Skip to content
/ IoCs Public

Files

Latest commit

9d121a4 · Jun 6, 2024

History

History
39 lines (39 loc) · 2.88 KB

crimson_palace_stac1248-alpha.csv

File metadata and controls

39 lines (39 loc) · 2.88 KB
1
IndicatorDataNotes
2
sha256110c5eec940f3abb8b3a671cd292bc9ef65772168325a7949290e9828353824asslwnd64.exe (PhantomNet)
3
sha256e9cb02690d987de8d392d0e24b3ccbb294c751dff73962135913c7ec0d8a8064sslwnd64.exe (PhantomNet)
4
sha256c1abc254d231574044ffe7bdd030be04618916f255396197f1151bfec98c04b6nethood.exe (PhantomNet)
5
sha256e8cd237ac43fa0505d858ac8eb800020eeca104a1cd931d3b6d0ef656ee5393doci.dll (PhantomNet)
6
sha256173bb620ed2eee6b356e128da88e173eb1b69253ecd616f8f984087688c089fdX64.dll (PhantomNet, renamed to oci.dll)
7
sha256c06065d3de3bfb37168a5d94baf1c675f831a201937ef774a36c2ea2bf6fc49ewlbsctrl.dll (EAGERBEE)
8
sha256b05b92fd84cc3e3bd6378cadbe9b8b2cb926c42383e6194be1df44d1b9202fc1TSVIPSrv.dll (EAGERBEE)
9
sha256951c7f8fdb6cfc8b362615ab1eec4a07dc8fccfd3a7ecda8255908a93b6a1f21TSVIPSrv.dll (EAGERBEE)
10
sha25601544aeb502163c4fb7bac483430059183ce3d11aee78cd4a6c7074c5289540eC:\ProgramData\Microsoft\DeviceSync\jli.dll (EAGERBEE)
11
sha25647c4a62fe75aa62906f0b110668e17947e905a33759100de21b987879b47183bC:\ProgramData\Microsoft\Vault\vmnat.dll (Merlin)
12
sha2567ed44a0e548ba9a3adc1eb4fbf49e773bd9c932f95efc13a092af5bed30d3595pc2msupp.dll (Malicious DLL sideloaded by MOBPOPUP.exe)
13
sha256f499f8d9584e5f4474b19324b807a38fec1c1d38d5df2ff4c1e16798311bc25bMSI64.exe (RUDEBIRD)
14
sha25668ee8c2209641a6796e06caa115effcb89f722a5737210b5bebb87a36e5141a8ba0oddof.dll (CSC compilation artifact from 1.ps1 execution)
15
sha2569404f51ccaf4165e6add08344f04b90ae79a045814d6b1de6b6c1e30981faa78SophosUD.exe (PowHeartBeat)
16
sha2560e010a36ff24299592569f7c3fc01c597e158996d94b66eb3bbf757742663e76SophosUD.exe (PowHeartBeat)
17
sha2561b97afb3310b3af944f74c2d715c110cec32ec536c0a9837b8c88df3438b2a63SophosUD2.exe (PowHeartBeat)
18
sha2562a662b58f1dd229e7dba923a4d123658e3c10c0cfcec03748fbe577db81db34dSensAPI.dll (Malicious DLL sideloaded by ph.exe)
19
sha256bbc0fe549a9e902528a125abd13b1f7c53746416d9c9bb91f88877f37a4ce11cC:\ProgramData\Microsoft\Windows\svcchost.dll (Malicious DLL sideloaded by renamed vmnat.exe, svcchost.exe)
20
domaincloud.keepasses.comMerlin C2
21
ip89.44.197.74Merlin C2
22
domainscancenter.trendrealtime.comRUDEBIRD C2
23
ip185.195.237.123RUDEBIRD C2; EAGERBEE C2
24
ip195.123.247.50RUDEBIRD C2
25
ip172.67.130.71PhantomNet C2
26
ip45.90.58.103PhantomNet C2; RUDEBIRD C2
27
ip185.195.237.121PhantomNet C2
28
ip104.21.3.57PhantomNet C2
29
ip185.82.217.164PhantomNet C2
30
ip195.123.245.79PhantomNet C2
31
ipassociate.feedfoodconcerning.infoPhantomNet C2
32
ipassociate.freeonlinelearningtech.comPhantomNet C2
33
ipmsudapis.infoPowHeartBeat C2
34
ip154.39.137.29PowHeartBeat C2
35
ip147.139.47.141PowHeartBeat C2
36
ip185.167.116.30PhantomNet C2; EAGERBEE C2
37
ipassociate.freeonlinelearning.comEAGERBEE C2
38
ip91.220.202.143EAGERBEE C2
39
ip139.162.18.97dllhost.exe