among China-based threat actors, including such clusters of espionage activities.

  • web:windowsforum.com

    Attackers have weaponized a recently patched Windows Server Update Services (WSUS) remote code execution bug (CVE‑2025‑59287) to gain SYSTEM-level access to WSUS hosts and deliver the ShadowPad backdoor, using native Windows tools and simple staging techniques that make detection and containment difficult for unprepared organizations.

  • web:www.atheniantech.com

    The ShadowPad malware is written in C and Assembly language, specifically for Windows OS. It provides a backdoor for gaining unauthorized access to the victim's data and transfer it to the C&C Server.

  • web:www.sophos.com

    This attribution of ShadowPad campaigns to theater commands is based on the submitter's location for ShadowPad malware samples uploaded to the VirusTotal analysis service (potentially indicating the victim's country), the C2 domain names that appear to reference specific regions (e.g., cloudvn. info suggests Vietnam targeting), contextual ...

AI Forensic Analysis

Only Available for Registered Users. Sign in to view.

VirusTotal Information

loading…

IP Geolocation

Loading…