INTEL_REPORT
ESET WeLiveSecurity · published 5/20/2026, 8:40:00 AM · TLP amber
Summary
Ingested excerpt (first ~500 chars of normalized text).
Webworm: New burrowing techniques ESET researchers describe new tools and techniques that the Webworm APT group recently added to its arsenal Webworm: New burrowing techniques Award-winning news, views, and insight from the ESET security community English Español Deutsch Português Français TIPS & ADVICE BUSINESS SECURITY ESET RESEARCH About ESET Research Blogposts Podcasts White papers Threat reports WeLiveScience FEATURED Ukraine crisis – Digital security resource cent…
https://www.welivesecurity.com/en/eset-research/webworm-new-burrowing-techniques
sha256:4fc77c27339570dd1253f2e3ecb11e8f57127cbf1bc0b21e90ba8044470cc74e
What we pulled out
Deterministic extractor (IOC + allowlisted tokens + ATT&CK IDs present in DB).
Indicators
Linked with report → mentions → indicator. Values open the indicator workspace.
Malware families
Allowlist token matches only.
Threat actors mentioned
Allowlist mentions — not a formal attribution verdict.
ATT&CK techniques
MITRE IDs referenced in text and present in local technique table.
CONTINUE INVESTIGATION
High-signal pivots without leaving the thread you started in search.
Browse the report corpus.
Neighborhood from the first linked indicator.
| Open → |
| ip | 108.61.200.151 | Open → |
| ip | 144.168.60.233 | Open → |
| domain | wamanharipethe.s3.ap | Open → |
| domain | amazonaws.com | Open → |
| domain | whpjewellers.s3.amazonaws.com | Open → |
| domain | secretsdump.py | Open → |
| domain | config.dat | Open → |
| domain | alive.txt | Open → |
| domain | wamanharipethe.s3.ap-south-1.amazonaws.com | Open → |
| domain | socket.io | Open → |
| domain | searchapp.exe | Open → |
| domain | agent.zk | Open → |
| domain | ssh.exe | Open → |
| domain | proxy.ae | Open → |
| domain | svc.exe | Open → |
| domain | 0316.exe | Open → |
| domain | agent.vwd | Open → |
| domain | dsocks.exe | Open → |
| domain | s3.ap | Open → |
| url | https://github.com/anjsdgasdf/WordPress | Open → |
| cve | CVE-2017-7692 | Open → |