Pearl Sleet (APT37) APT IOCs - Part 6 - SEC-1275-1
Tags
attack-pattern: | Domains - T1583.001 Domains - T1584.001 Powershell - T1059.001 Powershell - T1086 |
Common Information
Type | Value |
---|---|
UUID | 9860745f-313c-4f8e-b5ee-e4d8fe8adf1a |
Fingerprint | 1edbf7a2128f50ef |
Analysis status | DONE |
Considered CTI value | 0 |
Text language | |
Published | Nov. 8, 2024, midnight |
Added to db | Nov. 8, 2024, 9:30 a.m. |
Last updated | Nov. 8, 2024, 9:30 a.m. |
Headline | Pearl Sleet (APT37) APT IOCs - Part 6 |
Title | Pearl Sleet (APT37) APT IOCs - Part 6 - SEC-1275-1 |
Detected Hints/Tags/Attributes | 6/1/22 |
Source URLs
URL Provider
Details | Provider | Source level domain |
---|---|---|
Details | 1275.ru | 1275.ru |
RSS Feed
Details | Id | Enabled | Feed title | Url | Added to db |
---|---|---|---|---|---|
Details | 8 | ✔ | Архивы IOC - SEC-1275-1 | https://1275.ru/ioc/feed | 2024-08-30 22:08 |
Attributes
Details | Type | #Events | CTI | Value |
---|---|---|---|---|
Details | Domain | 3 | filedownloadserve.com |
|
Details | Domain | 3 | kakaofilestorage.com |
|
Details | Domain | 3 | navarar.com |
|
Details | File | 1 | panic.dat |
|
Details | File | 1 | viewer.dat |
|
Details | md5 | 3 | 105ecd9f6585df4e1fe267c2809ee190 |
|
Details | md5 | 3 | 358122718ba11b3e8bb56340dbe94f51 |
|
Details | md5 | 3 | 5f6682ad9da4590cba106e2f1a8cbe26 |
|
Details | md5 | 3 | 7a66738cca9f86f4133415eedcbf8e88 |
|
Details | md5 | 3 | 852544f01172b8bae14ec3e4d0b35115 |
|
Details | md5 | 3 | acf4085b2fa977fc1350f0ddc2710502 |
|
Details | md5 | 3 | b85a6b1eb7418aa5da108bc0df824fc0 |
|
Details | md5 | 3 | e4ddd5cc8b5f4d791f27d676d809f668 |
|
Details | IPv4 | 3 | 108.181.50.58 |
|
Details | IPv4 | 3 | 141.164.60.110 |
|
Details | IPv4 | 3 | 141.164.62.19 |
|
Details | IPv4 | 3 | 158.247.219.10 |
|
Details | IPv4 | 3 | 158.247.249.129 |
|
Details | IPv4 | 3 | 175.214.194.61 |
|
Details | IPv4 | 3 | 223.104.236.114 |
|
Details | IPv4 | 3 | 61.97.243.2 |
|
Details | Threat Actor Identifier - APT | 277 | APT37 |