Looking Back to Look Forward: The Anthem Breach
ID: 1b3c00a3-91d3-508f-b541-b6693bc8fc2e
STIX ID: report--1b3c00a3-91d3-508f-b541-b6693bc8fc2e
Feed Name: DomainTools
This report summarizes DomainTools/ThreatConnect analysis of the Anthem breach, attributing the large-scale data leak (approximately 80 million records) to Chinese-aligned actors by connecting malware C2 domains (we11point.com, topsec2014.com), IP 192.199.254.126, and registrant emails ([email protected], [email protected]) to a professor at Nanjing Southeast University with potential PLA links; it outlines the investigative steps, key indicators, and practical defensive recommendations such as monitoring typo-squatter domains and using reverse WHOIS and history tools.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
