Operation DustySky
Image Description
Common Information
Type Value
UUID 11aed187-a84e-4844-ab32-058ace910f18
Fingerprint 152d75e5e6d75c9d029194eba97d80497d16c9f54178e72ae89c1693987dcd63
Analysis status DONE
Considered CTI value 2
Text language
Published Jan. 7, 2016, 3:46 p.m.
Added to db March 10, 2024, 3:27 a.m.
Last updated Aug. 31, 2024, 8:06 a.m.
Headline Operation DustySky
Title Operation DustySky
Detected Hints/Tags/Attributes 142/3/368
Attributes
Details Type #Events CTI Value
Details Domain 26
clearskysec.com
Details Domain 3
www.seculert.com
Details Domain 403
securelist.com
Details Domain 1
spynews.otzo.com
Details Domain 3
copy.com
Details Domain 1
imazing.ga
Details Domain 1
www.nrg.co.il
Details Domain 5
www.passivetotal.org
Details Domain 1
ns.suppoit.xyz
Details Domain 1
supo.mefound.com
Details Domain 5
freelancer.com
Details Domain 1
www.cz.freelancer.com
Details Domain 6
securityxploded.com
Details Domain 1
privatetunnel.com
Details Domain 201
msdn.microsoft.com
Details Domain 1
facetoo.co
Details Domain 1
ra.goaglesmtp.co.vu
Details Domain 1
down.supportcom.xyz
Details Domain 1
bulk-smtp.xyz
Details Domain 1
email-market.ml
Details Domain 1
smtp.gq
Details Domain 4
update.ciscofreak.com
Details Domain 3
dnsfor.dnsfor.me
Details Domain 17
whois.domaintools.com
Details Domain 1
fac.tk
Details Domain 1
info.intarspace.co.vu
Details Domain 1
support.markting-fac.tk
Details Domain 1
singin.loginto.me
Details Domain 1
sales-spy.ml
Details Domain 5
details.zip
Details Domain 1
news.net-freaks.com
Details Domain 1
mailweb.otzo.com
Details Domain 1
ed3qy5yioryitoturysuiu.otzo.com
Details Domain 1
dfwsd.co.vu
Details Domain 3
cnaci8gyolttkgmguzog.ignorelist.com
Details Domain 1
0arfx4grailorhvlicbj.servehumour.com
Details Domain 1
hr.goaglesmtp.co.vu
Details Domain 194
drive.google.com
Details Domain 1
news20158.co.vu
Details Domain 1
directexe.com
Details Domain 6
video.zip
Details Domain 155
yandex.com
Details Domain 1174
gmail.com
Details Domain 1
news.bulk-smtp.xyz
Details Domain 4
mossad.gov.il
Details Domain 1
support-sales.tk
Details Domain 1
star.yaneom.space
Details Domain 1
yaneom.space.co
Details Domain 1
yaneom.ml
Details Domain 1
xr.downloadcor.xyz
Details Domain 1
wembail.supportmai.cf
Details Domain 1
wallnet.zyns.com
Details Domain 1
version.downloadcor.xyz
Details Domain 1
v6.support-sales.tk
Details Domain 1
us.suppoit.xyz
Details Domain 1
transkf.tk
Details Domain 1
suppot-sales.mefound.com
Details Domain 3
supports.mefound.com
Details Domain 1
support.mypsx.net
Details Domain 1
support.bkyane.xyz
Details Domain 1
sup.mefound.com
Details Domain 1
submit.mrface.com
Details Domain 1
sub.submitfda.co.vu
Details Domain 1
star.mefound.com
Details Domain 1
socks.israel-shipment.xyz
Details Domain 1
smtpa.dynamic-dns.net
Details Domain 1
smtp.email-test.ml
Details Domain 1
sky.otzo.com
Details Domain 1
sip.supportcom.xyz
Details Domain 1
ser.esmtp.biz
Details Domain 1
salesmarkting.co.vu
Details Domain 1
sales.suppoit.xyz
Details Domain 1
sales.blogsyte.com
Details Domain 1
ms.suppoit.xyz
Details Domain 1
mossad.mefound.com
Details Domain 1
marktingvb.ml
Details Domain 1
markit.mefound.com
Details Domain 1
marki.mefound.com
Details Domain 1
krowd.downloadcor.xyz
Details Domain 1
jenneaypreff.linkpc.net
Details Domain 1
jake.support-sales.tk
Details Domain 1
iphonenewsd.co.vu
Details Domain 1
infoblusa.tk
Details Domain 1
idf.idfcom.co.vu
Details Domain 1
hostgatr.mrface.com
Details Domain 1
hdgshfdgh.co.vu
Details Domain 1
games.buybit.us
Details Domain 1
gamail.goaglesmtp.co.vu
Details Domain 1
gabro.xxuz.com
Details Domain 1
facetoo.co.vu
Details Domain 1
email-test.ml
Details Domain 1
emailotest.co.vu
Details Domain 2
drivres-update.info
Details Domain 1
down.downloadcor.xyz
Details Domain 1
direct-marketing.ml
Details Domain 1
cl170915.otzo.com
Details Domain 1
buy.israel-shipment.xyz
Details Domain 1
baz.downloadcor.xyz
Details Domain 1
aqs.filezellasd.co.vu
Details Domain 1
acc.buybit.us
Details Domain 1
aaas.mefound.com
Details Domain 1
skynews1.blogsyte.com
Details Domain 1
goodwebmail.tk
Details Domain 1
0n4tblbdfncaauxioxto.ddns.net
Details Domain 1
cyaxsnieccunozn0erih.mefound.com
Details Domain 1
word.2waky.com
Details Domain 1
us-update.com
Details Domain 1
sales.intarspace.co.vu
Details Domain 1
newdowr.otzo.com
Details Domain 1
new.newlan.co.vu
Details Domain 1
lkvz7bsfuiaidsyynu7bd2owpe.dns05.com
Details Domain 1
gfhbgfzfgfgfgdg.otzo.com
Details Domain 1
3tshhm1nfphiqqrxbi8c.servehumour.com
Details Domain 1
nabzerd.co.vu
Details Domain 1
debka.ga
Details Domain 1
dontrplay.tk
Details Domain 1
zapt.zapto.org
Details Domain 1
news015.otzo.com
Details Domain 1
news.buybit.us
Details Domain 1
markting-fac.tk
Details Domain 1
adfdafsggdfgdfgsagaer.blogsyte.com
Details Domain 1
helthnews.ga
Details Domain 1
googledomain.otzo.com
Details Domain 1
accounts-helper.ml
Details Domain 1
www.dorcertg.otzo.com
Details Domain 1
directl.otzo.com
Details Domain 1
filezellla.otzo.com
Details Domain 3
ksm5sksm5sksm5s.zzux.com
Details Domain 1
markting.mefound.com
Details Domain 1
vbdodo.mefound.com
Details Email 1
cn=email-market.ml/emailaddress=info@email-market.ml
Details Email 1
emailaddress=info@smtp.gq
Details Email 1
test0work@yandex.com
Details Email 1
sky0news@gmail.com
Details Email 1
info@bulk-smtp.xyz
Details Email 1
innsniab@gmail.com
Details Email 1
hendsawi@gmail.com
Details Email 1
ibnkhaldon9@gmail.com
Details Email 1
info@news.bulk-smtp.xyz
Details Email 1
news@smtp.gq
Details Email 1
doron.eiliat@gmail.com
Details Email 1
bulk+mossad.gov.il@support-sales.tk
Details File 4
cyberattack_against_israeli_and_palestinian_targets.pdf
Details File 2
xtreme-rat-strikes-israeli-organizations-again.html
Details File 1
ivy.html
Details File 2
attacks-against-israeli-palestinian-interests.html
Details File 56
update.php
Details File 1
733.html
Details File 21
www.pas
Details File 4
plugin.exe
Details File 17
cv.doc
Details File 1
browser-password-dump.php
Details File 6
vboxmrxnp.dll
Details File 1
vmbusres.dll
Details File 4
vmguestlib.dll
Details File 4
key.php
Details File 55
test.php
Details File 1204
index.php
Details File 1
ios.php
Details File 1
nsr.php
Details File 1
rar.php
Details File 1
screen-2015-10-06_05-15-34-pm.png
Details File 4
conn.php
Details File 1
geoiploc.php
Details File 2
news.htm
Details File 2
pass.php
Details File 1
passho.php
Details File 1
passyah.php
Details File 1
poison-ivy.html
Details File 2
movie.exe
Details File 1
מהשבי.exe
Details File 1
boat.exe
Details File 1
bombings.exe
Details File 1
الدبلوماسية.exe
Details File 2
google-privacy.doc
Details File 9
details.doc
Details File 1
stabbing.exe
Details File 1
ties.exe
Details File 1
dsfihkfisgbdfsdfbsdkfs.php
Details File 1
בכיר.rar
Details File 1
singin.log
Details File 5
details.zip
Details File 3
de.php
Details File 1
hz.php
Details File 1
attachments.rar
Details File 5
open.php
Details File 8
b.php
Details File 1
hot-story.rar
Details File 6
report.rar
Details File 1
hot-report%26photos.rar
Details File 1
secret_report.rar
Details File 6
video.zip
Details File 1
newfolder.exe
Details File 11
new.exe
Details File 13
clean.exe
Details File 2
صبحي.exe
Details File 1
وإسرائيل.exe
Details File 1
لندن.exe
Details File 1
للسعودية.exe
Details File 1
נשכח.exe
Details File 2
wor.exe
Details File 1
virustotalscanner.exe
Details File 1
history.exe
Details File 1
concerns'.exe
Details File 1
worry.exe
Details File 1
novm-h-s.exe
Details File 1
musiclogs.exe
Details File 1
synchronization.exe
Details File 1
mp4.exe
Details File 54
file.exe
Details File 1
internet-y.exe
Details File 2
photos.rar
Details File 1
filezellacompiler.exe
Details File 5
set.exe
Details File 1
browsem.exe
Details File 1
هللا.exe
Details File 1
support.bk
Details File 1
drivres-update.inf
Details Github username 6
kbandla
Details md5 1
2f452e90c2f9b914543847ba2b431b9a
Details md5 1
1d9612a869ad929bd4dd16131ddb133a
Details md5 1
f589827c4cf94662544066b80bfda6ab
Details md5 1
15be036680c41f97dfac9201a7c51cfc
Details md5 1
0756357497c2cd7f41ed6a6d4403b395
Details md5 1
84e5bb2e2a27e1dcb1857459f80ac920
Details md5 1
18ef043437a8817e94808aee887ade5c
Details md5 1
3227cc9462ffdc5fa27ae75a62d6d0d9
Details md5 1
fcecf4dc05d57c8ae356ab6cdaac88c2
Details md5 2
9c60fadece6ea770e2c1814ac4b3ae74
Details md5 1
7a91d9bcd02b955b363157f9a7853fd1
Details md5 1
7f5cb76ca3ba8df4cabceb3c1cd0c11e
Details md5 1
c8fa23c3787d9e6c9e203e48081a1984
Details md5 1
6af77a2f844c3521a40a70f6034c5c4a
Details md5 1
aa288a5cbf4c897ff02238e851875660
Details md5 1
eea2e86f06400f29a2eb0c40b5fc89a6
Details md5 1
f94dfd49142bdae4a525997e4c0b944c
Details md5 1
8752f07a83b6830049dd5e6744bb444c
Details md5 3
f6e8e1b239b66632fd77ac5edef7598d
Details md5 1
e9586b510a531fe53fec667c5c72d87b
Details md5 1
e69bd8ab3d90feb4e3109791932e5b5e
Details md5 1
e55bbc9ef77d2f3723c57ab9b6cfaa99
Details md5 1
e3f3fe28f04847f68d6bec2f45333fa7
Details md5 1
ddb6093c21410c236b3658d77362de25
Details md5 1
dd9dcf27e01d354dbae75c1042a691ef
Details md5 1
d23b206a20199f5a016292500d48d3d2
Details md5 1
c75c58b9e164cc84526debfa01c7e4b9
Details md5 1
bf5d9726203e9ca58efb52e4a4990328
Details md5 1
bee2f490ec2cd30edaea0cb1712f4ed4
Details md5 1
bbd0136a96fec93fc173a830fd9f0fc0
Details md5 1
baff12450544ac476e5e7a3cbdeb98b5
Details md5 1
bab02ab7b7aa23efcab02e4576311246
Details md5 2
b1071ab4c3ef255c6ec95628744cfd3d
Details md5 1
aa541499a7dbbcb9cd522ccde69f59e6
Details md5 1
aa1f329a8cfdaf79c3961126a0d356fe
Details md5 1
a79c170410658eac31449b5dba7cc086
Details md5 1
a6aa53ce8dd5ffd7606ec7e943af41eb
Details md5 1
99ffe19cb57d538e6d2c20c2732e068c
Details md5 1
96d2e0b16f42c0fd42189fd871b02b5e
Details md5 1
96bf59cc724333ddbcf526be132b2526
Details md5 1
8cdb90b4e6c87a406093be9993102a46
Details md5 1
8bb2d2d1a6410c1b5b495befc6ae0945
Details md5 1
89125df531db67331a26c5064ab0be44
Details md5 1
8579d81c49fa88da8002163f6ada43e1
Details md5 1
84687e72feade5f50135e5fc0e1696e3
Details md5 1
79d701e58c55062faf968490ad4865b0
Details md5 1
796a6062d236f530d50209a9066b594a
Details md5 2
77d6e2068bb3367b1a46472b56063f10
Details md5 1
7450b92d96920283f441cb1cd39ab0c8
Details md5 1
6fd045ee7839fd4249aeda6ffd3e3b13
Details md5 1
641a0dbdd6c12d69dc8325522aaa2552
Details md5 1
5f0f503246665231c5bb7e8a78c16838
Details md5 1
577ac4f43871a07fd9b63b8a75702765
Details md5 1
4e93b3aa8c823e85fdc2ebd3603cd6e9
Details md5 1
45e662b398ecd96efd1abc876be05cb3
Details md5 1
3f88ca258d89ff4bd6449492f4bd4af6
Details md5 1
3ee15c163fbf6c36076b44c6fd654db2
Details md5 1
38b505a8aa5b757f326e0a8fe032e192
Details md5 1
286a1b5092f27b3e7e2f92e83398fcc2
Details md5 1
2606387a3dfb8bdc12beefacefc0354f
Details md5 1
22ff99f039feb3c7ae524b6d487bbff7
Details md5 1
1dfb74794a0befb6bb5743fa4305c87b
Details md5 1
154b2f008d80bf954394cf9ccbcccfda
Details md5 1
12fd3469bdc463a52c89da576aec857e
Details md5 1
0d65b89215a0ecb18c1c86dc5ac839d0
Details md5 1
0b0d1924eff3e6e6ca9bcbe60a0451bf
Details md5 1
5c3595e60df4d871250301b0b0b19744
Details md5 1
59f50a346aae12cbd5c1dec0e88bbde4
Details md5 1
ffc183a5c86b1ce0bab7841bb5c9917f
Details md5 1
bd07fd19b7598a0439b5cfd7d17ad9e6
Details md5 1
6dce847c27f5dd99261066093cb7b859
Details md5 1
a5c8bbacc9fce5cf72b6757658cf28f7
Details md5 1
ddd11518b1f62f2c91f2393f15f41dcd
Details md5 1
c46a40de75089a869ec46dec1e34fe7b
Details md5 1
bd19da16986240323f78341d046c9336
Details md5 1
5e0eb9309ef6c2e1b2b9be31ff30d008
Details md5 1
5896908cf66fd924e534f8cdb7bec045
Details md5 1
53f75e3d391e730a2972b4e2f7071c2e
Details md5 1
4731eb06a2e58a988684e62f523e7177
Details md5 1
3bf8898a88e42b0b74d29868492bd87f
Details sha1 1
f91948f456bf5510bdbb3a9245a5905324f7bbba
Details sha1 1
945a90159bae5b128e3170cb9096ea7b233fce43
Details sha1 1
ceca997310c6ce221d00ff6c17e523edc1bfce0a
Details sha1 1
a48662422283157455be9fb7d6f3f90451f93014
Details IPv4 1
45.32.13.169
Details IPv4 1
96.44.156.201
Details IPv4 1
5.101.140.118
Details IPv4 1
5.101.140.114
Details IPv4 1
6.9.0.114
Details IPv4 1
192.169.6.199
Details IPv4 1
192.52.167.235
Details IPv4 4
192.161.48.59
Details IPv4 3
107.191.47.42
Details IPv4 1
167.160.36.14
Details IPv4 1
172.245.30.30
Details IPv4 3
72.11.148.147
Details IPv4 3
192.52.167.125
Details IPv4 3
185.82.202.207
Details IPv4 1
185.12.187.105
Details IPv4 1
31.223.186.71
Details IPv4 1
45.32.236.220
Details IPv4 1
192.210.214.121
Details IPv4 1
192.169.7.99
Details IPv4 1
192.169.6.154
Details IPv4 1
185.117.73.116
Details IPv4 3
173.254.236.130
Details IPv4 4
162.220.246.117
Details Pdb 1
musiclogs.pdb
Details Pdb 2
news.pdb
Details Pdb 1
synchronization.pdb
Details Pdb 1
file.pdb
Details Pdb 1
internet.pdb
Details Pdb 1
i:\world\sfx\2015-08-10 ned ver 5p fixed\ned worm\obj\x86\debug\music synchronization.pdb
Details Pdb 1
i:\world\sfx\2015-08-08 ned ver 5p baker\ned worm\obj\x86\debug\music synchronization.pdb
Details Pdb 1
g:\world\sfx\2015-07-04 nedkey ver 1\nedkey ver 1\obj\x86\debug\internet.pdb
Details Pdb 1
c:\users\-\desktop\ned download and execute version 1 - doc\obj\x86\debug\news.pdb
Details Url 2
https://github.com/kbandla/aptnotes/blob/master/2012/cyberattack_against_israeli_and_palestinian_targets.pdf
Details Url 2
http://www.seculert.com/blog/2014/01/xtreme-rat-strikes-israeli-organizations-again.html
Details Url 1
https://securelist.com/blog/research/72283/gaza-cybergang-wheres-your-ir-team
Details Url 1
https://www.fireeye.com/blog/threat-research/2013/08/operation-molerats-middle-east-cyber-attacks-using-poison-
Details Url 2
http://pwc.blogs.com/cyber_security_updates/2015/04/attacks-against-israeli-palestinian-interests.html
Details Url 1
http://www.nrg.co.il/online/1/art2/594/733.html
Details Url 1
https://www.passivetotal.org/passive/45.32.13.169
Details Url 1
https://www.cz.freelancer.com/projects/iphone/write-some-software-8755699
Details Url 1
http://securityxploded.com/browser-password-dump.php
Details Url 1
https://msdn.microsoft.com/en-us/library/aa394582(v=vs.85).aspx
Details Url 1
http://ra.goaglesmtp.co.vu/nsr.php?pn=mww1beoxvdjqqib8ifbtufvcv1m&fr=&gr
Details Url 1
https://www.fireeye.com/blog/threat-research/2013/08/operation-molerats-middle-east-cyber-attacks-using-
Details Url 1
https://securelist.com/blog/research/72283/gaza-cybergang-wheres-
Details Url 1
https://whois.domaintools.com/185.12.187.105
Details Url 1
http://whois.domaintools.com/31.223.186.71
Details Url 1
https://copy.com/s8w9tqqzvdaxikcr/הריגתו
Details Url 1
http://support.markting-fac.tk/20151027/update.php
Details Url 1
http://singin.loginto.me/050915/<redacted>.php?id=
Details Url 1
http://sales-spy.ml/sales/details.zip
Details Url 1
http://news.net-freaks.com/upex/wor
Details Url 1
http://news.net-freaks.com/de.php?id=tasreb&token1=
Details Url 1
http://mailweb.otzo.com/hz.php?pn=uemgfcbbzg1pbmlzdhjhdg9y&fr=&gr=tm92zw1izxiosfoppgj
Details Url 1
http://info.intarspace.co.vu/u/dsfihkfisgbdfsdfbsdkfs.php?id=3dusaem
Details Url 1
http://ed3qy5yioryitoturysuiu.otzo.com/u/hea-n-p
Details Url 1
http://dnsfor.dnsfor.me/attachments.rar
Details Url 1
http://dfwsd.co.vu/open.php?id=openexe&token1=b3blbmv4zq&token2=b3blbmv4zq&c=openexe
Details Url 1
http://cnaci8gyolttkgmguzog.ignorelist.com/b.php?pn=uexbq0vit0wtnky2otlbihwgqwrtaw5pc3ry
Details Url 2
http://cnaci8gyolttkgmguzog.ignorelist.com
Details Url 1
http://0arfx4grailorhvlicbj.servehumour.com/u/procexp
Details Url 1
http://news20158.co.vu/index.php
Details Url 1
http://directexe.com/788/attachments.rar
Details Url 1
http://dfwsd.co.vu/open.php
Details Url 1
https://copy.com/tc6thzxjol3zd1bl/video.zip?download=1