OTX-686e3015617386ee38c7d6d1
high
📛 Threat Title
ShadowPad - C2 IP/Domain Tracker
Description
This pulse contains IOCs related to ShadowPad Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds. Pulse contains 2 indicator(s) (IOCs). View on OTX to inspect.
Indicators of Compromise (5)
Each indicator is enriched from the IOC database, threat-intel feed corroboration (Threat Hunt) and VirusTotal. Click one to expand.
ipv4
122.114.166.126
IOC database
- Type
- ipv4
- Value
122.114.166.126- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
106.52.243.150
IOC database
- Type
- ipv4
- Value
106.52.243.150- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
43.153.63.174
IOC database
- Type
- ipv4
- Value
43.153.63.174- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
122.114.12.82
IOC database
- Type
- ipv4
- Value
122.114.12.82- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
No VirusTotal details cached for this IOC. Open the IOC page to query VirusTotal.
ipv4
122.114.252.115
VT: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/122.114.252.115
IOC database
- Type
- ipv4
- Value
122.114.252.115- First seen
- Last seen
- Attached to this threat
- Appears in
- 1 threat
Threat Hunt — feed corroboration
Not present in any configured threat-intel feed.
Details From VirusTotal
VirusTotal: VT base fetch failed: HTTPError: 429 Too Many Requests for ip_addresses/122.114.252.115
References (1)
-
OTX pulse
AlienVaulkt OTX
This pulse contains IOCs related to ShadowPad Infrastructure. Additions are automatically added based on several sources like: OTX sandboxes samples, internal tools, through the use of Shodan or Censys queries, shared intel from LevelBlue partners or external feeds.
Remediations (8)
-
web:attack.mitre.org
ShadowPad is a modular backdoor that was first identified in a supply chain compromise of the NetSarang software in mid-July 2017. The malware was originally thought to be exclusively used by APT41, but has since been observed to be used by various Chinese threat activity groups.
-
web:github.com
Command and Control T1140 - Deobfuscate/Decode Files or Information ShadowPad has decrypted a binary blob to start execution. Command and Control T1568.002 - Dynamic Resolution: Domain Generation Algorithms ShadowPad uses a DGA that is based on the day of the month for C2 servers.
-
web:hunt.io
Learn about ShadowPad , a sophisticated backdoor malware used by Chinese threat actors. Discover its variants, targeted industries, and effective mitigation strategies.
-
web:medium.com
Identifying & Tracking ShadowPad Infrastructure SSL Certificate Pivoting from 02 Scenarios ShadowPad is a modular Remote Access Trojan (RAT) that is believed to be developed by the Chinese-State …
-
web:technewsday.com
VMware Threat Analysis Unit (TAU) have uncovered 85 command-and-control ( C2 ) servers supported by ShadowPad malware since September 2021. ShadowPad is a modular backdoor known among China-based threat actors, including such clusters of espionage activities.
-
web:windowsforum.com
Attackers have weaponized a recently patched Windows Server Update Services (WSUS) remote code execution bug (CVE‑2025‑59287) to gain SYSTEM-level access to WSUS hosts and deliver the ShadowPad backdoor, using native Windows tools and simple staging techniques that make detection and containment difficult for unprepared organizations.
-
web:www.atheniantech.com
The ShadowPad malware is written in C and Assembly language, specifically for Windows OS. It provides a backdoor for gaining unauthorized access to the victim's data and transfer it to the C&C Server.
-
web:www.sophos.com
This attribution of ShadowPad campaigns to theater commands is based on the submitter's location for ShadowPad malware samples uploaded to the VirusTotal analysis service (potentially indicating the victim's country), the C2 domain names that appear to reference specific regions (e.g., cloudvn. info suggests Vietnam targeting), contextual ...
AI Forensic Analysis
Only Available for Registered Users. Sign in to view.