Weekly Intelligence Report - 3 July 2025 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware - National Cyber Security Consulting
Common Information
Type Value
UUID 4b3d4200-6ee2-4fb7-a938-b9de2f08d959
Fingerprint b47689918791de49
Analysis status DONE
Considered CTI value 2
Text language
Published July 3, 2025, 10:15 p.m.
Added to db July 4, 2025, 1:20 a.m.
Last updated July 11, 2025, 10:50 p.m.
Headline Weekly Intelligence Report – 3 July 2025 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware
Title Weekly Intelligence Report - 3 July 2025 | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware - National Cyber Security Consulting
Detected Hints/Tags/Attributes 311/4/231
Archive Viewer
RSS Feed
Details Id Enabled Feed title Url Added to db
Details 6 National Cyber Security Consulting https://nationalcybersecurity.com/feed/ 2025-06-06 22:06
Attributes
Details Type #Events CTI Value
Details CERT Ukraine 13
UAC-0226
Details CVE 3
cve-2025-34040
Details Domain 106
api.ipify.org
Details Domain 348
system.net
Details Domain 5
conn-ectionor.cfd
Details Domain 5
optio-nalynk.online
Details Domain 5
ques-tion-ing.xyz
Details Domain 5
sendly-ink.shop
Details Domain 4
shaer-likn.store
Details Domain 4
alison624.online
Details Domain 4
bestshopu.online
Details Domain 4
black-friday-store.online
Details Domain 5
idea-home.online
Details Domain 4
book-handwrite.online
Details Domain 4
world-shop.online
Details Domain 4
lenan-rex.online
Details Domain 4
first-course.online
Details Domain 4
reading-course.online
Details Domain 4
make-house.online
Details Domain 4
est5090.online
Details Domain 4
zra-roll.online
Details Domain 4
tomas-company.online
Details Domain 4
clame-rade.online
Details Domain 4
dmn-for-hall.online
Details Domain 4
word-course.online
Details Domain 4
clothes-show.online
Details Domain 4
expressmarket.online
Details Domain 4
loads-ideas.online
Details Domain 4
sky-writer.online
Details Domain 4
becker624.online
Details Domain 4
adams-cooling.online
Details Domain 4
stadium-fresh.online
Details Domain 4
royalsoul.online
Details Domain 4
live-message.online
Details Domain 4
teammate-live.online
Details Domain 4
wood-house.online
Details Domain 4
ude-final.online
Details Domain 4
city-splash.online
Details Domain 4
door-black-meter.online
Details Domain 4
prt-max.online
Details Domain 4
albert-company.online
Details Domain 4
human-fly900.online
Details Domain 4
dmn-for-car.online
Details Domain 4
good-student.online
Details Domain 4
goods-companies.online
Details Domain 4
pnl-worth.online
Details Domain 4
ricardo-mell.online
Details Domain 4
live-coaching.online
Details Domain 4
wer-d.info
Details Domain 4
spring-club.info
Details Domain 4
all-for-city.info
Details Domain 4
beta-man.info
Details Domain 4
amg-car-ger.info
Details Domain 4
cc-newton.info
Details Domain 4
steve-brown.info
Details Domain 4
connect-room.online
Details Domain 4
live-gml.online
Details Domain 4
roland-cc.online
Details Domain 4
exir-juice.online
Details Domain 4
yamal-group.online
Details Domain 4
live-conn.online
Details Domain 4
online-room.online
Details Domain 4
platinum-cnt.info
Details Domain 4
crysus-h.info
Details Domain 4
lynda-tricks.online
Details Domain 4
message-live.online
Details Domain 4
white-life-bl.info
Details Domain 4
meet-work.info
Details Domain 4
prj-ph.info
Details Domain 4
hrd-dmn.info
Details Domain 4
ntp-clock-h.info
Details Domain 4
work-meeting.info
Details Domain 4
ph-crtdomain.info
Details Domain 4
nsim-ph.info
Details Domain 4
warning-d.info
Details Domain 4
live-meet.cloud
Details Domain 4
live-meet.blog
Details Domain 4
live-meet.info
Details Domain 4
live-meet.cfd
Details Domain 4
live-meet.live
Details Domain 4
network-show.online
Details Domain 4
redirect-review.online
Details Domain 4
arizonaclub.me
Details Domain 4
backback.info
Details Domain 4
cloth-model.blog
Details Domain 4
cook-tips.info
Details Domain 4
network-review.xyz
Details Domain 4
socks.beauty
Details Domain 4
gallery-shop.online
Details Domain 4
network-game.xyz
Details Domain 4
good-news.cfd
Details Domain 4
network-show-a.online
Details Domain 4
panel-network.online
Details Domain 4
panel-redirect.online
Details Domain 4
encryption-redirect.online
Details Domain 4
thomas-mark.xyz
Details Domain 4
rap-art.info
Details Domain 4
anna-blog.info
Details Domain 4
arrow-click.info
Details Domain 4
best85best.online
Details Domain 4
shadow-network.best
Details Domain 4
good-news.fashion
Details Domain 4
warplogic.pro
Details Domain 4
cyberlattice.pro
Details Domain 4
show-verify.xyz
Details Domain 4
top-game.online
Details Domain 4
suite-moral.info
Details Domain 4
nice-goods.online
Details Domain 4
crysus-p.info
Details Domain 4
wash-less.online
Details Domain 4
ptr-cc.online
Details Domain 4
white-car.online
Details Domain 4
live-content.online
Details Domain 4
bracs-lion.online
Details Domain 4
storm-wave.online
Details Domain 4
course-math.info
Details Domain 4
food-tips-blog.online
Details Domain 4
white-life.info
Details Domain 4
ph-work.info
Details Domain 4
normal-dmn.info
Details Domain 4
panel-meeting.info
Details Domain 4
prj-pa.info
Details Domain 4
ntp-clock-p.info
Details Domain 4
nsim-pa.info
Details Domain 4
pa-crtdomain.info
Details Domain 4
infinit-world.info
Details Domain 4
alex-mendez-fire.info
Details Domain 4
reg-d.info
Details Domain 4
everything-here.info
Details Domain 4
healthy-lifestyle.fit
Details Domain 4
alpha-man.info
Details Domain 4
lesson-first.info
Details Domain 4
master-club.info
Details Domain 1
www.quaser.com
Details Domain 1
www.siamgas.com
Details Domain 2
service.seeyon.com
Details Domain 1
www.zuelligindustrial.com
Details Domain 1
kalad.com.sa
Details Domain 1
ewet.bts.co.th
Details File 1
restore-my-file-kavva.txt
Details File 1284
powershell.exe
Details File 49
pwsh.exe
Details File 252
wmic.exe
Details File 265
vssadmin.exe
Details File 26
diskshadow.exe
Details File 5
pwsh.dll
Details File 38
wbadmin.exe
Details File 1
c:\\users\\public\\documents\\bellaciao.ps1
Details File 2
document.docm
Details File 2
wer-d.inf
Details File 2
spring-club.inf
Details File 2
all-for-city.inf
Details File 2
beta-man.inf
Details File 2
amg-car-ger.inf
Details File 2
cc-newton.inf
Details File 2
steve-brown.inf
Details File 2
platinum-cnt.inf
Details File 2
crysus-h.inf
Details File 2
white-life-bl.inf
Details File 2
meet-work.inf
Details File 2
prj-ph.inf
Details File 2
hrd-dmn.inf
Details File 2
ntp-clock-h.inf
Details File 2
work-meeting.inf
Details File 2
ph-crtdomain.inf
Details File 2
nsim-ph.inf
Details File 2
warning-d.inf
Details File 2
live-meet.inf
Details File 2
backback.inf
Details File 2
cook-tips.inf
Details File 2
rap-art.inf
Details File 2
anna-blog.inf
Details File 2
arrow-click.inf
Details File 2
suite-moral.inf
Details File 2
crysus-p.inf
Details File 2
course-math.inf
Details File 2
white-life.inf
Details File 2
ph-work.inf
Details File 2
normal-dmn.inf
Details File 2
panel-meeting.inf
Details File 2
prj-pa.inf
Details File 2
ntp-clock-p.inf
Details File 2
nsim-pa.inf
Details File 2
pa-crtdomain.inf
Details File 2
infinit-world.inf
Details File 2
alex-mendez-fire.inf
Details File 2
reg-d.inf
Details File 2
everything-here.inf
Details File 2
alpha-man.inf
Details File 2
lesson-first.inf
Details File 2
master-club.inf
Details File 2
tp.html
Details IBM X-Force - Threat Group Enumeration 24
ITG18
Details IPv4 5
185.130.226.71
Details IPv4 5
45.12.2.158
Details IPv4 5
45.143.166.230
Details IPv4 5
91.222.173.141
Details IPv4 5
194.11.226.9
Details IPv4 4
195.66.213.132
Details IPv4 4
146.19.254.238
Details IPv4 4
194.11.226.29
Details IPv4 4
194.11.226.46
Details IPv4 4
194.61.120.185
Details IPv4 4
2.56.126.230
Details IPv4 4
194.11.226.5
Details MITRE ATT&CK Techniques 257
T1070
Details MITRE ATT&CK Techniques 296
T1490
Details MITRE ATT&CK Techniques 249
T1566.002
Details MITRE ATT&CK Techniques 275
T1203
Details MITRE ATT&CK Techniques 15
T1542.003
Details MITRE ATT&CK Techniques 514
T1055
Details MITRE ATT&CK Techniques 58
T1014
Details MITRE ATT&CK Techniques 445
T1036
Details MITRE ATT&CK Techniques 199
T1564.001
Details MITRE ATT&CK Techniques 86
T1564.003
Details MITRE ATT&CK Techniques 358
T1003
Details MITRE ATT&CK Techniques 361
T1012
Details MITRE ATT&CK Techniques 1075
T1082
Details MITRE ATT&CK Techniques 568
T1071
Details MITRE ATT&CK Techniques 204
T1095
Details MITRE ATT&CK Techniques 213
T1573
Details MITRE ATT&CK Techniques 148
T1485
Details MITRE ATT&CK Techniques 133
T1496
Details Threat Actor Identifier - APT 260
APT35
Details Threat Actor Identifier - APT 482
APT42
Details Url 23
https://api.ipify.org
Details Url 1
https://www.quaser.com/
Details Url 1
https://www.siamgas.com/
Details Url 2
https://service.seeyon.com/patchtools/tp.html
Details Url 1
https://kalad.com.sa/
Details Yara rule 1
rule GIFTEDCROOK_Infostealer {
	meta:
		description = "Detects GIFTEDCROOK Infostealer based on known strings and behaviors"
		author = "CYFIRMA"
		date = "2025-07-01"
		malware_family = "GIFTEDCROOK"
		threat_type = "Infostealer"
		reference = "Internal Analysis / OSINT"
	strings:
		$s1 = "GIFTEDCROOK" ascii wide
		$s2 = "Crypto Wallets Found:"
		$s3 = "Collected browser credentials"
		$s4 = "Discord Token Grabber"
		$s5 = "System Information Collected"
		$s6 = "https://api.ipify.org"
		$s7 = "AppData\\Local\\Temp\\giftedcrook" wide
		$s8 = "Mozilla\\Firefox\\Profiles" wide
		$s9 = "Chrome\\User Data\\Default\\Login Data" wide
	condition:
		uint16(0) == 0x5A4D and (1 of ($s*) or all of ($s1, $s2, $s3))
}