IOC Radar
TLP:WHITE124 IOCs

10 Things I Hate About Attribution: RomCom vs. TransferLoader

BO
Botvrij.eu OSINT Feed
Published July 2, 2025Original Report

Threat Actors

Diamond Model

SOCIAL AXISTECHNOLOGY AXISADVERSARYTA829INFRASTRUCTUREsupportcausems.comonefile.socialsharepdf.limitedCAPABILITYunknownVICTIMunknown
Adversary(1)
Infrastructure(6)
Capability
Victim

5W+H Threat Analysis

Analysis unavailable

Indicators of Compromise

Indicators of Compromise124

TypeIndicatorConfidenceScoreFirst Seen
Domainsupportcausems.com
indicatornetwork
High
68
Jun 2, 26
Domainonefile.social
indicatornetwork
High
68
Jun 2, 26
Domainsharepdf.limited
indicatornetwork
High
68
Jun 2, 26
SHA2563a234b49b834849689da477f77ca6363b40ee83e58213ee51b1ec248da90a543
file-hashloadermalware
High
68
Jun 2, 26
Domain1drive.expert
indicatornetwork
High
68
Jun 2, 26
Domainstorage-hub.pub
indicatornetwork
High
68
Jun 2, 26
SHA12b301191aa9e1d2c8e3eefd38b6eb1952b1fce88
file-hashloadermalware
High
68
Jun 2, 26
Domaindr365.live
indicatornetwork
High
68
Jun 2, 26
Domaindrivehost.live
indicatornetwork
High
68
Jun 2, 26
Domain1drive.social
indicatornetwork
High
68
Jun 2, 26
SHA256cd526475391c375e8e40f0146146672928db9bbf210acb41e0fd41381cd5eb9a
file-hashloadermalware
High
68
Jun 2, 26
Domaind1rv.social
indicatornetwork
High
68
Jun 2, 26
Domaindrivestorage.online
indicatornetwork
High
68
Jun 2, 26
Domain1drivems.expert
indicatornetwork
High
68
Jun 2, 26
Domainsharedrive.pub
indicatornetwork
High
68
Jun 2, 26
Domaincloudlive.pub
indicatornetwork
High
68
Jun 2, 26
Domain1drive.bio
indicatornetwork
High
68
Jun 2, 26
SHA25654a94c7ec259104478b40fd0e6325d1f5364351e6ce1adfd79369d6438ed6ed9
file-hashloadermalware
High
68
Jun 2, 26
Domainonedrivems.works
indicatornetwork
High
68
Jun 2, 26
SHA2567fc65b23e0a85f548e4268b77b66a3c9f3d08b9c1817c99bc1336d51d36e1ec6
file-hashloadermalware
High
68
Jun 2, 26
Domainonedrweb.live
indicatornetwork
High
68
Jun 2, 26
Domainmydrv1.live
indicatornetwork
High
68
Jun 2, 26
Domainonedrivecloud.click
indicatornetwork
High
68
Jun 2, 26
Domaindocumentapproved.click
indicatornetwork
High
68
Jun 2, 26
Domainonedrivems.cloud
indicatornetwork
High
68
Jun 2, 26
Domaindvfilesync.pub
indicatornetwork
High
68
Jun 2, 26
Domaindeliverycitylife.com
indicatornetwork
High
68
Jun 2, 26
Domainfile-acess.live
indicatornetwork
High
68
Jun 2, 26
Domaindrshare.online
indicatornetwork
High
68
Jun 2, 26
SHA25607b9e353239c4c057115e8871adc3cfb42467998c6b737b28435ecc9405001c9
file-hashloadermalware
High
68
Jun 2, 26
Domainjournalctl.website
indicatornetwork
High
68
Jun 2, 26
Domainmy-drive365.pub
indicatornetwork
High
68
Jun 2, 26
Domain1drivecloud.click
indicatornetwork
High
68
Jun 2, 26
SHA256fba9f2c351e898bfc61c8b1181020212ccb9e55041c4dd433ca2867dbf796469
file-hashloadermalware
High
68
Jun 2, 26
Domainfile-share.works
indicatornetwork
High
68
Jun 2, 26
Domaindvcloud.live
indicatornetwork
High
68
Jun 2, 26
Domain1drv.me
loadermalwarenetwork
High
68
Jun 2, 26
Domaingdl-cloud.works
indicatornetwork
High
68
Jun 2, 26
Domainmy-356drv.online
indicatornetwork
High
68
Jun 2, 26
Domain1drvfiles.online
indicatornetwork
High
68
Jun 2, 26
Domainonelivedrv.com
indicatornetwork
High
68
Jun 2, 26
Domainonedrivecloud.net
indicatornetwork
High
68
Jun 2, 26
Domain1drv365.online
indicatornetwork
High
68
Jun 2, 26
Domainopendnsapi.net
indicatornetwork
High
68
Jun 2, 26
Domain365drv.live
indicatornetwork
High
68
Jun 2, 26
Domainlauradream.com
indicatornetwork
High
68
Jun 2, 26
Domain1drivecloud.live
indicatornetwork
High
68
Jun 2, 26
Domainmspdf.live
indicatornetwork
High
68
Jun 2, 26
Domain1drv.site
loadermalwarenetwork
High
68
Jun 2, 26
Domainshare-doc.live
indicatornetwork
High
68
Jun 2, 26
Domaincdngateway.us
loadermalwarenetwork
High
68
Jun 2, 26
Domain1dvstorage.com
indicatornetwork
High
68
Jun 2, 26
SHA25600385cae3630694eb70e2b82d5baa6130c503126c17db3fc63376c7d28c04145
file-hashloadermalware
High
68
Jun 2, 26
Domaingworkspace.social
indicatornetwork
High
68
Jun 2, 26
Domainlivestorage.click
indicatornetwork
High
68
Jun 2, 26
Domainmy1drv.online
indicatornetwork
High
68
Jun 2, 26
Domain1drvms.space
loadermalwarenetwork
High
68
Jun 2, 26
Domainmyonedrive365.live
indicatornetwork
High
68
Jun 2, 26
Domain1drivems.works
indicatornetwork
High
68
Jun 2, 26
Domainworkspace-doc.live
indicatornetwork
High
68
Jun 2, 26
Domaingdrive-share.online
indicatornetwork
High
68
Jun 2, 26
Domaingdrvdocs.online
indicatornetwork
High
68
Jun 2, 26
Domainclouderive.com
indicatornetwork
High
68
Jun 2, 26
Domainmngersrv.com
indicatornetwork
High
68
Jun 2, 26
Domainonlinedrive.click
indicatornetwork
High
68
Jun 2, 26
Domain365work.chat
indicatornetwork
High
68
Jun 2, 26
Domain1dcloud.live
indicatornetwork
High
68
Jun 2, 26
SHA1d890d4b40ce56f90b9ea168bf6d7bf5043a47319
file-hashloadermalware
High
68
Jun 2, 26
Domainonedr.expert
indicatornetwork
High
68
Jun 2, 26
Domaindrivedefend.com
indicatornetwork
High
68
Jun 2, 26
Domain1drive.pub
indicatornetwork
High
68
Jun 2, 26
SHA256e7917ff12114be5c79ca9bd0082eb628192c2ebfbee7aad2ae626ea208ee37cf
file-hashloadermalware
High
68
Jun 2, 26
Domainondv.live
indicatornetwork
High
68
Jun 2, 26
Domaindrivehub.live
indicatornetwork
High
68
Jun 2, 26
Domain1drv.eu.com
indicatornetwork
High
68
Jun 2, 26
Domaincloud-pdf.online
indicatornetwork
High
68
Jun 2, 26
Domain1drv.zone
loadermalwarenetwork
High
68
Jun 2, 26
SHA2566d5226cba687d99ce14eda8de290edd470e79436625618559c8db1458a53666c
file-hashloadermalware
High
68
Jun 2, 26
Domaindrsync.click
indicatornetwork
High
68
Jun 2, 26
Domaincloudly.live
indicatornetwork
High
68
Jun 2, 26
Domainhealthfy.bio
indicatornetwork
High
68
Jun 2, 26
Domainstoragedrive.pub
indicatornetwork
High
68
Jun 2, 26
Domainshare-pdf.live
indicatornetwork
High
68
Jun 2, 26
Domain1drv365.live
indicatornetwork
High
68
Jun 2, 26
Domain1drv.biz
loadermalwarenetwork
High
68
Jun 2, 26
SHA256f5f2761278163a1a813356666cb305fe37806f5f633b2a5475997f10d24fb3d4
file-hashloadermalware
High
68
Jun 2, 26
Domainpdf-storage.pub
indicatornetwork
High
68
Jun 2, 26
Domain1drvcloud.online
indicatornetwork
High
68
Jun 2, 26
Domaincloud1dv.com
indicatornetwork
High
68
Jun 2, 26
Domainconsvcprivacy.com
indicatornetwork
High
68
Jun 2, 26
SHA2568f3b065e6aa6bc220867cdcb1c250c69b2d46422c51f66f25091f6cab5d043de
file-hashloadermalware
High
68
Jun 2, 26
Domaindata-dv.live
indicatornetwork
High
68
Jun 2, 26
Domainonedrivecloud.live
indicatornetwork
High
68
Jun 2, 26
Domain1drive.works
indicatornetwork
High
68
Jun 2, 26
Domain1day.live
indicatornetwork
High
68
Jun 2, 26
Domain1dv.online
indicatornetwork
High
68
Jun 2, 26
Domainsite-staff.sale
indicatornetwork
High
68
Jun 2, 26
Domaindiskstorage.click
indicatornetwork
High
68
Jun 2, 26
Domainondrve.live
indicatornetwork
High
68
Jun 2, 26
SHA2567e51eb44cfd945f4a155707f773fae3207ebfb59d45ea866ba69bd9bc28dfc32
file-hashloadermalware
High
68
Jun 2, 26
Domain1drv-storage.pub
indicatornetwork
High
68
Jun 2, 26
Domaindrivepublic.live
indicatornetwork
High
68
Jun 2, 26
Domainfile-cloud.company
indicatornetwork
High
68
Jun 2, 26
Domaintemptransfer.live
loadermalwarenetwork
High
68
Jun 2, 26
Domain1dv365.live
indicatornetwork
High
68
Jun 2, 26
Domaindrivepoint.pub
indicatornetwork
High
68
Jun 2, 26
Domaindrive-share.pub
indicatornetwork
High
68
Jun 2, 26
Domainmy1drv.live
indicatornetwork
High
68
Jun 2, 26
Domainpdf-share.pub
indicatornetwork
High
68
Jun 2, 26
Domain1drive-work.online
indicatornetwork
High
68
Jun 2, 26
Domainonedrivecloud.expert
indicatornetwork
High
68
Jun 2, 26
Domaindatadrv1.com
indicatornetwork
High
68
Jun 2, 26
Domain1share.limited
indicatornetwork
High
68
Jun 2, 26
Domainpdfshare.click
indicatornetwork
High
68
Jun 2, 26
SHA25633971df8f5c34c3c79f64e2e28e300260499285bd37f77295ba88897728ace4b
file-hashloadermalware
High
68
Jun 2, 26
SHA2561c6a5476d485d311be1e07c2e0d2ae322214caa5d4f84398d4169d499105b01a
file-hashloadermalware
High
68
Jun 2, 26
Domaindriveshare.pub
indicatornetwork
High
68
Jun 2, 26
Domain1drv.world
indicatornetwork
High
68
Jun 2, 26
Domain1drw.live
indicatornetwork
High
68
Jun 2, 26
Domain1drv-team.works
indicatornetwork
High
68
Jun 2, 26
Domainms.share-onedr.com
indicatornetwork
High
68
Jun 2, 26
Domaindrivenc.pub
indicatornetwork
High
68
Jun 2, 26
Domain365msdrv.live
indicatornetwork
High
68
Jun 2, 26
Domainonestorelink.live
indicatornetwork
High
68
Jun 2, 26

IOC Relationship Graph

IOC Relationship Graph124 total IOCs
DomainSHA256SHA1
Domain108SHA25614SHA12Actors1REPORT10 Things I Hate About AttTA829
scroll to zoom · drag to pan · click IOC to open