https://tw itter.com/I ntrinsec https://fr.l inkedin.co m/compa ny/intrins ec https://w ww.intrins ec.com/bl og
Image Description
Common Information
Type Value
UUID c5db5504-0549-42e4-9b62-6ba1739b19d8
Fingerprint 60d58e53b6577ae2be5e81cf30bba874c65098cd2d04466cfc16d7598c330f56
Analysis status DONE
Considered CTI value 1
Text language
Published April 30, 2024, 3:15 p.m.
Added to db June 2, 2024, 11:17 a.m.
Last updated Aug. 31, 2024, 7:51 a.m.
Headline https://tw itter.com/I ntrinsec https://fr.l inkedin.co m/compa ny/intrins ec https://w ww.intrins ec.com/bl og
Title https://tw itter.com/I ntrinsec https://fr.l inkedin.co m/compa ny/intrins ec https://w ww.intrins ec.com/bl og
Detected Hints/Tags/Attributes 122/3/177
Attributes
Details Type #Events CTI Value
Details Autonomous System Number 3
AS198953
Details Autonomous System Number 1
AS216234
Details Autonomous System Number 4
AS57523
Details Autonomous System Number 3
AS49943
Details Domain 1
itter.com
Details Domain 1
inkedin.co
Details Domain 1
ec.com
Details Domain 2
extic.icu
Details Domain 2
reykh.icu
Details Domain 1
988.skins.com
Details Domain 1
muagol.com
Details Domain 1
gulappa.com
Details Domain 2
treasurybanks.org
Details Domain 1
q-report-53394.zip
Details Domain 1373
twitter.com
Details Domain 1
sweetapp.page
Details Domain 1
988skins.com
Details Domain 1
selevkis.app
Details Domain 397
asp.net
Details Domain 1
gulappa.app
Details Domain 1
musarno.app
Details Domain 1
modenetwork.app
Details Domain 1
juprewards.app
Details Domain 1
blastreward.app
Details Domain 1
somakop.app
Details Domain 1
filesnatchcloud.pro
Details Domain 1
huntersinternational.org
Details Domain 1
iseberkis.com
Details Domain 1
dumingas.com
Details Domain 1
bgp.tools
Details Domain 1
unitele.ru
Details Domain 1
proton.net.ru
Details Domain 1
proton.org.ru
Details Domain 1
marvin-occentus.net
Details Domain 1
pluralism.themancav.com
Details Domain 1
redviking.com
Details Domain 1
mavrin-occentus.net
Details Domain 1
binder-sa.com
Details Domain 1
aitcaid.com
Details Domain 1
welcome.visionaryyouth.org
Details Domain 1
trademark.iglesiaelarca.com
Details Domain 1
bologna.sunproject.dev
Details Domain 1
rome.sunproject.dev
Details Domain 1
florence.sunproject.dev
Details Domain 1
venice.sunproject.dev
Details Domain 1
sunproject.dev
Details Domain 1
turin.sunproject.dev
Details Domain 1
gammaprojec.dev
Details Domain 1
torontoclub.vip
Details Domain 1
mindsmatterphilly.org
Details Domain 1
designedlearning.com
Details Domain 1
ccrcorp.com
Details Domain 1
mannmortgage.com
Details Domain 1
firstlight.net
Details Domain 1
sdic.org
Details Domain 1
speedprocanada.com
Details Domain 1
osceolataxcollector.org
Details Domain 1
doctorkiltz.com
Details Domain 1
usrailandlogistics.com
Details Domain 1
atomwise.com
Details Domain 1
kalaswire.com
Details Domain 1
poolsbydesignaz.com
Details Domain 1
ggrinc.com
Details Domain 1
gatewaycr.org
Details Domain 1
buildingintelligence.com
Details Domain 1
intervention911.com
Details Domain 1
pestpatrol1.com
Details Domain 1
dems.ag
Details Domain 1
democraticags.org
Details Domain 1
invisiblepeople.tv
Details Domain 1
govos.com
Details Domain 1
vlanj.org
Details Domain 1
vsofm.com
Details Domain 1
admin.nursing.com
Details Domain 1
presswire.com
Details Domain 1
democraticgovernors.org
Details Domain 1
locustfamilydentistry.com
Details Domain 1
sitesofconscience.org
Details Domain 1
fancy.justbartanews.com
Details Domain 1
galimidilaw.com
Details Domain 1
breakpointbooking.com
Details Domain 1
kristinhannah.com
Details Domain 1
barbarajking.com
Details Domain 1
baumgartnerlawyers.com
Details Domain 4127
github.com
Details Domain 6
research.openanalysis.net
Details Domain 425
isc.sans.edu
Details Domain 434
medium.com
Details Domain 32
lolbas-project.github.io
Details Domain 202
krebsonsecurity.com
Details Domain 370
www.proofpoint.com
Details Domain 4
embee-research.ghost.io
Details File 1
open_document.pdf
Details File 1
50k.png
Details File 55
control.exe
Details File 1205
index.php
Details File 1
q-report-53394.zip
Details File 1
q-report-60033.js
Details File 376
wscript.exe
Details File 1
useraccount.aspx
Details File 748
kernel32.dll
Details File 5
regsvr.exe
Details File 5
stat.js
Details File 1
2849.xlsx
Details File 1
50.png
Details File 1
theme.js
Details File 22
update.js
Details File 1
dex.php
Details File 1
03_2024.txt
Details File 1
matanbuchus-triage.html
Details Github username 17
elastic
Details Github username 27
sigmahq
Details Github username 2
pr0xylife
Details sha1 1
0875c1e4c4370ab9fbf453c8160bb5abc8ad95e7
Details IPv4 1
5.252.177.213
Details IPv4 1
185.11.61.170
Details IPv4 1
185.11.61.71
Details IPv4 1
185.11.61.172
Details IPv4 1
193.143.1.207
Details IPv4 1
193.141.1.196
Details IPv4 1
193.143.1.198
Details IPv4 1
193.143.1.197
Details IPv4 1
91.226.31.34
Details IPv4 1
91.212.166.21
Details IPv4 1
166.1.173.27
Details IPv4 1
193.143.1.54
Details IPv4 1
147.45.47.87
Details IPv4 1
162.33.177.118
Details IPv4 1
185.11.61.169
Details IPv4 1
185.11.61.171
Details IPv4 1
193.143.1.196
Details IPv4 1
193.143.1.0
Details IPv4 1
45.134.26.0
Details IPv4 1
45.135.232.0
Details IPv4 1
45.140.17.0
Details IPv4 1
91.212.166.0
Details IPv4 3
176.111.174.0
Details IPv4 1
185.11.61.0
Details IPv4 1
185.122.204.0
Details IPv4 1
185.198.69.0
Details IPv4 1
185.234.216.0
Details IPv4 1
185.81.68.0
Details IPv4 1
188.119.66.0
Details IPv4 1
194.26.135.0
Details IPv4 1
45.93.20.0
Details IPv4 1
62.122.184.0
Details IPv4 1
85.209.11.0
Details IPv4 1
87.247.158.0
Details IPv4 1
91.240.118.0
Details IPv4 1
91.241.19.0
Details IPv4 1
152.89.198.0
Details IPv4 1
194.32.236.0
Details IPv4 1
213.226.123.0
Details IPv4 1
5.42.199.0
Details IPv4 1
91.213.50.0
Details IPv4 1
34.168.202.91
Details IPv4 1
37.128.207.92
Details IPv4 2
128.254.207.82
Details IPv4 1
194.67.193.0
Details IPv4 1
45.9.74.0
Details Url 1
https://fr.l
Details Url 1
https://twitter.com/unit42_intel/status/1772988284571877807/photo/2.
Details Url 1
https://988skins.com/admin/view/stylesheet/50k.png
Details Url 1
https://selevkis.app/useraccount.aspx
Details Url 1
https://muagol.com/useraccount.aspx
Details Url 1
https://github.com/elastic/detection-
Details Url 1
https://github.com/sigmahq/sigma/blob/62d4fd26b05f4d81973e7c8e80d7c1a0c6a
Details Url 1
https://twitter.com/cryptolaemus1/status/1765796398526566434
Details Url 1
https://github.com/pr0xylife/matanbuchus/blob/main/matanbuchus_07.03_2024.txt
Details Url 1
https://research.openanalysis.net/matanbuchus/loader/yara/triage/dumpulator/emulation
Details Url 3
https://isc.sans.edu/diary/malspam
Details Url 252
https://medium.com
Details Url 1
https://lolbas-project.github.io/lolbas/binaries/control
Details Url 1
https://krebsonsecurity.com/2023/09/snatch-ransom-group-exposes-visitor-ip-addresses
Details Url 3
https://www.proofpoint.com/us/blog/threat-insight/ta569-socgholish-and-beyond
Details Url 1
https://embee-research.ghost.io/latrodectus-script-deobfuscation
Details Url 1
https://twitter.com/unit42_intel/status/1772988284571877807