2022-03-28 21:36:07 +01:00

15 KiB

1TypeIndicatorContextSource
2emailjowhar@xintongwood.clubMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
3emailbabu.d@tvsrubber.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
4emailciti.in.pm@xerago.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
5emaildean.ds@msruas.ac.inMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
6emailin-nonciti.basupport@xerago.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
7emailinfo@empiink.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
8emailnarayanababu.py.ph@msruas.ac.inMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
9emailnshcorp@nshcorp.inMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
10emailomars@salecharter.netMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
11emailpooja.fa@msruas.ac.inMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
12emailproductionbelgavi@hodekindia.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
13emailpurchase2@hitechelastomers.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
14emailqs@gsengint.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
15emailrakesh.ict@msruas.ac.inMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
16emailroopa.tsld@msruas.ac.inMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
17emailsec.ls@msruas.ac.inMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
18emailsysteam@xerago.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
19emailvaishnavi.kj@tvsrubber.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317539153738683
20emailmuthuprakash.b@tvsrubber.comMailbox leveraged by Russian APTshxxps://www.facebook[.]com/UACERT/posts/317482093744389
21URLhxxp://consumerspanel[.]frge.io/Phishing page targeting Ukrainehxxps://www.facebook[.]com/UACERT/posts/317482093744389
22Domainconsumerspanel[.]frge.ioPhishing page targeting Ukrainehxxps://www.facebook[.]com/UACERT/posts/317482093744389
23MD565237e705e842da0a891c222e57fe095microbackdoor.dll (MicroBackdoor)hxxps://cert.gov.ua/article/37626
24URLhxxps://cdn.discordapp.com/attachments/947916997713358890/949948174636830761/one.exeUAC-0056 grouphxxps://cert.gov.ua/article/37704
25URLhxxps://cdn.discordapp.com/attachments/947916997713358890/949948174838165524/dropper.exeUAC-0056 grouphxxps://cert.gov.ua/article/37704
26URLhxxps://cdn.discordapp.com/attachments/947916997713358890/949978571680673802/cesdf.exeUAC-0056 grouphxxps://cert.gov.ua/article/37704
27IPv4156.146.50.5UAC-0056 grouphxxps://cert.gov.ua/article/37704
28MD515c525b74b7251cfa1f7c471975f3f95(Go downloader) UAC-0056 grouphxxps://cert.gov.ua/article/37708
29MD52fdf9f3a25e039a41e743e19550d4040(Discord downloader) UAC-0056 grouphxxps://cert.gov.ua/article/37708
30MD54f11abdb96be36e3806bada5b8b2b8f8(GrimPlant) UAC-0056 grouphxxps://cert.gov.ua/article/37708
31MD59ad4a2dfd4cb49ef55f2acd320659b83(Discord downloader) UAC-0056 grouphxxps://cert.gov.ua/article/37708
32MD59ea3aaaeb15a074cd617ee1dfdda2c26(GraphSteel) UAC-0056 grouphxxps://cert.gov.ua/article/37708
33MD5aa5e8268e741346c76ebfd1f27941a14(Cobalt Strike Beacon) UAC-0056 grouphxxps://cert.gov.ua/article/37708
34MD5b8b7a10dcc0dad157191620b5d4e5312UAC-0056 grouphxxps://cert.gov.ua/article/377108
35MD5c8bf238641621212901517570e96fae7(Go downloader) UAC-0056 grouphxxps://cert.gov.ua/article/37708
36MD5ca9290709843584aecbd6564fb978bd6(bait document) UAC-0056 grouphxxps://cert.gov.ua/article/37708
37MD5cf204319f7397a6a31ecf76c9531a549(bait document) UAC-0056 grouphxxps://cert.gov.ua/article/37708
38IPv445.84.0.116UAC-0056 grouphxxps://cert.gov.ua/article/37708
39URLhxxp://45.84.0.116:443/cUAC-0056 grouphxxps://cert.gov.ua/article/37708
40URLhxxp://45.84.0.116:443/iUAC-0056 grouphxxps://cert.gov.ua/article/37708
41URLhxxp://45.84.0.116:443/mUAC-0056 grouphxxps://cert.gov.ua/article/37708
42URLhxxp://45.84.0.116:443/pUAC-0056 grouphxxps://cert.gov.ua/article/37708
43URLhxxps://forkscenter.fr/BitdefenderWindowsUpdatePackage.exeUAC-0056 grouphxxps://cert.gov.ua/article/37708
44URLhxxps://forkscenter.fr/Sdghrt_umrj6/wisw.exeUAC-0056 grouphxxps://cert.gov.ua/article/37708
45URLhxxps://nirsoft.me/nEDFzTtoCbUfp9BtSZlaq6ql8v6yYb/avp/amznussraps/UAC-0056 grouphxxps://cert.gov.ua/article/37708
46URLhxxps://nirsoft.me/s/2MYmbwpSJLZRAtXRgNTAUjJSH6SSoicLPIrQl/field-keywords/UAC-0056 grouphxxps://cert.gov.ua/article/37708
47domainforkscenter.frUAC-0056 grouphxxps://cert.gov.ua/article/37708
48domainnirsoft.meUAC-0056 grouphxxps://cert.gov.ua/article/37708
49URLhxxps://tinyurl[.]com/2p8kpb9vUAC-0028 grouphxxps://cert.gov.ua/article/37788
50Hostnamepanelunregistertle-348.frge[.]ioUAC-0028 grouphxxps://cert.gov.ua/article/37788
51Hostnameeo9p1d2bfmioiot.m.pipedream[.]netUAC-0028 grouphxxps://cert.gov.ua/article/37788
52Hostnameeoiw8lhjwuc3sh2.m.pipedream[.]netUAC-0028 grouphxxps://cert.gov.ua/article/37788
53MD500a54a6496734d87dab6685aa90588f8UAC-0020 grouphxxps://cert.gov.ua/article/37818
54MD51c2c41a5a5f89eccafea6e34183d5db9UAC-0020 grouphxxps://cert.gov.ua/article/37818
55MD532343f2a6b8ac9b6587e2e07989362abUAC-0020 grouphxxps://cert.gov.ua/article/37818
56MD53ed8263abe009c19c4af8706d52060f8UAC-0020 grouphxxps://cert.gov.ua/article/37818
57MD55db4313b8dbb9204f8f98f2c129fd734UAC-0020 grouphxxps://cert.gov.ua/article/37818
58MD567274bdd5c9537affbd51567f4ba8d5fUAC-0020 grouphxxps://cert.gov.ua/article/37818
59MD575e1ce42e0892ed04a43e3b68afdbc07UAC-0020 grouphxxps://cert.gov.ua/article/37818
60MD5993415425b61183dd3f900d9b81ac57fUAC-0020 grouphxxps://cert.gov.ua/article/37818
61MD5adebdc32ef35209fb142d44050928083UAC-0020 grouphxxps://cert.gov.ua/article/37818
62MD5baf502b4b823b6806cc91e2c1dd07613UAC-0020 grouphxxps://cert.gov.ua/article/37818
63MD5d0632ef34514bbb0f675c59e6ecca717UAC-0020 grouphxxps://cert.gov.ua/article/37818
64MD5d34dbbd28775b2c3a0b55d86d418f293UAC-0020 grouphxxps://cert.gov.ua/article/37818
65MD5e08d7c4daa45beca5079870251e50236UAC-0020 grouphxxps://cert.gov.ua/article/37818
66MD5ecc7bb2e4672b958bd82fe9ec9cfab14UAC-0020 grouphxxps://cert.gov.ua/article/37818
67MD5f0197bbb56465b5e2f1f17876c0da5baUAC-0020 grouphxxps://cert.gov.ua/article/37818
68IPv4176.119.2.212UAC-0020 grouphxxps://cert.gov.ua/article/37815
69IPv4176.119.2.214UAC-0020 grouphxxps://cert.gov.ua/article/37815
70IPv4176.119.5.194UAC-0020 grouphxxps://cert.gov.ua/article/37815
71IPv4176.119.5.195UAC-0020 grouphxxps://cert.gov.ua/article/37815
72URLhttp://176.119.2.212/web/t/data.outUAC-0020 grouphxxps://cert.gov.ua/article/37815
73URLhttp://176.119.5.195/k9otb49xqUAC-0020 grouphxxps://cert.gov.ua/article/37815
74URLhttp://getmod.host/DSGb3Y3XUAC-0020 grouphxxps://cert.gov.ua/article/37815
75URLhttp://getmod.host/OcthdaLmUAC-0020 grouphxxps://cert.gov.ua/article/37815
76URLhttp://getmod.host/ThlAHy3SUAC-0020 grouphxxps://cert.gov.ua/article/37815
77URLhttp://getmod.host/25s2mhUAC-0020 grouphxxps://cert.gov.ua/article/37815
78domaingetmod.hostUAC-0020 grouphxxps://cert.gov.ua/article/37815
79domainmeteolink.hostUAC-0020 grouphxxps://cert.gov.ua/article/37815
80domainnetbin.hostUAC-0020 grouphxxps://cert.gov.ua/article/37815
81domainstormpredictor.hostUAC-0020 grouphxxps://cert.gov.ua/article/37815
82domainsyncapp.hostUAC-0020 grouphxxps://cert.gov.ua/article/37815
83URLhxxp://45.95.11.34:88/get.phpUAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
84FileHash-MD503f12262a2846ebbce989aca5cec74a7UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
85FileHash-MD55fb6202b8273a6a4cda73cee3f88ce1aUAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
86FileHash-MD572ed59f0d293ceede46bd69a09322f30UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
87FileHash-MD5cd1a425e1ac6bc029fb4418523e43e88UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
88FileHash-MD5dfb5a03f56769e3d1195bdfe6bb62070UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
89FileHash-SHA256090997b4691f1a155187a181dbf54aec034eafc7b9344016867fe50da15829dfUAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
90FileHash-SHA2564df873ea077bdbfe5389d30b5b0d0ad4a3fa663af4a4109859b61eb7f6099fc8UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
91FileHash-SHA2565e06d688ac955b351c3ced0083dc7e372e447458e6604fd82ac118a6ac8e553cUAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
92FileHash-SHA2566b721ab9f73718c393aca2b9ad06f45b09dbfb23d105ca5872d8df7515ae14c4UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
93FileHash-SHA256fd72080eca622fa3d9573b43c86a770f7467f3354225118ab2634383bd7b42ebUAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
94IPv445.95.11.34UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
95URLhxxp://45.95.11.34:3000/testUAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
96URLhxxp://45.95.11.34:88/_[A-Z0-9]UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
97URLhxxp://45.95.11.34:88/get.php?a=We4Qu6UAC-0035 (InvisiMole)hxxps://cert.gov.ua/article/37829
98FileHash-MD536dc2a5bab2665c88ce407d270954d04UAC-0088 DoubleZerohxxps://cert.gov.ua/article/38088
99FileHash-MD57d20fa01a703afa8907e50417d27b0a4UAC-0088 DoubleZerohxxps://cert.gov.ua/article/38088
100FileHash-MD5989c5de8ce5ca07cc2903098031c7134UAC-0088 DoubleZerohxxps://cert.gov.ua/article/38088
101FileHash-MD5b4f0ca61ab0c55a542f32bd4e66a7dc2UAC-0088 DoubleZerohxxps://cert.gov.ua/article/38088
102FileHash-SHA25630b3cbe8817ed75d8221059e4be35d5624bd6b5dc921d4991a7adc4c3eb5de4aUAC-0088 DoubleZerohxxps://cert.gov.ua/article/38088
103FileHash-SHA2563b2e708eaa4744c76a633391cf2c983f4a098b46436525619e5ea44e105355feUAC-0088 DoubleZerohxxps://cert.gov.ua/article/38088
104FileHash-SHA2568dd8b9bd94de1e72f0c400c5f32dcefc114cc0a5bf14b74ba6edc19fd4aeb2a5UAC-0088 DoubleZerohxxps://cert.gov.ua/article/38088
105FileHash-SHA256d897f07ae6f42de8f35e2b05f5ef5733d7ec599d5e786d3225e66ca605a48f53UAC-0088 DoubleZerohxxps://cert.gov.ua/article/38088
106URLhxxps://product2020.mrbasic.com:8080UAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
107hostnameproduct2020.mrbasic[.]comUAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
108FileHash-MD513612c99a38b2b07575688c9758b72ccUAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
109FileHash-MD51aba36f72685c12e60fb0922b606417cUAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
110FileHash-MD51af894a5f23713b557c23078809ed01cUAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
111FileHash-MD53293ba0e2eaefbe5a7c3d26d0752326eUAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
112FileHash-MD54fb630f9c5422271bdd4deb94a1e74f4UAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
113FileHash-MD59c22548f843221cc35de96d475148ecfUAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
114FileHash-SHA256042271aadf2191749876fc99997d0e6bdd3b89159e7ab8cd11a9f13ae65fa6b1UAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
115FileHash-SHA25663a218d3fc7c2f7fcadc0f6f907f326cc86eb3f8cf122704597454c34c141cf1UAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
116FileHash-SHA256830c6ead1d972f0f41362f89a50f41d869e8c22ea95804003d2811c3a09c3160UAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
117FileHash-SHA256839e968aa5a6691929b4d65a539c2261f4ecd1c504a8ba52abbfbac0774d6fa3UAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
118FileHash-SHA256a2ffd62a500abbd157e46f4caeb91217738297709362ca2c23b0c2d117c7df38UAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
119FileHash-SHA256c0962437a293b1e1c2702b98d935e929456ab841193da8b257bd4ab891bf9f69UAC-0026 HeaderTiphxxps://cert.gov.ua/article/38097
120URLhxxp://ao3[.]hmgo[.]pw/tags/Akihabara@TODEEP/worksUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
121URLhxxp://ao3[.]hmgo[.]pw/tags/Akihabara@TODEEP/works/updateUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
122URLhxxp://ao3[.]hmgo[.]pwUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
123URLhxxps://ao3[.]hmgo[.]pwUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
124FileHash-MD51365b82e7da0968e97c095d8bd9166ddUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
125FileHash-MD518e73cc3d5eda742530ba3fef59e3943UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
126FileHash-MD53303286735a07ae5d14db9c12843d44eUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
127FileHash-MD54a78df33d4f987103dc0c0f3a302b8cbUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
128FileHash-MD5b5525108912ee8d5f1519f1b552723e8UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
129FileHash-MD5b724ff750dff495e6634ddf0f1263844UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
130FileHash-MD5bcdab4ae622811f699765bfb9cb909d2UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
131FileHash-MD5e4b54ee2f0068762179e7e514d90bf16UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
132FileHash-SHA25637e644deee0add76bac9c5121355a03a459b1a97917383765bf3df94e9af7e29UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
133FileHash-SHA25659ed536e1955e310f321435d43ca8b60cb3746514f3c3ea951d43633cacbe7bcUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
134FileHash-SHA2566149680c8541980d46c17681e37e4751e2baca1d13ee648b8188dfb24bf56f7cUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
135FileHash-SHA2567cf3f758b2abb303dec89736dfd55c38309a21aec2d83d3d4e590f9538fc5f15UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
136FileHash-SHA256c14fce93183dc4173be02b2a48d1ed06b43656c7b6d5a290d9948b6947df9033UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
137FileHash-SHA256d324d7f30984931176ff878a81c7c1f4f979ad3d759c7f33427bba10d9deb1f6UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
138FileHash-SHA256f98e1e61c84a5ed098e7481ab339e2881195f4d1b101c92b81113eb7ff56e63dUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
139FileHash-SHA256fbabc4e5a6470606fc64c39c182b5a7a71f8fa96f50c67725d52abf184f75fd4UAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
140domaindhdhk0k34[.]comUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
141domainhmgo[.]pwUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
142hostnameao3[.]hmgo[.]pwUAC-0051 (UNC1151)hxxps://cert.gov.ua/article/38155
143hostnamewebdavml07[.]bplaced[.]netUAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371
144FileHash-MD555cafceba527c3e68852b1af071929c0UAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371
145FileHash-MD55d29da2285390164a0a7d80e6ed23da7UAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371
146FileHash-MD5878c30bdefb1b76ea10823a6d5a32f89UAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371
147FileHash-MD5eda76ae28628c64d9e12a86adef6dc69UAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371
148FileHash-SHA25613eaa638d071e7dc124cf982b8777c6ef50a3d9dc8c57d22d23abe1bae5560f5UAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371
149FileHash-SHA25678b492e211e91b1ef9a4bcd5ba80c9572545d5f3f63d3071e3253dcec3a5d97cUAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371
150FileHash-SHA256bab351b5f19ecaa24eaa438dd93decd5587e0b441fc43b78893ca2e207b2cb2fUAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371
151FileHash-SHA256c50972c11ffd1da9e0ed670b99296f75ec52933699790285d050c0654c21fda3UAC-0010 (Gamaredon)hxxps://cert.gov.ua/article/38371