OPERATION TASKMASTERS
Image Description
Common Information
Type Value
UUID f0083b54-ceaa-45a7-a176-9eec7d0d19cc
Fingerprint cbe87516b18bce55df57c8f7ee7ea8d854940493bc14d945acebe247a3952f80
Analysis status DONE
Considered CTI value 2
Text language
Published Aug. 15, 2019, 3:57 p.m.
Added to db May 19, 2024, 12:41 p.m.
Last updated Aug. 31, 2024, 8:37 a.m.
Headline OPERATION TASKMASTERS
Title OPERATION TASKMASTERS
Detected Hints/Tags/Attributes 96/3/690
Attributes
Details Type #Events CTI Value
Details File 3
a.bin
Details File 50
a.exe
Details File 2
a.rar
Details File 2
a0101377.exe
Details File 2
a0144508.dll
Details File 2
aact.dll
Details File 2
aavd.dll
Details File 2
acdw.dll
Details File 2
adobeace.exe
Details File 2
aphicsit.exe
Details File 2
atnow.dat
Details File 7
au.exe
Details File 2
avppower.exe
Details File 5
b.bin
Details File 2
b.rar
Details File 2
bakit.exe
Details File 52
bcrypt.dll
Details File 2
bhos.dll
Details File 2
buert.exe
Details File 2
cc.zip
Details File 2
cfd.exe
Details File 2
cierdecll3.htm
Details File 2
cjwz.dll
Details File 86
service.exe
Details File 2
connectres.txt
Details File 2
conshlp.exe
Details File 2
cpuzud.exe
Details File 2
crec.aspx
Details File 4
ctfmom.exe
Details File 2
curl.rar
Details File 2
czof.dll
Details File 5
d.bat
Details File 2
d.rar
Details File 2
dat4.tmp
Details File 2
dc1.dll
Details File 2
dcs.rar
Details File 2
dex.exe
Details File 2
dlwy.dll
Details File 5
drweb.exe
Details File 2
ds9vs.dll
Details File 2
dumpsvc.dat
Details File 1260
explorer.exe
Details File 2
fcopy.dat
Details File 2
fcxl.dll
Details File 54
file.exe
Details File 2
flashplayerupdater.exe
Details File 3
ftps.dll
Details File 2
fzhi.dll
Details File 2
gc.chm
Details File 2
gd.exe
Details File 2
gfk.chm
Details File 2
gjhzs.rar
Details File 2
gjhzs909.rar
Details File 2
gllr.chm
Details File 4
global.aspx
Details File 2
gp.chm
Details File 2
gpzf.dll
Details File 2
gpzf_.dll
Details File 2
hp.exe
Details File 2
hpmon.exe
Details File 2
hpmon04.exe
Details File 2
hpudsvc.exe
Details File 2
ht.exe
Details File 4
i.bin
Details Domain 2
mormorsale.com
Details Domain 2
net17.ns01.info
Details Domain 2
net17.ns1.name
Details Domain 2
newhouse.fartit.com
Details Domain 2
nomotion.mrface.com
Details Domain 3
novnitie.com
Details Domain 3
ns02.ns02.us
Details Domain 2
openfire.https443.net
Details Domain 2
openfire.zzux.com
Details Domain 2
pellguide.myddns.rocks
Details Domain 2
polygo.camdvr.org
Details Domain 2
popmail.linkpc.net
Details Domain 2
provisioned.kozow.com
Details Domain 2
quatermeter.strangled.net
Details Domain 2
sb1.ns01.biz
Details Domain 2
sb1.ns01.info
Details Domain 2
selfsegmentation.zzux.com
Details Domain 2
sellbase.loseyourip.com
Details Domain 2
slogicroot.com
Details Domain 2
software.zyns.com
Details Domain 2
sound.my03.com
Details Domain 2
spartacus.ezua.com
Details Domain 2
sssbbb.25u.com
Details Domain 2
sssbbb.ddns.me.uk
Details Domain 2
sssbbb.ddns.uk
Details Domain 2
standpay.dynu.com
Details Domain 2
statcountone.dynu.com
Details Domain 2
tec.ns02.us
Details Domain 2
twoseccends.onedumb.com
Details Domain 2
whathelp.mywire.org
Details Domain 2
whogetthis.ddnsfree.com
Details Domain 2
zerofocus.toythieves.com
Details Domain 330
facebook.com
Details Domain 29
www.nirsoft.net
Details Domain 71
www.openwall.com
Details Domain 3
download.openwall.net
Details Domain 4127
github.com
Details Domain 9
sectools.org
Details Domain 6
www.win-rar.com
Details Domain 281
docs.microsoft.com
Details Domain 212
technet.microsoft.com
Details Domain 3
www.wischik.com
Details Domain 3
www.the-sz.com
Details Domain 98
www.secureworks.com
Details Domain 47
www.slideshare.net
Details Domain 184
www.fireeye.com
Details Domain 262
www.welivesecurity.com
Details Domain 101
www.group-ib.com
Details Domain 24
www2.fireeye.com
Details Domain 4
www.erai.com
Details Domain 216
www.symantec.com
Details Domain 13
www.trendmicro.de
Details Domain 111
www.justice.gov
Details Domain 6
www.nccgroup.trust
Details Domain 403
securelist.com
Details Domain 5
investors.fireeye.com
Details Email 132
pt@ptsecurity.com
Details File 2125
cmd.exe
Details File 6
i.exe
Details File 2
i2.dll
Details File 2
i2.exe
Details File 2
i2mss.exe
Details File 2
igfxmon.exe
Details File 2
igfxmons.exe
Details File 6
igfxpers.exe
Details File 2
igfxspel.exe
Details File 2
igfxsper.exe
Details File 5
ii.exe
Details File 2
ii2.exe
Details File 2
iis.exe
Details File 3
in.exe
Details File 2
insets.exe
Details File 54
install.exe
Details File 2
insts.exe
Details File 2
int.dll
Details File 3
int.exe
Details File 2
iprip.exe
Details File 2
ipsec3.dll
Details File 2
ipsec4.dll
Details File 2
ipxrip.exe
Details File 2
ivjq.dll
Details File 2
iyzp.dll
Details File 2
jssg.dll
Details File 2
kerfcc.exe
Details File 2
krtf_.dll
Details File 2
lfmn.dll
Details File 2
lgyo.dll
Details File 35
libeay32.dll
Details File 38
lsass.dmp
Details File 2
lsmiis2.exe
Details File 2
lsmis5.exe
Details File 2
lsoss_1_.exe
Details File 4
m.bin
Details File 4
m.rar
Details File 2
microhlp.exe
Details File 2
myz.dat
Details File 2
mz8.chm
Details File 2
n.bin
Details File 3
n.rar
Details File 2
nbtscan.dat
Details File 2
nd.rar
Details File 3
netui4.dll
Details File 2
nov.bin
Details File 2
nov.rar
Details File 2
ns.chm
Details File 2
nt4.rar
Details File 2
oqaj.dll
Details File 2
ot5.dat
Details File 4
p.bin
Details File 2
p2.dat
Details File 2
p264.dat
Details File 2
p6.bin
Details File 2
p6.chm
Details File 2
part001.rar
Details File 2
part002.rar
Details File 2
part003.rar
Details File 2
part004.rar
Details File 2
part005.rar
Details File 2
part006.rar
Details File 2
part007.rar
Details File 2
part008.rar
Details File 2
part009.rar
Details File 2
part010.rar
Details File 2
part011.rar
Details File 10
path.txt
Details File 2
pdx.dat
Details File 2
phicsit.exe
Details File 2
pl.chm
Details File 4
pp.rar
Details File 2
pp3.exe
Details File 2
pp6.exe
Details File 2
psc.chm
Details File 2
psc.dat
Details File 2
psl.dat
Details File 2
psug.dll
Details File 4
pwdump7.exe
Details File 3
r.bin
Details File 2
r.chm
Details File 2
r.rar
Details File 2
rar.dat
Details File 96
rar.exe
Details File 9
res.txt
Details File 2
rlbl.dll
Details File 2
rp.chm
Details File 118
sc.exe
Details File 748
kernel32.dll
Details File 108
0.exe
Details File 3
02.dll
Details File 4
03.dll
Details File 10
1.asp
Details File 156
1.exe
Details File 2
1211.exe
Details File 2
12183250.dll
Details File 2
123.mp3
Details File 2
16.bin
Details File 2
16.mp3
Details File 2
161.bin
Details File 2
2.asp
Details File 59
2.exe
Details File 2
2018-04-223-13-04_a.exe
Details File 2
2018-04-223-13-30_a.exe
Details File 2
2018wk.exe
Details File 2
231.dll
Details File 10
64.dll
Details File 2
6666.exe
Details File 2
682.dll
Details File 2
682.exe
Details File 2
6to4.dll
Details File 5
7.txt
Details File 2
858.exe
Details File 4
86.dll
Details File 2
876.exe
Details File 2
8789.exe
Details File 2
8789bk.chm
Details File 2
999.exe
Details CVE 12
cve-2017-0176
Details Domain 226
ptsecurity.com
Details Domain 6
google.ru
Details Domain 3
brengkolang.com
Details Domain 2
cc.zip
Details Domain 2
pladi1.ht
Details Domain 2
ru.ru
Details Domain 2
aabdc.dynssl.com
Details Domain 2
accountside.zyns.com
Details Domain 2
anata.ooguy.com
Details Domain 2
associates.ddns.us
Details Domain 2
atlasdo.epac.to
Details Domain 2
atlasdo1.epac.to
Details Domain 2
automatically1101.dynu.com
Details Domain 2
bestcash.accesscam.org
Details Domain 2
billing.lflinkup.org
Details Domain 2
bluetraveller.onmypc.net
Details Domain 2
carrot.compress.to
Details Domain 2
clientlogin.jkub.com
Details Domain 2
dbcript.yourtrap.com
Details Domain 2
economic.itsaol.com
Details Domain 2
elp.linkpc.net
Details Domain 2
elp.ns01.us
Details Domain 2
finaldog.giize.com
Details Domain 2
foundbox.zyns.com
Details Domain 2
francegod.mefound.com
Details Domain 2
freestylepannel.dynu.com
Details Domain 2
funsclub.wikaba.com
Details Domain 2
funstraction.ignorelist.com
Details Domain 2
fwiffer.jkub.com
Details Domain 2
game.changeip.org
Details Domain 2
greatland.yourtrap.com
Details Domain 2
happynewlife.mrface.com
Details Domain 2
jailout.sexidude.com
Details Domain 2
jfgi.onedumb.com
Details Domain 2
konwleg.mypop3.net
Details Domain 2
looseup.mywire.org
Details Domain 2
mail3.5wya.com
Details Domain 2
menzu4.25u.com
Details Domain 2
mindme.2waky.com
Details File 4
rt.pdf
Details File 2
rt.rar
Details File 30
s.exe
Details File 5
scan.dat
Details File 12
scan.exe
Details File 2
scss.exe
Details File 2
set.dll
Details File 5
set.exe
Details File 2
sft.dat
Details File 2
sgpq.dll
Details File 2
small.exe
Details File 2
smsc.exe
Details File 2
souicsit.exe
Details File 2
srgk.dll
Details File 6
str.txt
Details File 2
svdnost.exe
Details File 3
svohost.exe
Details File 2
svohost_1_.exe
Details File 2
sysinit.dll
Details File 2
systeminfo.mp3
Details File 3
t.bin
Details File 17
t.exe
Details File 3
t.rar
Details File 2
t2p.rar
Details File 58
test.exe
Details File 3
tfs.dat
Details File 2
tgb.rar
Details File 2
tlhh.dll
Details File 2
tplh.dll
Details File 2
tr.dll
Details File 7
tr.exe
Details File 2
tracert.dll
Details File 2
tradoigfx.exe
Details File 2
traffic.exe
Details File 2
ttbyabc.dll
Details File 2
tuye.dll
Details File 2
ul.dat
Details File 2
ul2.dat
Details File 4
up.dat
Details File 2
uwse.dll
Details File 2
uyv.rar
Details File 2
v.rar
Details File 4
view.js
Details File 9
view.jsp
Details File 2
vniplat.exe
Details File 2
w.bin
Details File 3
warn.aspx
Details File 2
wincsit.exe
Details File 3
winspool.dll
Details File 2
wk.chm
Details File 4
wk.exe
Details File 2
wtfmon.exe
Details File 2
wvae3.bat
Details File 2
wvae3.exe
Details File 2
wvares.dat
Details File 9
x.dll
Details File 19
x.exe
Details File 2
yhro.dll
Details File 2
z.bin
Details File 2
zeqh.dll
Details File 2
zmss.exe
Details File 2
zmss8.exe
Details File 2
zsmss.dat
Details File 2
zsmss.dll
Details File 2
zsmss.exe
Details File 2
zsrss.exe
Details File 2
atlasdo.ep
Details File 2
atlasdo1.ep
Details File 5
ns01.inf
Details File 3
atnow.html
Details File 9
start.html
Details File 2
eb3cafea830c1bd94585fc896.aspx
Details File 6
bb897553.aspx
Details File 3
pslist.aspx
Details File 3
dbx_utils.html
Details File 7
tunnel.aspx
Details File 3
jsp_file_browser.jsp
Details File 6
cyber-espionage-apt32.html
Details File 4
read-the-manual.pdf
Details File 13
mandiant-apt1-report.pdf
Details File 3
wbnr-are-you-ready-to-respond.html
Details File 4
2015_12_wp_operation_iron_tiger.pdf
Details File 2
dissecting-lurid-apt.pdf
Details Github username 5
hiwincn
Details Github username 4
ysrc
Details Github username 29
gentilkiwi
Details Github username 24
sensepost
Details Github username 6
tennc
Details md5 2
3ab32b47a7dcb67c6d8943ff04254c1e
Details sha256 3
02e5bf4227f94e72c401ef8a052f61c370c1dcfbb4695e432ccd2982bbf529e9
Details sha256 3
039c1faf0f37f47908b213c00d1ee595ade0e058e252596e0c92979a2b7b4143
Details sha256 3
03f96088c715c06baa00492a0a4eb5bb0d00a9daa12f507ff77bb292acdd5e70
Details sha256 3
05732e84de58a3cc142535431b3aa04efbe034cc96e837f93c360a6387d8faad
Details sha256 3
0dc5c83da6281e026f0e05652ff7c0701f9690b43a12c661f9e077e9b365c94d
Details sha256 3
11b06fc4dbacc2357d7f277e302be9c3ce907b9fd91ffd8e847d0afb86eec1e2
Details sha256 3
1257539e1d64d3b646c4016332338041fd11afb3c3bbe3c1b9f1a3580968d722
Details sha256 3
129cf0573d54447fa4985bc26c8a6f0caf41f239a3e3605137ecc1365b828166
Details sha256 3
12a56d1dfe0d3ed044fb1cab55c5f444fd98835761ce2b3f7a8ea8ac2389b9af
Details sha256 3
16e2a78ab2ccb064c1f35a89cfb4bd64491ae97d48bd1e90124e1162f2804147
Details sha256 7
16f413862efda3aba631d8a7ae2bfff6d84acd9f454a7adaa518c7a8a6f375a5
Details sha256 3
1743c9db17aa0b6d58be9eed32330c5c0099e364d402316af9c40ab7caac1bff
Details sha256 3
1789d39a2312199a41783c289d20ad655b9f4273730fe159b70e411ba4b600c0
Details sha256 3
1827b320f931f6cf653a18577255e8e300d073f17faace10a3c75d0575d3e744
Details sha256 3
18c213f57520461fc5e279b3756b6bf91ecf172e7921d50eb5a6a1d276d9a559
Details sha256 3
1977d9f301abc22e228f53386831bb1238c0baadfffd25c8313bfefb20bb7e22
Details sha256 3
19bd3d0a545eda42e7f7e202bed8a69bae101de84b9abcd1c32e73d9d1bf7e5e
Details sha256 3
1baaa8bc49b1fc28c423601c8de57dbaef93e83bafe24495e3ef1e69b9a0b252
Details sha256 3
1ce3cd926981c57f6f8374505c820a566bfe019639388dc2f10f37848e0dfd22
Details sha256 3
1d867802f3a5a21a4e47e5dcc19cba0361e7adc943f7254d68373b132ccff5b2
Details sha256 3
1e36e7cc7efffae741fff6f6767a1119956290ca25dc56cf6408122608a8e0b7
Details sha256 3
1ecd8eec4b37234a6f7574863bd2de4e68a657689da2e08a9fbb5cefbf2da929
Details sha256 3
20b5edba5804aaa4a3f75582f289f44005db7391783588261ad7bcfb245b8807
Details sha256 3
2216524bdbebbbcff6bbeb7ba0a138a4870a960adb4cf848777dff9df9bfdd9f
Details sha256 3
22d5ed5378baab14f70b6e1ab52365cefeec2436ddb9a5162350eb426939e2ab
Details sha256 3
24ce0093ee095036a6ac214f84ccf3e5d041778a560ec62a557857f0b848cd7a
Details sha256 3
2626b49ee4c59421d4731d1eec153c87ec01763d8df42ba903bdf269249b6279
Details sha256 3
27000cb784d047f664f372e2af1a61a0b5e9c557e215f524f5589d0fbf5a7116
Details sha256 3
2725d22e16cb7e7588a7fa644723b3050d598857f3892ee33511e5b055dea3c6
Details sha256 3
28aedf8050d2ab7a4b5028746c714023087d1f5b5767f5a6c3e1aaea7441391b
Details sha256 3
2a0760e9eec9c3957ff78f0d8db8dc17d92b80d1e4dc649b2886dc6a0c234187
Details sha256 3
2c24ee33ca77d1c03da75bb465019dd8778497f6e57fc06d0da08d0de8a2872a
Details sha256 3
2c36ce8d1754145243c8c44475408018f7be4377343019e12026bdcb712d5cb3
Details sha256 3
2c96c4d32bdc02ff89abe4ddc9a18fdb4e5e3be0ed5fac561a3be8622f17b131
Details sha256 3
2f3c52f9c858d38b6964b9de37a97c251892db941117bf6c47743272dd133ac8
Details sha256 3
32aee4c9b886cf026d55c8de703af5c5469cd0b2ce6cfb67e039f7c347221f92
Details sha256 3
339828a0516652dc5bc61b72602df017d6a10db78773309e9951197ab40a2313
Details sha256 3
33b06cb06e1034fac0ea27995bd2c10cc8645d082e900bb5256c4f045403483d
Details sha256 3
3470407f1f5c445660978f8990b1f515e77210aaf7314b1f407dd76c4ca1e874
Details sha256 3
3497b28c5652bee5b205818be6c5cb90b8c8ca4bfea0ee0817af55e7c339fd6a
Details sha256 3
35a45a79d9f3ee66dc81a8329a111fdf16a1d55d2de8a43caebd5a39a04050a9
Details sha256 3
36c42bddac7a187d82a16cd13be8b94c47066beee8e0ce4e02c97ffa4b578cc3
Details sha256 3
375b40c30da648eabfbcecdc6e6392673963eae99a73518933abb9fa7fcc9bce
Details sha256 3
378344be58d2277c2456825b14e008f97330c37a8af876d18b5e9edf568f30c8
Details sha256 3
38499a5289dcd333cb50eb7aac9886448e7b2d3792516e8ecd938a2279e5ace1
Details sha256 3
3877a9167494d8d344a0c49274c1e4f91b4c35398e74a9b941303d35822a7aeb
Details sha256 3
395d40d5ab54e009a02d990a37327a477e60530c83242c3e1de1dde26db7666f
Details sha256 3
39d021ef22f95e8c301533e7bca0b12b8e14909f1c4b3ed6c9b1f03d610cfba0
Details sha256 3
3a39cd5cb362188de53b702fec934523c27123b080803b1b8a859e288ac353dd
Details sha256 3
3b178c063372245c8a6cfd4f059fb43c0be08bfb49209096ce38e379bf521669
Details sha256 3
3ba85e2c2e40fc60d62214b85fe3c46bfd11ecdabf7506a3fadd81a7360029cf
Details sha256 3
3ce4b936bdb3469057cc193dfca58ef6ae28f8b4355285ab6e97cc7457ec3cad
Details sha256 3
3d75740a1db7a259345e100ccee3e3cea3ed46d707804438f2c6884197a64076
Details sha256 3
3f8b447a2c0c1e677cd77481875861fd2d75b82056b129f163463b5225a6369e
Details sha256 3
40361a025ded3e83a206277de2d1a24c58932964e23d0cf7d2a2fad287192eb7
Details sha256 3
413aa698e2edb042a3fee76ef015a1a610f54f1502ca21f7f95a19ad2eb352d6
Details sha256 3
41428673b20408c052fff5c6e8e06dd9aad4f151394fd248a81462d3e7416777
Details sha256 3
42829129b396465f0355b88e1a4fcbd62e1db26d6a226da5fd045314c9de57a9
Details sha256 3
439eeeab09bc8f7fcb65bc221d50d13989f00746f4b155516086620186c785e0
Details sha256 3
4417c224c82a7df33af41dc4d9a07dc6955a531432048c6fd9874e48d6502d18
Details sha256 3
446f84069e825062d1d56971b7578361ebc4feb1988950701065d9c18a3e7941
Details sha256 3
457e509889288c9523ebc1333682a9d9b3d913f9d49f8ed5e24add9ce2c813f4
Details sha256 3
45ef65b99d5970c736ca5c5d84c4d335107a7f4c9c42d57cb02809819fec722f
Details sha256 3
49bbe9ef463ae3be170016282fb34baaf643232fdd00ec10e94c6fe3ecb5047a
Details sha256 3
4cf787e9b2d3fe6e38476d280a066f0c6e7a452c14b077903009be16bc373e0b
Details sha256 3
4eaf82cc6f13a0f97cbab23f2acf86523768ea09f8a6172dd31db9ef59abf8cd
Details sha256 3
4eb28758d50cbb661c0aa3df9260d7f8214b1d74ab623b07b50cf1a98e019d52
Details sha256 3
597fd8d8bf5078c2e3bceb4b64ec88985da9d8976b24c4d49792950ba2f79ccf
Details sha256 3
5a15a3692edb61202f1afb8e5da1d6f1fe73183644eff3a38ebb69d9811783ce
Details sha256 3
5a19eb4140a5871e409a6bad547035622a0f4ff993e3d8daa76cfc25338acda6
Details sha256 3
5b3f3655c5683596394c44a52e002c08dfe1da688c116dedf0de1c859d334b4c
Details sha256 3
5bbf07235c668683b3cf1b2dff1f815bc760a195ae7cfd62948a6ebf24f2d204
Details sha256 3
5cc12ad9e80c6654d7b6c07d40eace36ce6b6e1806be81a50fe6bd94aecf255b
Details sha256 3
5d5113b9ff6d52048e964e6c6daca6152448ad43d809bce29b2ef193ade2a51a
Details sha256 3
5eccc046835c58cea560566f6da47d424a994773ee3a05fbf429d3c9dde0ad7c
Details sha256 3
5ecccb17c7a529c8066f353bfae342e9e27a1c1e8916f199e539e359757b11c5
Details sha256 3
5f1d61f09d461ce6860b92c1e8d6410f511ba3428c1442364c9e052a97c48f75
Details sha256 3
6195ed2380118a50740fc7cb3cb646128bdda649ffc1f51f34e208bfc0f2d3cf
Details sha256 3
6324e31d90e7ccff78f3311a067373828d764b5ee7f1a9224e01fcfd2aa0c717
Details sha256 3
63ae495d981e1ec36a32d989c2d414c03094ccbb7f5438498af5be8ac8e22882
Details sha256 3
63b1e09be45ab14596aa4c1f2ee406ff3e275caeb16ebe0fd44c520bfe6b78ff
Details sha256 3
6414a7dc658da05ed0f1c3814256b9729e55560110ad46fd5e6fadec2aa66a2c
Details sha256 3
69ce2cd26e72ac68c362733d5186ab22f9266e9530c80477fae2454631373973
Details sha256 3
6ba6052f2074318e094ceeefcd8a661ee89e178795cb3ed66be8dad787d695d0
Details sha256 3
6bc4497b86df521b413e4574f4cd4289c986348d2a69da1945ff1a1784db05db
Details sha256 3
7310a400d6cc9435323407f1e1fa9307069de6a54a61ea39e05d161e8bb1ec38
Details sha256 3
74cc653d34fbb5ce9cf6f80261e5b096c5f77939f06cabc9f0258c43751a3fdf
Details sha256 3
79d531f0676a3ea00217f66fd84e2e101b6258816987e8a9fb2e5b59834a3700
Details sha256 3
7ad0fa474c9d85b29a76e2d3ab28dea27ec86d1db63f423f276d63f345372df8
Details sha256 3
830d032697691b6819eaed2e65bbd60cfc95b935ca4cba0784a9ca07e117962a
Details sha256 3
84be0e1cd0a8fd4231657baa7ebf7df2d0193ac0ec86e2115f0ca96fe5af5391
Details sha256 3
852f4a10f3077f5285a345e0cc5b24c23904c1ea81d289879c1b7a9ff8a3886a
Details sha256 3
87103c8c2c26310c01545501808da8375b1393c5666c0d3ee0532436a0787024
Details sha256 3
8729e9acc699a2663c3526c2592b6a65eb581c18e90fd658d24ebc27a145006a
Details sha256 3
8864395a61e6301de16a1bc1e44ba81eef50f381c5c5ba96b775125d9cfe9bb5
Details sha256 3
88d1f87fb3dd62742669ddcd1ed3ef75a7739b0890218b5ef9205add410ba9bc
Details sha256 3
8a9ab306676b0ff96308a8d1c3bb2708f056ba4c40b8924e554652d9d6bae10d
Details sha256 3
8eed9833eeb8da580c21ecc24cf11eac9e9fcbf0ce3c590ba083fd87cb79162c
Details sha256 3
8f9ed3df67aaae1173f812176a3ae0e55c5cf509f214b907fb2429d25e660c3b
Details sha256 3
8fd5e77eb0f3793fa3edcb37d6036837c509b73e316de12acef3f9fe53785800
Details sha256 3
8ff83ce96392a54e747cee31d81c01bbaeb625d219e91e2242c7851065a132d9
Details sha256 3
90c5478cdf810f74a8459c49c23f1744ca70f80e8ccde28f7b35fdcd47058991
Details sha256 3
930f71453c6ddbc130c14c5a0374b8a0a1ed9f783a1d937a95a74da2085091f5
Details sha256 3
94cae63dcbabb71c5dd43f55fd09caeffdcd7628a02a112fb3cba36698ef72bc
Details sha256 3
97954187fd1963ff8f3f4940dd159a5615f53414f40d2b6ec5e8c65bead1f823
Details sha256 3
9905e15fe72312c0b331438e54d33290f3570b069d240594cfc7b29776433347
Details sha256 3
9a6363406e3cc50f8933edf57a6eb2b34397a0ca1a01e2bc15bfb631dcd39237
Details sha256 3
9b645e000ae447e7b7761486f2502620a728a92f63a88350559d2ce25fd6e740
Details sha256 3
9c6644ddfa0964444fff983c69147b84663a06634d70e8a7a6afdd83cf81b047
Details sha256 3
9c83f3ad5cdc485d4537711cdfde08f804dff4ec5965e3ca4d592ab89c470a90
Details sha256 3
9d14d680770d58efa7cd10eddc4d0567003cfa0c637b19293ae9947b179352b7
Details sha256 3
9f59d8da895d673b8a44cf22af5aa102ae47bcf9c1d0747f90a20b08fa26cd51
Details sha256 3
9f7f1ffad39b78f807819d1c0a387029051bf83a5327fdd114747e69af27dd3f
Details sha256 3
a199f7cffedfbc29de5038f26d787b8cebe9419faa3ebcc60ff525a8394cd8e6
Details sha256 3
a1c5fa585fe39756b9b68c8300d004fa2197f35a5f91d45099cca6f48a273a9e
Details sha256 3
a32f9871166c20ca071beabf31e55cd78b91c680ec4eb2974b8c6d897e4a937f
Details sha256 3
a3b0472c35f9b1b831fe29a395cd03c34c805f5f1b48e4916543118edb7bfc59
Details sha256 3
a4027994d393f63c9729181364a65ba597b788f99a8f5b9071df056a5924871a
Details sha256 3
a4d43dbd89469003db525011bf7c0f4238bcfb62ef50817aa476d0a111a9838e
Details sha256 3
a5986423f0e4cbeaea4161de313b3f9ad5f5b0489fd49c7d646478a46030dc1f
Details sha256 3
a5ffd5be9acc472a237f8dddf189a46eeca6ba026fa8f3a564c533891d3a6068
Details sha256 3
a65fb1ff99711b0705d290f04ac82e8b1c4d57d97609cad1fb438e8c098ea4ac
Details sha256 3
a6a0c55de5c8def0ea81edb5bedf8b3e44847193a8a424b3ff143f0fea527e85
Details sha256 3
a9953390e2107439391ef965b29e573ffbcdeda99a2f9b23e2b661dc0b39a2ae
Details sha256 3
aa142160446a919eaba99ce15992f6e11b1fdaa7a9f569979a29068120f774cf
Details sha256 3
ac2f7a35bf6467d149099ba5c7287730f9ecbdbe30620da00ef706cace38d52c
Details sha256 3
add1aa87ae6d4e6adf430882b4b41c85084c456427fcca74e04231b7af035fd2
Details sha256 3
af5632eae9c825a9842498da8c8433067aec9f5de6e8dd6aed9869fc55e3311f
Details sha256 3
b134337a9eb771de606402d402259755c376bd3cd9a8d3b082d1a6d42082c3ba
Details sha256 3
b1461180e5ec961f373353b9320396614bd103a92113c2da8451a85d9a26d40f
Details sha256 3
b3298921d64b38212d420c1db99f7af5131dd034045ecfd5e61c81b5132b7aa8
Details sha256 3
b44f2e6ebc44ddef1b31882fa936c5ec9c59444aefa496e31db78dd0496c40ff
Details sha256 3
b5fafcd5ba301bdced4aead83b43776b181177c095fa77ec7c1cd20ca0c1f16a
Details sha256 3
b66961d7a143258328faf6adfab3a76cc6c5203db6de75dbc8d92188a94f6e1b
Details sha256 3
b6705d56b6652327766ae0cd6d534fd1c9fa15fb285c66634a0865709b54ba4f
Details sha256 3
b6bb6a615cd4b69b6ef356687c3d89aee6c10cd9017983a0a0123dcd34b73dc7
Details sha256 3
b7f81319543f16894802903decf8e6cc67b653bca110d46a1922110c45ecf927
Details sha256 3
b872982be285a934624a1b0062be3f6f6d4cf581582225d462b4ca42fac6fac2
Details sha256 3
b9aec9fe90560aef73d243ec98407ce16b9205c43bb479c9c48d3d6571fd3549
Details sha256 3
ba7100cbdf75cb422415d92e3f40a96fcc0e1fb7371a4bf93d8b1ee6eb33a71b
Details sha256 3
bb0120f8a8a47be9b6d83bbf1a3cc88e83c7c15ad6853763b3322c23fa7dfeae
Details sha256 3
bd66c143e61378e20b8707b1087aa3ccda89b981ea9bb0cd58af1553ac5ccd6a
Details sha256 3
c0811489113e099728a172129eb65dd83135f005228dc1c68e692b7aebfa4f74
Details sha256 3
c2d461bb057a5285c0b486191406a8cdcb27b068b85c6a2f1ed2e4440a89667c
Details sha256 3
c5730237d582ebc67b16aec7d8c2f4713374e2e24f4526012f81d691fec4047d
Details sha256 3
c5c7971596c26d2b06a681823eff6498e2d711ef2cb835561f3f02ec939cfc70
Details sha256 3
c9b7d6f903a3c60abe223301930c83b10e5d75c766fd46ad76efb9c06a5e9c78
Details sha256 11
c9d5dc956841e000bfd8762e2f0b48b66c79b79500e894b4efa7fb9ba17e4e9e
Details sha256 3
cc65064d24dcb2a2a828a3094bc6aa8552d562ef70dd54516847ee2ed1af505d
Details sha256 3
cda8e6fcc17eb0d20aa9f9886b68f24fe620dd62b64f24dda2bcc631d80e5668
Details sha256 3
cebf1b189633ac68edf0f7c5ee511c98bbfa4faa035f03bea9567c7618716f90
Details sha256 3
cee7ea70b2acd485091fad2bebfdd94e7441e193b971933c1262da8e0b9dc869
Details sha256 3
cf5175433e33881f72310afcadb3f2a26f2d587ed7eacbd142ae87253794be53
Details sha256 3
d7e74cac420244d367745dae65559483b9ce8bf503f3e673011579a5a0d5d8db
Details sha256 3
d9b584f7dc2f9ddbde5c2100adf8c41345844b6fe611b32c8a706985d65937f4
Details sha256 3
da913c1f55544b34f246438767bfd9e635b972a0796e214f78b94928d7301344
Details sha256 3
db0cb43151ccf1b60f7c2b2a26be378685c9867dd67cdd9ba74c242c9d719fe3
Details sha256 3
db84364a4dd1d45c7f7ee0da8a173a2476824f35d1802d3ffd7298bf58c506fd
Details sha256 3
dbb05dec80b41eddbb9d28788287bcb5c976c43e9db10e7858ac0f7cc73dc6f8
Details sha256 3
dcb8ecd5bbc1d57ea7b5931d11d216a3cad6b486072164adcb6054914d19ca06
Details sha256 3
dd23795a9b4fd3d90a74db73a9b6d4ea51f5be558485ae7c5c2c03d84e434b63
Details sha256 3
dd8c418eba9c96c668d744034a059b7b2208bdc57266b1d96637d9e5ff1cd61f
Details sha256 3
ddbac58f0b4bd56d398fcc7c5284e01b30451f6eb57510eb85d68602dcb3a803
Details sha256 3
e0e1e5f4fc7b2dd84b8d3062547b4c339c2fb223ea691be519df34013ec8db25
Details sha256 3
e10aff4db0d0e8ffc308875d6b92a856842ca884adee45120b8797a5e1b4bf66
Details sha256 2
e2e3689cba34a8dd3c25a964e7993692305ddaea9ab4d6f7289daec7fec1cdee
Details sha256 3
e3caa5762fc729758a88d19e8318a7bec582a0545c410b9d6e83fa6bbc6f191b
Details sha256 3
e3d8a0a3d83205c25372d914417360c5a6982a2265fb96bcce7ca04e40c6be8c
Details sha256 3
e472ad43000af4d77ace2444345bcc66f927d835c9bd188ebb5c67a4a83b3f36
Details sha256 3
e723076ee10041e3112e721ef1487ba124ba05dc0da2cdbf288f948aa2cf080e
Details sha256 3
e7e0d94408986525f439d39004292062a487fd8d0e1c5497754ac960e36dc5ee
Details sha256 3
e8c54be8487438b0956203dc5da2c2122b999f12526e623d50f542666646f176
Details sha256 3
ecf37807c9f986238e3eeffa4f9dc3514a88f03e9a9576932962af7cb00c84af
Details sha256 3
ef0281ccde19c2e2190617741cec07342ba7261c30a746e2fece1f4012c2adfd
Details sha256 3
efb05cd4dd9c7057b56f25264715e1139b35f6c183b17528a1004ad09e3da6f8
Details sha256 3
f20e33f5d59b06ed725c8da4429d46781d3796c0f661ebf4abc9f8f0d95d11ec
Details sha256 3
f40f0060217884e5fcd26c05eb585d548fa95bcba2e0399e13e69110adadc0f1
Details sha256 3
f9b02a73df01cc80f3f0e0f00c65683a853f61cb8fb9b928bfb5b3fbecdac614
Details IPv4 3
115.171.23.103
Details IPv4 2
104.207.131.59
Details IPv4 2
104.238.148.252
Details IPv4 2
104.238.167.138
Details IPv4 2
104.238.171.66
Details IPv4 2
104.238.188.193
Details IPv4 2
104.238.190.19
Details IPv4 2
104.238.191.117
Details IPv4 2
104.238.191.58
Details IPv4 2
107.191.47.0
Details IPv4 2
107.191.55.121
Details IPv4 2
107.191.56.255
Details IPv4 2
107.191.61.53
Details IPv4 2
107.191.62.30
Details IPv4 2
107.191.62.63
Details IPv4 2
107.191.63.40
Details IPv4 2
108.171.192.40
Details IPv4 2
108.186.9.16
Details IPv4 2
108.61.103.113
Details IPv4 2
108.61.165.235
Details IPv4 2
108.61.176.6
Details IPv4 2
108.61.184.73
Details IPv4 2
108.61.209.166
Details IPv4 2
108.61.213.122
Details IPv4 2
108.61.96.123
Details IPv4 2
109.74.193.218
Details IPv4 2
115.171.217.22
Details IPv4 2
137.175.104.3
Details IPv4 2
137.175.4.161
Details IPv4 3
139.59.181.152
Details IPv4 2
162.251.123.38
Details IPv4 2
173.199.70.35
Details IPv4 2
173.254.221.208
Details IPv4 2
173.254.221.212
Details IPv4 2
173.254.221.225
Details IPv4 2
173.254.47.58
Details IPv4 2
174.138.174.134
Details IPv4 2
178.124.164.210
Details IPv4 2
178.62.64.194
Details IPv4 2
185.92.220.4
Details IPv4 2
198.13.38.9
Details IPv4 2
198.13.40.158
Details IPv4 2
208.115.124.86
Details IPv4 2
208.115.124.90
Details IPv4 2
209.250.236.178
Details IPv4 12
209.99.40.222
Details IPv4 2
212.38.176.192
Details IPv4 2
216.244.78.239
Details IPv4 2
216.244.81.206
Details IPv4 2
45.32.10.120
Details IPv4 2
45.32.144.26
Details IPv4 2
45.32.144.36
Details IPv4 2
45.32.150.105
Details IPv4 2
45.32.188.102
Details IPv4 2
45.32.189.150
Details IPv4 2
45.32.189.152
Details IPv4 2
45.32.190.19
Details IPv4 2
45.32.20.96
Details IPv4 2
45.32.22.137
Details IPv4 2
45.32.233.191
Details IPv4 2
45.32.245.189
Details IPv4 2
45.32.252.97
Details IPv4 2
45.32.58.23
Details IPv4 2
45.63.115.143
Details IPv4 2
45.63.119.108
Details IPv4 2
45.63.27.207
Details IPv4 2
45.63.28.153
Details IPv4 2
45.63.28.169
Details IPv4 2
45.63.29.29
Details IPv4 2
45.76.120.223
Details IPv4 2
45.76.127.45
Details IPv4 2
45.76.133.158
Details IPv4 2
45.76.138.76
Details IPv4 2
45.76.208.43
Details IPv4 2
45.76.221.147
Details IPv4 2
45.76.44.21
Details IPv4 2
45.76.44.8
Details IPv4 2
45.76.45.183
Details IPv4 2
45.76.46.180
Details IPv4 2
45.76.85.174
Details IPv4 2
45.76.85.89
Details IPv4 2
45.77.11.53
Details IPv4 2
45.77.134.16
Details IPv4 2
45.77.141.40
Details IPv4 2
45.77.226.22
Details IPv4 2
45.77.233.247
Details IPv4 2
45.77.239.146
Details IPv4 2
45.77.65.74
Details IPv4 2
46.21.151.78
Details IPv4 2
67.20.113.129
Details IPv4 2
67.20.97.63
Details IPv4 2
69.195.80.130
Details IPv4 2
74.220.221.82
Details IPv4 2
76.74.178.92
Details IPv4 2
80.240.25.110
Details IPv4 2
83.234.149.173
Details IPv4 2
84.200.14.210
Details IPv4 2
84.200.4.230
Details IPv4 2
96.44.175.168
Details Threat Actor Identifier - APT 22
APT18
Details Threat Actor Identifier - APT 665
APT29
Details Threat Actor Identifier - APT 132
APT32
Details Threat Actor Identifier - APT 115
APT1
Details Threat Actor Identifier - APT 297
APT27
Details Threat Actor Identifier - APT 783
APT28
Details Threat Actor Identifier - APT 278
APT10
Details Threat Actor Identifier - APT 181
APT33
Details Threat Actor Identifier - APT 258
APT34
Details Threat Actor Identifier - APT 194
APT35
Details Threat Actor Identifier - APT 85
APT15
Details Threat Actor Identifier by SecureWorks 25
TG-3390
Details Threat Actor Identifier - FIN 8
FIN5
Details Url 3
http://www.nirsoft.net/utils/atnow.html
Details Url 3
https://www.openwall.com/passwords/windows-pwdump
Details Url 3
https://download.openwall.net/pub/projects/john/contrib/win32/pwdump
Details Url 3
https://github.com/hiwincn/htran
Details Url 3
https://sectools.org/tool/nbtscan
Details Url 3
https://www.win-rar.com/start.html?&l=4
Details Url 2
https://github.com/ysrc/webshell-sample/blob/master/aspx/a91320483df0178
Details Url 14
https://github.com/gentilkiwi/mimikatz
Details Url 6
https://docs.microsoft.com/en-us/sysinternals/downloads/procdump
Details Url 3
https://technet.microsoft.com/ru-ru/sysinternals/bb897553.aspx
Details Url 3
https://technet.microsoft.com/ru-ru/sysinternals/pslist.aspx
Details Url 3
http://www.wischik.com/lu/programmer/dbx_utils.html
Details Url 3
https://www.the-sz.com/products/portscan
Details Url 4
https://github.com/sensepost/regeorg/blob/master/tunnel.aspx
Details Url 3
https://github.com/tennc/webshell/blob/master/jsp/jsp_file_browser.jsp
Details Url 2
http://www.secureworks.com/resources/blog
Details Url 3
http://www.slideshare.net/matthewdunwoody1/no-easy-breach-derby-con-2016
Details Url 6
https://www.fireeye.com/blog/threat-research/2017/05/cyber-espionage-apt32.html
Details Url 4
https://www.welivesecurity.com/wp-content/uploads/2017/02/read-the-manual.pdf
Details Url 5
https://www.group-ib.com/blog/cobalt
Details Url 8
https://www.fireeye.com/content/dam/fireeye-www/services/pdfs/mandiant-apt1-report.pdf
Details Url 3
https://www2.fireeye.com/wbnr-are-you-ready-to-respond.html
Details Url 2
https://www.secureworks.com/research/threat-group-3390-targets-organizations-for-
Details Url 5
https://www.secureworks.com/research/bronze-union
Details Url 3
https://www.erai.com/customuploads/ca/wp/2015_12_wp_operation_iron_tiger.pdf
Details Url 3
https://www.symantec.com/connect/blogs/tick-cyberespionage-group-zeros-japan
Details Url 2
https://www.trendmicro.de/cloud-content/us/pdfs/security-intelligence/white-papers/wp_
Details Url 3
https://www.justice.gov/file/1080281/download
Details Url 2
https://www.nccgroup.trust/uk/about-us/newsroom-and-events/blogs/2018/march
Details Url 3
https://www.welivesecurity.com/2018/04/03/lazarus-killdisk-central-american-casino
Details Url 3
https://securelist.com/be2-custom-plugins-router-abuse-and-target-profiles/67353
Details Url 3
https://investors.fireeye.com/static-files/b7dcb16f-44a8-4cfb-927f-efeed397dd52